A novel Artificial Intelligence (AI)-enabled automated conceptual framework, AutoAIPenTest, is proposed that integrates machine learning, reinforcement learning, and large language models to perform intelligent, real-time security assessments in dynamic IoT ecosystems.
Abstract
The rapid proliferation of the Internet of Things (IoT) has transformed industries by enabling seamless interconnectivity among devices, applications, and networks. However, this widespread adoption has also introduced significant security vulnerabilities, exposing IoT ecosystems to cyber threats such as unauthorized access, data breaches, and large-scale cyber-attacks. As IoT technology continues to evolve, mitigating these vulnerabilities remains a complex and pressing challenge. In this context, penetration testing, which is also known as pen testing, serves as a proactive security measure, enabling organizations to identify and address potential weaknesses before they can be exploited by malicious actors. Penetration testing for IoT systems is a specialized security assessment that addresses the unique vulnerabilities of interconnected devices, networks, and communication protocols, differing significantly from traditional computing and network penetration testing methodologies. In this regard, this study presents a review of penetration testing as a critical methodology for identifying, assessing, and mitigating security risks in IoT environments. We examine the key steps, tools, and methodologies specifically designed for IoT penetration testing, demonstrating their applicability across diverse infrastructures through a simple case study. Further, this study also proposes a novel Artificial Intelligence (AI)-enabled automated conceptual framework, AutoAIPenTest, that integrates machine learning, reinforcement learning, and large language models to perform intelligent, real-time security assessments in dynamic IoT ecosystems. Our findings highlight the critical role of proactive security measures, including structured penetration testing, secure development practices, and regulatory compliance, in strengthening the resilience of the IoT ecosystem. By discussing existing challenges and proposing effective security strategies, this study contributes to ongoing efforts to secure IoT domains and ensure that technological advancements do not come at the expense of cybersecurity.
The rapid proliferation of Internet of Things (IoT) devices has transformed everyday environments, connecting homes, enterprises, and industrial systems in unprecedented ways. While these devices offer significant convenience and functionality, their widespread deployment coupled with common weak security mechanisms, make them an attractive target for cyberattacks. In this paper, we examine IoT as a cyber attack platform, analysing both real-world incidents and proof-of-concept attacks to understand how compromised devices are leveraged to target other systems. We identify the IoT device vulnerabilities most frequently exploited, classified according to the OWASP Top 10 IoT vulnerabilities, and evaluate the resulting impact on the confidentiality, integrity, and availability (CIA) of targeted systems. Our review highlights the evolving strategies attackers use to harness IoT devices for distributed attacks, from botnets to lateral movement within networks. Based on these insights, we discuss the lessons learned and underscore the critical role of robust security mechanisms in enabling the next generation of secure IoT devices and services.
V. Vassilakis, Thomas Girdler· International Symposium on C...· 0 citations
Internet of Things (IoT) has become a new paradigm that combines physical devices with computing and networking features to form intelligent systems that can accomplish their tasks with minimal human interaction. It is estimated that by 2030, there will be more than 30 billion interconnected IoT devices, which will transfer more than 40 zettabytes of data each year. Nevertheless, this exponential increase has brought surprising cybersecurity issues, and recent evaluations show that over 70% of IoT devices are susceptible to hacking. This review examines the complex security environment of IoT ecosystems, evaluates vulnerabilities at each layer of architecture, explores new threat vectors, and assesses new defense solutions. This paper introduces a systematic review of IoT security issues based on a five-layer architecture and specifically focuses on the vulnerabilities of the network and application layers. It examines the ways in which artificial intelligence, blockchain technology, edge computing, and Zero Trust Architecture will transform IoT security paradigms. This review helps reveal long-standing issues such as resource limitations, device heterogeneity, and scaling challenges through the analysis of actual attack cases and defenses in the field of smart healthcare, industrial IoT, smart cities, and other vital infrastructures. Recommendations on future research directions are then given at the end of the paper with an emphasis on quantum-resistant cryptography, 6G network security, and standardized security frameworks required to construct resilient IoT ecosystems.
Muhammad Sami Intizar, Maria Sikandar, Aqsa Siddique et al.· Journal of Computational and...· 0 citations
Internet of Things (IoT) technologies in the healthcare industry, also known as the Internet of Medical Things (IoMT), have proven to greatly improve patient monitoring, diagnostics, and clinical decision-making. The increasing prevalence of resource-challenged medical devices, wireless connectivity, and cloud services, however, has brought new risks around security and privacy concerns that can now directly impact patient safety and data integrity. In this paper, a thorough study of 41 peer-reviewed research papers from January 2018 through May 2025 revealed the current state of security vulnerabilities and resilience strategies in healthcare IoT systems. It provides a comprehensive analysis of security threats at the device, network, and application levels such as unauthorized access, malware and ransomware, data breaches, and denial-of-service attacks delivered in a systematic manner. This contrasts with existing surveys, which consider single security mechanisms and improve upon various multi-layered security means such as AI-enabled anomaly detection, blockchain-based authentication and auditability, low-compute cryptographic techniques, and privacy-preserving methods such as federated learning. The outcomes also show that although emerging technologies add a great deal of security and trust capabilities, issues on scalability, interoperability, deployment, and regulations are not yet fully addressed. This review highlights important knowledge gaps and offers structured knowledge and future directions for research to address the design of secure, resilient, and practically deployable IoMT architectures for real-world healthcare environments.
