Publication:
Integrating physical unclonable functions with machine learning for the authentication of edge devices

Date

2026

Authors

Abdul Manan, Sheikh

Journal Title

Journal ISSN

Volume Title

Publisher

Kuala Lumpur : Kulliyyah of Engineering, International Islamic University Malaysia, 2026

Subject LCSH

Internet of things -- Data processing
Internet of things -- Security measures
Edge computing -- Security measures

Subject ICSI

Call Number

et TK 5105.8857 A1364I 2026

Research Projects

Organizational Units

Journal Issue

Abstract

The rapid growth of the Internet of Thing (IoT) has increased the demand for lightweight and robust hardware security mechanisms. Physical Unclonable Functions (PUFs) have emerged as promising hardware security primitives for device authentication, cryptographic key generation, and counterfeit prevention by leveraging intrinsic manufacturing process variations. Their capability for on demand cryptographic key generation eliminates the requirement for persistent key storage, thereby enhancing security against key extraction and tampering. However, PUF responses are often affected by environmental noise, voltage fluctuations, and device aging, which can compromise their reliability and randomness. Furthermore, recent advances in Machine Learning (ML) have demonstrated the ability to model and predict Challenge–Response Pairs (CRPs) of conventional strong PUFs, posing significant security risks. PUFs can be implemented in Application-Specific Integrated Circuits (ASICs) or, at lower cost, in Field-Programmable Gate Arrays (FPGAs). FPGAs are widely used in IoT and embedded systems due to their programmability, partial reconfigurability, and faster time-to-market. This research presents the design, implementation, calibration, and evaluation of FPGA-based PUFs aimed at improving robustness against environmental variations and ML modeling attacks. Both Arbiter PUFs (APUFs) and Ring Oscillator (RO) PUFs were implemented on an Intel Altera Cyclone IV-E FPGA, with CRPs extracted in real time using a logic analyzer. To mitigate noise and improve consistency, PUF CRPs were processed using whitening and hashing techniques. The performance of the proposed PUFs was evaluated using key metrics including reliability, uniqueness, randomness, and correctness. Randomness was validated through the NIST Statistical Test Suite (STS), while reliability was assessed under variations in temperature, voltage, and device aging. The study also explores the synergy between Artificial Intelligence (AI) and PUFs for IoT security. AI enhances edge computing security through advanced threat detection, automated responses, and optimized resource management. More than 900,000 CRPs were collected for both APUF and RO PUF and evaluated using key metrics including randomness, reliability, and uniqueness. The APUF demonstrated near ideal characteristics with high entropy, reliability (97.99%), and uniqueness (49.99%), while the RO PUF showed similarly strong statistical quality and robustness with reliability of 98.01% and uniqueness of 49.99%. Machine learning resistance was assessed using Logistic Regression (LR), Random Forest (RF), Gradient Boosting (GB), and MultiLayer Perceptron (MLP) models. For APUF, LR and GB achieved low prediction performance (around 61%), whereas RF and MLP attained high accuracies up to 97%, reflecting their ability to model complex PUF behaviour. The higher prediction accuracy observed for complex models such as MLP and RF can be advantageously interpreted from an anomaly detection perspective, rather than purely as a weakness. In contrast, RO PUF prediction accuracies remained close to random guessing (below 50%), confirming strong resistance against learning based attacks and high robustness of the CRP data. Moreover, when integrating PUFs into existing FPGA architectures, design compatibility, required modifications, and interactions with other system functions must be carefully considered. These factors highlight the importance of robust design strategies to ensure reliable and scalable PUF implementations for practical hardware security applications.

Description

Keywords

Citation