ZT-FRL-PLF: A Self-Evolving Zero-Trust Security Framework for Wireless Sensor Networks Using Federated Reinforcement Learning and Physical-Layer Fingerprinting
Keywords:
Wireless Sensor Networks; Zero Trust Architecture; Federated Reinforcement Learning; Physical-Layer Fingerprinting; Intrusion Detection; Self-Healing Networks; Internet of Things Security; PUF AuthenticationAbstract
Wireless Sensor Networks (WSNs) are fundamental pillars of the Internet of Things (IoT) ecosystem, enabling pervasive sensing, monitoring, and actuation across critical domains including smart grids, industrial automation, healthcare, and environmental monitoring. However, the intrinsic resource constraints, open wireless medium, and distributed deployment of WSN nodes expose them to a broad spectrum of cyber threats including Sybil attacks, replay attacks, denial-of-service (DoS), probe attacks, and unauthorized node spoofing. Existing security architectures predominantly rely on perimeter-based trust models that assume internal network legitimacy an assumption fundamentally incompatible with the threat landscape of large-scale WSN deployments.
This paper proposes ZT-FRL-PLF, a novel self-evolving Zero-Trust security framework for WSNs that integrates three synergistic technologies: (i) a Zero Trust Architecture (ZTA) enforcing continuous contextual authentication for every sensor node and communication session, (ii) Federated Reinforcement Learning (FRL) enabling distributed, privacy-preserving intrusion detection across sensor clusters without centralizing raw data, and (iii) Physical-Layer Fingerprinting (PLF) exploiting inherent hardware imperfections carrier frequency offset (CFO), RSSI drift, in-phase/quadrature (I/Q) imbalance, phase noise, and Physical Unclonable Function (PUF) responses to authenticate sensor nodes at the radio frequency level. A trust-weighted federated aggregation mechanism dynamically adjusts the influence of each sensor cluster based on a reinforcement learning reward signal that jointly optimizes detection accuracy, energy efficiency, and spoof-resistance. A self-healing decision engine automatically classifies network actions into ALLOW, REROUTE, or ISOLATE categories based on a composite zero-trust risk score.
Through extensive experimentation using the KDD Cup 99 intrusion detection data set (50,000 instances, 41 attributes), it is evident that ZT-FRL-PLF provides an impressive detection performance rate of 99.21%, 99.37% precision, 99.18% recall, 99.27% F1 score, and a minimum false alarm rate of 0.89%, which outperforms all existing baseline approaches, including conventional trust-based models, traditional machine learning based IDS, and blockchain technology security schemes. Moreover, the proposed approach offers enhanced network lifetime (1020.4 units) and low energy utilization (0.98 energy index units) relative to other energy-intensive blockchain techniques (1.95 energy index)..