Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions ESİN ECE AYDIN, , Cyber Security and Privacy Research Lab., SPFLab, Department of Computer Engineering, Istanbul Technical University, Türkiye
ŞERİF BAHTİYAR, , Cyber Security and Privacy Research Lab., SPFLab, Department of Computer Engineering, Istanbul Technical University, Türkiye
arXiv:2609.24669v1 [cs.CR] 21 Sep 2026
GÜRKAN GÜR, , Zurich University of Applied Sciences (ZHAW), Institute of Computer Science (InIT), Switzerland Providing autonomous intelligence, pervasive connectivity and usability to human life and industry has led to the emergence of the Internet of Things (IoT). To support time-sensitive and resource-constrained applications, IoT systems nowadays increasingly rely on edge computing. This brings computation and decision-making closer to end devices. In edge-enabled IoT architecture, latency and communication overhead are reduced, but interactions among a larger and more diverse set of devices, edge nodes, services, and data sources are introduced as well. In such environments, security and privacy mechanisms provide the foundation for protection, while trust management can assess the reliability of interacting entities and adapting secure decisions. In this paper, we systematically review the current state of trust management in edge-enabled IoT. To this end, we propose a comprehensive taxonomy that maps physical, network, and application architectural IoT layers against the consumer, commercial, industrial, and infrastructure IoT domains. We further investigate state-of-art research based on their trust design, how trust integrated into secure IoT operations, the attacks that effect trust management process. Based on these findings, we identify key gaps in current research and outline future directions for context-aware and adaptive trust management in edge-enabled IoT. CCS Concepts: • General and reference → Surveys and overviews; • Security and privacy → Trust frameworks; Security requirements. Additional Key Words and Phrases: security, trust management, Internet of Things (IoT), IoT attacks, review ACM Reference Format: ESİN ECE AYDIN, , ŞERİF BAHTİYAR, , and GÜRKAN GÜR, . 2026. Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions. 1, 1 (September 2026), 34 pages. https://doi.org/10.1145/nnnnnnn.nnnnnnn
1
Introduction
Security and privacy have long been central pillars of research in networked systems. However, securing IoT operations introduces unique challenges that security and privacy alone do not fully address, including reliable data exchange, dependable service provision, and context-aware decision-making [20, 46]. Modern IoT ecosystems no longer consist of just Internet-connected devices. Instead, IoT entities form dynamic relationships with neighboring devices, edge Authors’ Contact Information: ESİN ECE AYDIN, , Cyber Security and Privacy Research Lab., SPFLab, Department of Computer Engineering, Istanbul Technical University, Istanbul, Türkiye, [email protected]; ŞERİF BAHTİYAR, , Cyber Security and Privacy Research Lab., SPFLab, Department of Computer Engineering, Istanbul Technical University, Istanbul, Türkiye, [email protected]; GÜRKAN GÜR, , Zurich University of Applied Sciences (ZHAW), Institute of Computer Science (InIT), Winterthur, Switzerland, [email protected]. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]. © 2026 Copyright held by the owner/author(s). Publication rights licensed to ACM. Manuscript submitted to ACM Manuscript submitted to ACM
1
2
Aydin et al.
