Utility-Based Task Placement for Sustainable Anomaly Detection in IoT Edge-Cloud Architectures
Resource-constrained IoT environments require security detection mechanisms that balance responsiveness, computational cost, and detection capability. This paper presents a utility-based decision framework for adaptive task placement of anomaly detection across local, edge, and cloud layers. Five operational metrics are formalised, covering latency and communication cost, energy cost, detection complexity, attack coverage, and context relevance, and integrated into a composite utility function that selects the most suitable processing layer for each incoming event. The framework incorporates confidence-modulated detection scoring and globally normalised context relevance to enable principled escalation of complex or uncertain events. A discrete-event simulation modelling a three-tier IoT architecture with nine attack categories demonstrates that the proposed balanced configuration achieves 97% of cloud-level detection quality while consuming 53% of its energy cost, outperforming all baseline strategies in composite utility. Per-class analysis confirms that the framework routes high-severity events to more capable layers while retaining simple traffic locally. The configurable weight vector further enables operators to navigate the efficiency–detection trade-off according to deployment requirements.