IoT Network Traffic Analysis for User Behavior Mapping and Adaptive Privacy Risk Mitigation.

Show simple item record

dc.contributor.author Dissanayake, T.D.
dc.contributor.author Fernando, S.A.D.S.
dc.contributor.author Duwarahavidyan, J.
dc.contributor.author Bandara, W.M.T.H.
dc.contributor.author Sudheera, K.L.K.
dc.date.accessioned 2026-09-08T03:48:28Z
dc.date.available 2026-09-08T03:48:28Z
dc.date.issued 2026-03-04
dc.identifier.citation Dissanayake, T. D., Fernando, S. A. D. S., Duwarahavidyan, J., Bandara, W. M. T. H. & Sudheera, K. L. K. (2026). IoT Network Traffic Analysis for User Behavior Mapping and Adaptive Privacy Risk Mitigation. 23rd Academic Sessions & Vice – Chancellor’s Awards, Faculty of Engineering, University of Ruhuna, Sri Lanka. 87. en_US
dc.identifier.issn 2362-0412
dc.identifier.uri http://ir.lib.ruh.ac.lk/handle/iruor/21730
dc.description.abstract The recent rise of Internet of Things (IoT) devices has raised significant concerns about user privacy, as these devices may unknowingly expose sensitive information to third parties. Since smart devices continuously communicate over a network, they generate unique traffic patterns that can be passively captured by an attacker without the user’s knowledge. Although this traffic is encrypted, it can still reveal device identities and user behaviors within the environment. This study investigates how network traffic can be analyzed to identify specific IoT devices and how detected device triggers can be mapped to meaningful user actions under realistic deployment conditions. Accordingly, we propose a novel four-stage methodology to address this challenge. First, we introduce a Retrieval-Augmented Generation (RAG) based device fingerprinting approach that supports open-set recognition and enables identification of previously unseen devices. Second, we implement a hybrid device trigger detection method that combines a rule-based system with a Long Short-Term Memory (LSTM) approach to improve reliability under practical constraints. Third, sequences of detected triggers are mapped to user behaviors using a prompt-engineered Large Language Model (LLM) framework capable of inferring complex activities without reliance on fixed training datasets. Furthermore, we evaluate and propose privacy-preserving mitigation techniques that conceal genuine user behavior within realistic fake behaviors through adaptive traffic obfuscation, increasing attacker uncertainty rather than attempting to fully block inference. To support experimentation and evaluation, two practical testbeds are deployed for data collection and validation, and a user-friendly web application integrates the full pipeline into an accessible interface. Overall, this work provides practical insights into privacy risks in smart environments and demonstrates effective, deployable strategies for mitigating behavior inference from encrypted IoT traffic. en_US
dc.language.iso en en_US
dc.publisher Faculty of Engineering , University of Ruhuna, Sri Lanka. en_US
dc.subject Behavior inference en_US
dc.subject Device fingerprinting en_US
dc.subject Encrypted traffic analysis en_US
dc.subject IoT privacy en_US
dc.subject Passive sniffing en_US
dc.title IoT Network Traffic Analysis for User Behavior Mapping and Adaptive Privacy Risk Mitigation. en_US
dc.type Article en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Browse

My Account