servers, cloud services, and autonomous applications. These heterogeneous entities continuously exchange information and rely on one another to complete distributed tasks and provide seamless services. Furthermore, next-generation IoT ecosystems are fundamentally characterized by the integration of edge AI. In this decentralized deployment, intelligence is distributed across edge and end devices rather than being centralized in the cloud. By this change, privacy and security enforcement are also distributed across heterogeneous edge and end nodes [18, 35]. However, they do not by themselves determine with whom an entity should interact, whose data or services should be relied upon, or how much autonomy should be granted in day-to-day IoT operation. Therefore, trust emerges as an equally critical third dimension. According to [11], trust enables IoT systems to assess the reliability of relationships between things and realize the full potential of their interactions. From consumer-related ones to infrastructure-wide IoT applications, integrating trust mechanisms is an important aspect for the successful operation of IoT. Besides, as stated in [118], trust assessment can make a substantial impact on the overall security of IoT systems. In edge-enabled IoT, trust management are not centralized: models, training data, and score updates can be evaluated by end nodes themselves. This enables privacy-preserving decisions, reduced latency and bandwidth usage. However, local decision making and cross-layer collaboration become important design issues in trust management of next-gen IoT as mentioned by [94]. Although trust is recognized as a one of the fundamental requirements for reliable IoT operation [20, 83], currently, trust remains is an abstract concept without a widely accepted definition. The literature offers a wide spectrum of definitions: ranging from subjective confidence and probabilistic behavioral belief [2, 70, 80, 124], to reputation-based and QoS-driven trustworthiness [40, 118], and to multi-dimensional, context-aware, or AI-predicted trust [16, 20, 78, 94, 99]. The literature lacks a consistent view of whether trust concerns devices, data, services, or all three, resulting in fragmented methodologies and inconsistent evaluation. This survey addresses this gap by examining trust in conjunction with security and privacy. It examines the definition of trust in the literature, the processes of trust management, and its integration into IoT operations to improve resilience, robustness, and secure decision-making. This survey is structured around the following research questions: • RQ1 – How is trust management in edge-enabled IoT characterized across application domains, architectural layers, and trust targets (device, data, and service), and what recurring design patterns emerge in trust management? • RQ2 – How do reviewed schemes use trust scores to drive IoT operational decisions, and trust-related attacks, including routing, reputation, data-integrity, and identity-related threats are targeted? • RQ3– What research gaps remain in IoT trust management, and what future research directions are needed for scalable and resource-efficient trust mechanisms, adversary-aware and attack-adaptive models in emerging IoT environments including edge-enabled, agent-based, immersive, and physically–virtually coupled deployments? 1.1
Existing Surveys
We compare eighteen recent survey papers published between 2019 and 2026 with our work, as given in Table 1. The comparison covers several aspects of trust management. Trust target indicates trust subjects each survey focuses. Trust design taxonomy indicates whether the survey provides a structured trust-management design, including evidence acquisition, trust modeling, dissemination, and maintenance. Operational roles of trust capture how trust is used in practice to support IoT decisions, such as access control, secure routing, intrusion detection, service selection, or data aggregation. Trust attack analysis indicates whether trust-related attacks are systematically identified and analyzed. The last one, architecture scope, gives the IoT deployment targeted by each survey. Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
3
Table 1. Comparison of Existing Surveys on Trust Management in IoT with Our Work Survey
Year
Xu et al. [134] Wang et al. [127] D’Aniello & Fotia [29] Jmal et al. [50] Kamble et al. [51] Sagar et al. [99] AlMarshoud et al. [13] Tyagi et al. [117] Shirvani & Masdari [105] Aaqib et al. [1] Lenard et al. [65] Alhandi et al. [11] Wang et al. [123] Konsta et al. [57] Muzammal et al. [82] Marche & Nitti [76] Pourghebleh et al. [90] Najib et al. [83]
2026 2026 2025 2025 2024 2024 2024 2023 2023 2023 2023 2023 2022 2022 2021 2020 2019 2019
Our work
2026
Trust Design
Operational
Trust Attack
Architecture
Device
Trust Targets Data
Service
Taxonomy
Roles of Trust
Analysis
Scope
✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
✓ ∼
∼ ∼ ∼ ✓
✓ ✓ ∼ ∼ ✓ ✓ ✓ ✓ ∼ ✓ ✓ ✓ ✓ ✓ ✓ ∼ ∼ ✓
∼
✓ ✓
Edge-Enabled IoV Distributed IoV Edge-Enabled IoT SIoT General IoT SIoT Decentralized IoV WSN-Based IoT General IoT General IoT Distributed IoT WSN-Based IoT Heterogeneous IoT Edge-Enabled IoT General IoT SIoT General IoT General IoT
