Skip to main navigation Skip to search Skip to main content

Middleware Architecture for the Management and Mitigation of OWASP ML05: Model Theft in IoT Machine Learning Networks

  • Julio Yair Rivera
  • , Ángel Pinto
  • , Nelson A. Pérez García
  • , Monica Karel Huerta
  • , Cesar Viloria Nuñez
  • , Marvin Luis Pérez Cabrera
  • , Frank Ibarra Hernández
  • , Juan Torres Tovio
  • , Erwin J. Sacoto-Cabrera

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The increasing integration of machine learning (ML) models into Internet of Things (IoT) applications has led to notable advancements in automation and decision-making. However, these models are vulnerable to modern attack vectors recognized by the OWASP Top 10 for Large Language Model Applications, specifically ML05: Model Theft, where adversaries gain unauthorized access to model parameters and training data, compromising intellectual property and sensitive information. Such threats are particularly concerning in IoT environments due to their distributed nature and resource limitations. This paper proposes a middleware architecture for the management and mitigation of model theft risks by incorporating encryption, access control, obfuscation, watermarking, continuous monitoring, and service assurance programmability. By strengthening the security management framework of ML models deployed in IoT, the proposed architecture aims to protect against theft, ensure data confidentiality, and maintain network resilience. The approach includes detailed mathematical models and an evaluation of existing security measures, demonstrating the architecture's effectiveness in diverse IoT deployments, such as telemedicine and smart cities.

Original languageEnglish
Title of host publicationTEMSCON Global 2025 - 2025 IEEE Technology and Engineering Management Society Conference - Global, Conference Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331542740
DOIs
StatePublished - 2025
Event2025 IEEE Technology and Engineering Management Society Conference - Global, TEMSCON Global 2025 - San Diego, United States
Duration: 4 Aug 20257 Aug 2025

Publication series

NameTEMSCON Global 2025 - 2025 IEEE Technology and Engineering Management Society Conference - Global, Conference Proceedings

Conference

Conference2025 IEEE Technology and Engineering Management Society Conference - Global, TEMSCON Global 2025
Country/TerritoryUnited States
CitySan Diego
Period4/08/257/08/25

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 11 - Sustainable Cities and Communities
    SDG 11 Sustainable Cities and Communities

Keywords

  • Cybersecurity
  • IoT
  • Middleware Architecture
  • Model Theft
  • OWASP ML05:2023

Cite this