M. R. M. Hanan, M. J. A. Sabani· Sri Lankan Journal of Techno...· 0 citations
The Internet of Things (IoT) is transforming industries and daily life by connecting billions of devices, enabling smart homes, cities and industrial systems. This rapid expansion, however, introduces significant cybersecurity vulnerabilities, leaving IoT systems increasingly exposed to both established and emerging attack techniques. This paper presents a structured critical review of IoT cybersecurity, distinguished from prior general surveys by three contributions: first, a cross-layer mapping of named, dated case studies to the specific Security-by-Design principles that would have mitigated them; second, a comparative, feasibility-based evaluation of lightweight cryptographic primitives and blockchain consensus protocols for resource-constrained devices, rather than a descriptive overview; and third, a critical appraisal of the operational limitations of AI-based and blockchain-based defences, including adversarial manipulation, data scarcity and energy cost, set against the claims commonly made for these technologies. We examine the current state of IoT security across the perception, network and application layers; the common vulnerabilities that affect these systems, from insecure device design and weak default credentials to unencrypted communications; and the real-world consequences of these flaws through recent, named case studies, including the Aisuru botnet which is active since 2024 and 2024 vulnerability disclosures affecting Mitsubishi Electric and OMRON industrial controllers. We argue that securing the IoT ecosystem requires sustained, coordinated effort from manufacturers, regulators and end-users, and we identify where current technological and regulatory responses fall short of that goal.
K. Curran, Jack Kyle, Lovepreet Singh· Recent Progress in Science a...· 0 citations
The rapid expansion of the Internet of Things (IoT) has created a heterogeneous attack surface that spans consumer devices, enterprise systems, industrial control networks, and critical infrastructure. Although prior work has examined vulnerabilities within individual domains, there is limited empirical evidence comparing security exposure across operational sectors. This paper presents a cross-sector measurement study of publicly reachable IoT systems in consumer, commercial, industrial, infrastructure, and military environments. Using indexed Internet discovery and controlled non-intrusive vulnerability assessment, we constructed a dataset comprising 424 unique vulnerabilities and 12,366 vulnerability instances across multiple device classes. The analysis evaluates severity distribution, vulnerability categories, and sector-specific exposure behavior, showing that IoT insecurity is not uniform: consumer and commercial environments exhibit high-frequency web and configuration weaknesses, while industrial and infrastructure systems demonstrate fewer but higher-impact vulnerabilities related to control protocols and segmentation. To improve risk prioritization, an Isolation Forest-based anomaly detection model was applied to identify high-risk IoT exposure profiles based on vulnerability density and severity characteristics. The results indicate that IoT risk is primarily shaped by deployment context, highlighting the need for sector-aware defensive strategies and scalable AI-assisted analysis approaches.
Hafiz Munaam Hussain Tariq, Amin Salem Saleh, Tahreem Khan· International Conference on...· 0 citations
The Internet of Things (IoT) has emerged as a transformative technology by enabling billions of interconnected devices to communicate, exchange data, and provide intelligent services across diverse application domains such as healthcare, smart cities, agriculture, industrial automation, and transportation. Despite its widespread adoption, the heterogeneous nature of IoT devices, resource constraints, and the increasing sophistication of cyber-attacks have introduced significant security and privacy challenges. Ensuring the security of IoT environments has therefore become a critical requirement for protecting sensitive data, maintaining service availability, and preserving user privacy. This paper presents a comprehensive review of IoT security by examining recent research trends, fundamental security requirements, major threat environments, and practical security guidelines. The study discusses essential security requirements, including confidentiality, integrity, availability, authentication, authorization, non-repudiation, and data freshness. Furthermore, it analyzes security threats at the device, network, cloud, and application layers and summarizes practical measures for developing secure IoT systems. The paper also highlights recent advancements in lightweight authentication, zero-trust security, artificial intelligence-assisted threat detection, and privacy-preserving techniques that strengthen modern IoT ecosystems. The review provides a concise yet comprehensive overview of IoT security concepts and serves as a useful reference for researchers, practitioners, and students interested in developing secure and reliable IoT applications.
Arul Anitha Dr. A· International Journal of Inn...· 0 citations