✓
✓ ∼ ✓ ∼ ∼ ✓ ∼ ∼ ✓
∼ ∼ ✓
✓ ✓
✓
✓
✓ ✓ ✓ ∼
✓ ∼ ✓ ∼ ✓ ∼
∼ ∼
✓ ∼ ✓ ∼ ✓ ✓ ∼
✓
✓
✓
Edge-Enabled IoT
✓ = explicitly covered, ∼ = partially covered, blank = not covered
Across all the surveys examined, device trust is the only target treated consistently. This reflects that IoT trust management has device-centric model, where IoT nodes, sensors are evaluated for their trustworthiness. While a few recent surveys have begun to expand their scope such as [11, 82, 90, 105] including data trust, and [50, 76, 99] focusing on service trust which is unsurprising given their focus on Social IoT and service recommendation or selection. To the best of our knowledge, no prior survey paper covers all three trust targets; the closest cases are the review by [82, 123, 127, 134], however, they still address one or two of the remaining trust targets only partially. According to [99], trust management schemes are categorized into recommendation-based, reputation-based, prediction-based, and policy-based groups. However, this classification combines two different aspects into a single taxonomy: recommendation and reputation-based schemes describe the source of trust evidence, whereas prediction and policy-based schemes describe how trust is computed. Since these dimensions are independent, a single scheme may belong to multiple categories simultaneously. Therefore, in this survey, trust evidence sources and trust computation mechanisms are treated as separate dimensions. [1, 83] classify trust models across a broad architectural scope, ranging from centralized to distributed IoT systems. However, these surveys do not analyze the operational roles of trust or trust-related attacks. [82, 90] provide more detailed discussions of trust computation methods and adversarial threats. [51] frames trust management as a core enabler of secure IoT applications across five main domains: agriculture, education, healthcare, home security, and transportation. The authors further organize prior work using a five-part taxonomy, including trust measures (QoS, social-based trust), trust circulation (centralized, distributed), trust algorithms (fuzzy logic, machine learning, Bayesian methods, entropy-based models, regression), trust generation (single, multi attribute), and highlighting trust-related attacks. However, the study lacks an evaluation of the operational roles of trust within IoT systems. While [105] categorizes the operational roles of trust, it does not offer any taxonomy for trust management design, and it omits giving any structure how trust is addressed in state-of-the-art approaches. Edge-enabled IoT architectures are examined in [29, 57, 134] where trust is maintained distributed across devices, Manuscript submitted to ACM
4
Aydin et al.
fog/edge nodes, and cloud rather than confined to a centralized structures. They emphasize decentralized mechanisms such as blockchain, and edge-local reputation. [57] reviews state-of-the-art approaches together with the threat models. The authors categorize 53 papers and evaluate each one on seven dimensions: information gathering, trust formation, propagation and update, threat model, experiments, and simulator. Different taxonomies are suggested based on layers, deployment modes, algorithms, or enabling technologies. However, the taxonomies in [29, 50, 76, 90, 105] remain incomplete with respect to the full trust lifecycle. 1.2
Contributions & Paper Organization
Building on the the research questions outlined in Section 1 and comparison in Table 1, this survey makes the following contributions: • We present a systematic literature review of trust-management techniques in edge-enabled IoT and classify the selected studies. We use a taxonomy that maps each study across IoT layers and four application domains: consumer, commercial, industrial, and infrastructure IoT. • We provide an analysis of trust-related attacks by relating adversarial objectives, attacker behavior patterns, and affected stages of the trust-management process. We further examine how trust-management outputs are used to inform decisions and trigger actions within IoT systems. • We identify key research challenges in building trustworthy edge-enabled next-generation IoT. Then, we outline possible future research directions. The remainder of this paper is organized as follows. First, Section 2 provides background, gives definitions, and explains trust management process along the trust components. Next, Section 3 presents the systematic review methodology we follow for comparative analysis. Then, representative state-of-the-art frameworks are analyzed and discussed in Section 4. Section 5 discusses open research challenges, including architectural, trust-model, adversarial, and ecosystem barriers, and outlines future directions. Finally, Section 6 concludes the paper. 2
Trust, Security and Privacy Foundations in IoT
