
Bare-metal embedded systems, such as ARM Cortex-M4-based devices, are vulnerable to attacks such as buffer overflows due to the lack of operating system protection. This paper presents a novel approach for detecting standard C library functions -such as memcpy, memset, strncat-that are susceptible to such vulnerabilities by analyzing micro-architectural instruction traces. We propose machine learning pipelines, including CNN-, LSTM-, and autoencoder-based detectors. Our approach uses data pre-processing techniques, such as sliding windows with varying stride are employed to optimize classification accuracy. Evaluating the algorithm with 25 custom workloads simulating common weaknesses (e.g., CWE-120, CWE-126) shows 93.89% TPR, 73.19% TNR, 26.81% FPR, and 6.11% FNR. This work advances IoT security by enabling online and real-time vulnerable function identification supporting zero-day attack detection. This goes beyond existing techniques targeting only higher-level platforms.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
