Two papers propose hierarchical runtime monitoring for edge-IoT
Two 7 October 2026 arXiv papers describe hierarchical edge-IoT monitors, but disagree on TeSSLa versus RTLola, tier count, latency, and testbeds.
Two arXiv cs.CR papers from 7 October 2026 describe hierarchical runtime verification meant to catch coordinated edge-IoT attacks while sending compact results upstream rather than raw packets. The earlier report uses edge TeSSLa monitors over size, payload validity, rate, and timestamp drift that emit four-valued verdicts at sub-microsecond per-event cost, with a gateway MonPoly monitor at microsecond scale and roughly one Boolean per aggregation window per node on the uplink. Its container testbed covered buffer overflow, time spoofing, denial of service, and mixed APT patterns, and every alert included a witness naming the device, tier, and predicate. The later report instead specifies three layers—edge classification, gateway aggregation of short per-device windows, and a cloud tier combining MonPoly with RTLola—and says edge and gateway per-event monitoring stayed in the microsecond range. The sources disagree on tools, tier count, and latency: TeSSLa with gateway MonPoly and sub-microsecond edge cost versus cloud MonPoly with RTLola and only microsecond-scale edge and gateway cost. On a 15-actor Docker testbed with eight attack profiles plus a silent-bypass case, the later design attributed incidents to attacker-labelled devices; MonPoly covered coordinated overflow and multi-vector, escalation, and persistent-campaign activity, while RTLola caught silent nodes that event-triggered monitors miss.
- Both reports are arXiv cs.CR items from 2026-10-07 (10:40 and 10:49 UTC) on hierarchical runtime verification for edge-IoT.
- Report 1: edge TeSSLa specs over size, payload validity, rate, and timestamp drift emit four-valued verdicts per window at sub-microsecond per-event cost; a gateway MonPoly monitor runs at microsecond scale.
- Report 1: the uplink carries about one Boolean per aggregation window per node instead of raw packets, and every alert includes a witness naming the device, tier, and predicate.
- Report 1 container testbed covers buffer overflow, time spoofing, denial of service, and mixed APT patterns.
- Report 2: three layers—edge classification, gateway aggregation of short per-device windows, and a cloud tier running MonPoly and RTLola together.
- Report 2: MonPoly checks coordinated overflow plus per-device multi-vector, escalation, and persistent-campaign patterns; RTLola checks a time-triggered silent-node property missed by event-triggered monitors.
- Report 2 evaluation: a 15-actor Docker testbed with eight attack profiles plus silent bypass; device-attributable incidents named attacker-labelled devices; RTLola caught silent bypasses.
- Sources disagree on stack and cost: TeSSLa plus gateway MonPoly with sub-microsecond edge cost versus cloud MonPoly plus RTLola with edge and gateway monitoring only in the microsecond range.
Coverage timelineoldest first · each row is one article
- · 1d agoHierarchical Security Monitoring for Edge-IoT: A Formal Methods Approach
arXiv cs.CR· 32
Hierarchical TeSSLa and MonPoly monitors detect cross-device edge-IoT attacks while sending only compact verdicts upstream.
- · 1d agoHybrid Hierarchical Runtime Verification for Edge-IoT Security: Combining MonPoly and RTLola
arXiv cs.CR· 34
A three-layer edge-IoT monitor pairs MonPoly with RTLola to catch coordinated attacks and silent compromised nodes.