Security-by-Design and Risk-Based Certification for AI-Enabled Smart Home
The integration of Artificial Intelligence (AI) into Internet of Things (IoT) ecosystems has enabled the development of advanced cyber–physical systems, including smart appliances, while introducing security, privacy, and AI governance risks that extend beyond the scope of traditional threat models. Existing approaches often address cybersecurity, AI risk management, and regulatory compliance in isolation, leaving manufacturers without a systematic method for translating identified threats into architectural controls and certification requirements. To address this gap, this study proposes a Security-by-Design and risk-based certification framework that combines a six-layer IoT-AI reference architecture with STRIDE-based threat analysis augmented to capture AI-specific threats, including prompt injection and data poisoning. The resulting cross-layer analysis informs a four-level certification model (L1–L4) that deterministically maps each appliance configuration to a set of mandatory security and governance controls according to its degree of autonomy and AI capability. The framework is instantiated and evaluated using a physical smart-refrigerator prototype, demonstrating how threat identification can be systematically translated into design decisions and certification requirements. The proposed framework provides manufacturers, certification bodies, and researchers with a reproducible engineering pathway for designing and evaluating secure, governance-aligned AI-enabled IoT appliances.