Security in IoT concerns protecting devices, communication channels, and services against unauthorized access, manipulation, and disruption with confidentiality, integrity, and availability as its core objectives. However, IoT deployments are heterogeneous, resource-constrained, and large-scale which makes conventional security mechanisms difficult to apply [26]. Static and heavyweight cryptographic protocols suffer from significant latency [27, 32], energy consumption [19], and may be vulnerable in key management [32]. As a result, IoT security research seeks lightweight protection and detection mechanisms. The central challenge in this landscape is the transition from perimeter security to zero-trust models, where every entity must continuously prove its integrity and trustworthiness. Privacy encompasses protecting user identity, preventing personal inferences, and ensuring regulatory compliance. IoT devices continuously collect data about individuals, environments, and activities, often without the user’s explicit knowledge. Consequently, privacy risks arise. Protection mechanisms such as data anonymization, differential privacy, encryption, and access control can be used to limit exposure. However, deploying these in IoT requires careful consideration. For example, when IoT systems are deployed by static role-based policies, access rights cannot adapt as IoT environment changes. Besides, cryptography also poses challenges in key lifecycle management. Informed consent, data ownership, and accountability become harder to sustain across multi-party, cross-layer data flows. Accordingly, recent research integrates trust-based differential-privacy-based mechanisms [86], federated learning (FL) for sensitive Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
5
data [55], and privacy-preserving access control [37]. The central challenge in this landscape is the transition from data secrecy to context-aware privacy preservation in order to balance data utility with user privacy. 2.1
IoT System Characteristics
Securing IoT deployments is inherently difficult: devices are heterogeneous and resource-constrained, adversaries may be external or already authenticated, and privacy must be preserved while data is continuously sensed, transmitted, and processed. The literature characterizes IoT systems along several complementary dimensions. IoT systems are commonly described through functional layers. These are typically physical (perception), network, and application layers [11, 57, 109, 117], with extended variants with processing or transport layers [20]. IoT systems can also be characterized by the location of sensing, computation, and decision-making along the device–edge–fog–cloud continuum. These are device-level [61, 116], edge-level, fog-level [92], cloud-level [59] and device–edge–cloud combinations [29, 78, 108, 110]. Third, IoT systems can be further distinguished by their application domains. In order to reflect requirements of the deployed systems, these could be consumer, enterprise, commercial, industrial, or military application domains. For example, [85] investigates IoT application domains under two: critical IoT and massive IoT. Additional dimensions could be the organizational architecture of IoT entities, such as centralized, hierarchical, or peer-to-peer structures, as well as node mobility, ranging from static infrastructure to mobile vehicular and aerial networks [22, 28, 142]. For this survey paper, we consider edge-enabled IoT architectures based on a three-layer model and four types of application domains, as presented in Figure 1. We divide IoT application domains by end-user and market as Businessto-Consumer (B2C) and Business-to-Business (B2B). The B2C segment includes consumer IoT which encompasses devices and ecosystems designed for direct use by individuals to improve quality of life, convenience, and personal wellness. The B2B segment is significantly more diverse, focusing on enterprise-level applications where IoT is deployed to optimize processes, reduce costs, and manage assets. It includes commercial, industrial, and infrastructure IoT. CONSUMER IoT
COMMERCIAL IoT
INDUSTRIAL IoT
INFRASTRUCTURE IoT
smart home
smart retail
smart factory
smart city
wearables
smart office
mining
smart grid
healthcare
smart building
oil & gas
smart transport
Application Layer
Wi-Fi (Wi-Fi 7) & Ethernet, Bluetooth LE 5 / Thread / Zigbee (short-range mesh), Cellular: 4G / 5G + RedCap (wide-area) LPWAN: LoRaWAN / NB-IoT / LTE-M, Satellite IoT (LEO) (remote / global coverage) Gateways, routers & edge / MEC nodes, IoT protocols: MQTT 5 / CoAP / HTTPS-QUIC, Security stack: TLS 1.3, zero-trust
Network Layer
Cameras & LiDAR (vision / depth), Radar — mmWave, Environmental sensors (MEMS: temperature, humidity, air quality), Wearable / bio-sensors (heart rate, motion, glucose), RFID & UWB tags (identification & localization), GPS / multi-band GNSS, Actuators & smart appliances (locks, valves, relays), MCUs with TinyML / edge AI (on-device intelligence)
Physical Layer
Fig. 1. Three-Layer Model of IoT Systems Across Consumer, Commercial, Industrial, and Infrastructure Domains
2.2
Trust in IoT
The trust landscape defines who can securely and reliably operate on behalf of whom, encompassing trust in devices, the data they produce, and the services that act upon that information. It determines not only who is allowed to participate Manuscript submitted to ACM
6
Aydin et al.
in the system, but also how much autonomy each participant is granted under varying conditions. Many researchers associate trust management solely with social IoT environments [62, 73, 79, 84]. In reality, devices in all IoT systems depend on many others for data and services. A well-known example of this occurred in February 2020 when Simon Weckert artificially created a virtual traffic jam on Google Maps by transporting 99 smartphones in a wheelbarrow [76]. Although not a conventional IoT deployment, this incident shows how untrusted data can propagate through a system and lead to incorrect operational decisions. To better understand trust in IoT operations, it is first necessary to establish key trust-related definitions and then examine how trust management is performed in IoT systems. Trust management schemes identify three participant roles: the trustor, who evaluates and holds trust; the trustee, whose trustworthiness is assessed; and the recommender, who supplies indirect evidence about a third party [56]. These roles provide the basis for defining the key concepts underlying trust assessment in IoT. We additionally use the following definitions: Definition 1: Trustworthiness refers to the degree to which a trustee exhibits observable qualities such as reliability, integrity, competence, and benign behavior. [114] further incorporates factors such as capacity, energy, performance, and cost. In general, trustworthiness denotes the inherent properties of the trustee that justify a given trust assessment. Definition 2: Trust is the quantitative or qualitative measure of the confidence that a trustor 𝑎 places in a trustee 𝑥 to behave as expected over interval [𝑡 0, 𝑡]. Formally, we can define trust as in Equation 1 where 𝐸𝑎 (𝑥) denotes the trust evidence available to 𝑎, and 𝑓 (·) is the trust evaluation function. 𝑇𝑎 (𝑥 | 𝑡) = 𝑓 (𝐸𝑎 (𝑥)) ,
(1)
Definition 3: Device trust is the value 𝑇𝑎 (𝑥 | 𝑡) ∈ [0, 1] by which trustor 𝑎 expresses confidence that trustee device 𝑥 will operate benignly up to time 𝑡, computed from evidence 𝐸𝑎 about 𝑑’s behavioral history, operational integrity, and adherence to expected node-level functions. Definition 4: Data trust is the graded confidence 𝑇𝑎 (𝑥 | 𝑡) by which trustor 𝑎 judges that trustee data 𝑥 is reliable for use, based on evidence 𝐸𝑎 (𝑥) about its accuracy, integrity, or freshness. Definition 5: Service trust is the graded confidence 𝑇𝑎 (𝑥 | 𝑡) by which trustor 𝑎 judges that service 𝑥 ∈ S𝑥 (all services of a specific IoT device) will deliver its advertised functionality correctly, completely, and within agreed quality-of-service over interval [𝑡 0, 𝑡], without malicious or negligent behavior, based on service-specific evidence 𝐸𝑎 (𝑥). Definition 6: A trust relationship is a measurable, subjective, and transferable association [136] between a trustor and a trustee, representing the trustor’s context-dependent confidence in the trustee. Definition 7: Trust-related attacks are a class of adversarial strategies in which malicious entities deliberately manipulate the inputs, computation, or dissemination of trust scores to subvert the trust management system itself. Unlike conventional network attacks that target data or availability, trust poisoning attacks manipulate or corrupt the evidence upon which trust assessments are built. In order to develop trust relationships and protect against adversarial behaviors and cyber-physical attacks, trust must be managed continuously. Figure 2 illustrates the conceptual workflow of trust management process in IoT. Trust management begins with evidence acquisition, in which a trustor may collect device, data, and service related information that serve as inputs to trust assessment. These evidences are then processed during evidence aggregation, where an initial trust value is formed, direct and indirect evidence may be aggregated, and normalized. After that, a trust modeling technique (rule-based, probabilistic, ML, or blockchain-assisted) computes a trust value per targets in trust computation step. Subsequently, trust distribution determine where trust is calculated, stored, and shared across the network. For example, at an edge device these trust values can be stored and how updated values are propagated to Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
7
other entities. Trust scores can be then used by IoT end devices, edge nodes or cloud/data center to support decisions in IoT operations such as routing, access control, service selection, and intrusion detection. Finally, in trust maintenance trust scores are updated after new interactions or elapsed time.
Trust Evidence Acquisition
Evidence Aggregation
Trust Computation
Different Trust Representations:
DEVICE TRUST
●
Acquisition Methods: Direct Observation Indirect Recommendation
Collect Evidences about IoT Entities
DATA TRUST
○,○
Dissemination Models: Decentralized Distributed Centralized
SERVICE TRUST Aggregate & Normalize Heterogeneous Evidence
Trust Maintanence
Trust Distribution
Trigger Trust Updates Decay Outdated Trust Values
Disseminate Trust Information
Compute Trust per Targets
Evidence Flow
IoT End Devices
Edge Devices
Cloud/Data Center
Trust Flow Trust-Driven Decision Flow Process Flow
Fig. 2. Conceptual Trust Management Process
Most IoT trust management frameworks follow a common process, as illustrated in Figure 2. Before discussing current frameworks, it is important to briefly discuss some important components of this process. 2.2.1 Trust Evidence Acquisition. It is a process that an IoT system uses to gather information about IoT entities. Some surveys distinguish single and multi attribute evidence collection [11, 51, 57, 99]. We omit this distinction because most state-of-the-art frameworks use multiple attributes; instead we classify evidence acquisition by source: direct or indirect. Direct evidence refers to trust information based on an assessing entity 𝑎’s first-hand observations of a target 𝑥, which may be a device, data item, stream, or service. Let 𝜏 (𝑥) ∈ {device, data, service} denote the trust target type of 𝑥. Direct evidence is represented by a pair of positive and negative outcomes, (𝑝𝑎,𝑥 , 𝑛𝑎,𝑥 ), and a vector of normalized metrics (ℓ ) (1) (𝐿) 𝑚𝑎,𝑥 = (𝑚𝑎,𝑥 , . . . , 𝑚𝑎,𝑥 ), where each 𝑚𝑎,𝑥 ∈ [0, 1]. The direct trust score is then computed uniformly as in Equation 2
where Φ(·) is an aggregation function whose inputs are interpreted according to 𝜏 (𝑥). 𝑇𝑑 (𝑎, 𝑥) = Φ 𝑝𝑎,𝑥 , 𝑛𝑎,𝑥 , 𝑚𝑎,𝑥 ; 𝜏 (𝑥)
(2)
In practice, this reduces to either a success ratio as shown in Equation 3: 𝑇𝑑 (𝑎, 𝑥) =
𝑝𝑎,𝑥 𝑝𝑎,𝑥 + 𝑛𝑎,𝑥
(3)
or a weighted metric combination as given in Equation 4: 𝑇𝑑 (𝑎, 𝑥) =
𝐿 ∑︁ ℓ=1
(ℓ ) 𝜔 ℓ (𝜏 (𝑥)) · 𝑚𝑎,𝑥 ,
𝐿 ∑︁
𝜔 ℓ (𝜏 (𝑥)) = 1
(4)
ℓ=1
Direct evidence can be further divided into two forms, as shown in Figure 5: experience and observations. Nodes’ direct interactions with each other provide experience-based evidence, such as recording the number of successfully forwarded packets relative to failed ones [87]. Observation-based evidence, on the other hand, is obtained through monitoring or overhearing interactions between other nodes. Direct evidence acquisition is generally considered more Manuscript submitted to ACM
8
Aydin et al.
objective observation from the perspective of an IoT node. It is less dependent on other’s subjective observations, therefore it is less vulnerable to trust poisoning attacks. Although indirect evidence is more susceptible to trustpoisoning attacks, it becomes essential when direct interactions are unavailable. In such cases, trust is inferred from recommendations or reputation (consensus). Recommendations represent evaluations shared by neighboring nodes regarding the reliability of a target entity [76]. In contrast, reputation (consensus) aggregates trust opinions from multiple nodes into a community-level score. However, its effectiveness depends on the credibility of obtained trust value [136] and recommenders [5]. The set of all indirect source can be denoted as R𝑥 , and each source 𝑟 providing opinions about target 𝑥. 𝑚𝑟 (𝑥) ∈ [0, 1] denotes the normalized trust opinion that 𝑟 contributes about 𝑥. Indirect trust can be computed as in Equation 5 where 𝜔𝑟 ∈ [0, 1] is the credibility weight assigned to source 𝑟 : Í 𝑟 ∈ R𝑥 𝜔𝑟 𝑚𝑟 (𝑥) Í 𝑇𝑟 (𝑥) = 𝑟 ∈ R𝑥 𝜔 𝑟
(5)
In hybrid trust evidence acquisition models, direct and indirect evidence are combined to obtain an aggregated trust score. The trust that assessing entity 𝑎 assigns to target 𝑥 is commonly computed as a weighted combination [120] where 𝛼 ∈ [0, 1] controls the relative influence of direct versus indirect evidence: 𝑇 (𝑎, 𝑥) = 𝛼 · 𝑇𝑑 (𝑎, 𝑥) + (1 − 𝛼) · 𝑇𝑟 (𝑥)
(6)
This hybrid formulation is motivated by a common limitation of IoT deployments: direct evidence is often incomplete, intermittent, or outdated by the time a stable trust estimate can be formed. IoT nodes try to collect signals related to competence, honesty, and security [17]. However, building a reliable interaction history remains a significant challenge [77]. When first-hand interaction history is limited, schemes typically reduce weight 𝛼 and rely more heavily on recommendations or reputation [39, 103]; as sufficient direct observations accumulate, 𝑇𝑑 (𝑎, 𝑥) is given greater weight and dependence on potentially unreliable indirect sources is reduced. On the other hand, another challenge is that IoT environments often change faster than the evidence base used to support trust decisions [55, 137]. Sparse interactions therefore yield insufficient evidence for stable trust relationships. To compensate, some studies incorporate interaction intensity as an additional trust parameter [102], while [76] introduces a relationship component that assigns the highest value to directly connected entities and, for indirect pairs, derives trust from the weakest link along the available social path. However, if sufficient direct observations and trustworthy recommendations are both unavailable, many existing schemes simply assign a default initial trust score to previously unknown entities, which may lead to inaccurate trust decisions during early interactions [47]. 2.2.2 Trust Computation. Trust computation maps aggregated evidence to a trust value for a given target, such as a device, data, or service. In the state-of-the-art, there are many families of computation methods, each differing in how evidence is interpreted, combined, and converted into a trust value. Rule-based and weighted-sum models combine selected trust inputs using predefined rules, weights, thresholds, or ranking methods. They are generally lightweight and interpretable, but their effectiveness depends on how the rules and weights are defined [12, 16]. Fuzzy-logic models use expert-defined rules to handle imprecise inputs and avoid relying on strict thresholds [98]. Probabilistic and statistical approaches model trust as uncertain or evolving evidence and update it as new observations become available. Examples include Beta-based reputation, Bayesian updating, and Markov models [14]. Subjective logic further represents belief, disbelief, and uncertainty separately, rather than reducing them to a single value. Learning-based approaches, including neural networks (NN), clustering, and federated learning, learn trust patterns from behavioral or interaction data and can capture relationships that are Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
9
difficult to express through predefined rules [41, 79, 140]. Agent-based designs also appear as multi-agent reputation and clustering schemes. They treat IoT nodes as cooperating agents whose group membership follows local trust [36], while multi-agent reinforcement learning uses interacting learners to update trust-aware decisions at runtime [21, 115]. However, learning based methods generally introduce higher data and computational requirements. Game-theoretic approaches model trust-related interactions as strategic behavior between entities and can incorporate mechanisms such as voting, incentives, and coalition formation [81]. Blockchain is also used in trust computation frameworks, mainly to provide a distributed mechanism for recording, sharing, and protecting trust values rather than serving as a trust computation method by itself [63, 107]. No single approach is universally preferred: the choice depends on the trust target (device, data, or service), the available evidence, and the resource constraints of the deployment [9]. Besides, authors in [16] highlight the need for trust modeling while considering which IoT domains it will be adapted to. 2.2.3 Trust Distribution. Trust distribution is the stage at which computed scores are stored and shared so that other entities can use them for operational decisions. Before scores can be disseminated, they must be represented in a comparable form. In the state-of-the-art, trust may be modeled as a binary, nominal, discrete, or continuous value [9]. Most schemes use a scalar score in [0, 1], while others keep multiple trust dimensions or map entities to discrete states such as trustworthy or malicious [12, 49, 55, 58, 60, 119]. Trust can also be represented as a vector, a matrix, or a graph of relationships, which enables indirect inference when only partial evidence is available [78, 93]. Once a representation is chosen, two further questions arise: where trust scores are stored, and how they are disseminated across IoT network. Storage may be local to the evaluating node, held at an edge or fog gateway, or recorded on a shared ledger. Dissemination then determines who receives those stored values and along which path: top-down, horizontally among peers, through cluster heads, or by consensus exchange. IoT trust management can be implemented through centralized, distributed, or decentralized architectures. Among the surveyed studies, decentralized architectures are our focus. Table 2 compares the three families in terms of computation placement, dissemination strategy, typical use cases, and key drawbacks. Table 2. Architectural Comparison of Trust Management Placement Architecture Decentralized (Our Focus) Distributed Centralized
Computation Edge compute locally; cloud syncs globally Peer evaluation without central coordination Central server processes all raw telemetry, compute trust
Dissemination Local gateway push; regional cloud coordination P2P broadcast or consensus protocols Cloud broadcasts lists/policies to nodes
Best Suited For Large-scale, mixed-resource IoT (e.g., IIoT, smart cities) