Edge AI for Cybersecurity
Graduate research into edge anomaly detection using compact state-space models with larger reasoning systems operating centrally.
The question
Can security systems detect meaningful anomalies close to where data is produced, while reserving larger reasoning systems for the context-heavy decisions they are better suited to make?
Constraints
Edge environments have real limits: compute, memory, power, bandwidth, intermittent connectivity, and a high cost for false alarms. Any useful design must treat those constraints as core architecture inputs.
Research approach
The thesis explores compact state-space models for local temporal signals and a tiered architecture that escalates only the evidence requiring broader context. Evaluation focuses on detection quality, latency, resource use, and operational usefulness.
Why the architecture matters
The edge and the center should not compete. A good system lets each layer do the work it handles best, reducing data movement while preserving the ability to investigate and explain significant events.
Next steps
Current work is refining datasets, evaluation criteria, and the boundary between local detection and central reasoning. Results will be published as the experiments become defensible.
Have a related problem?
Work with me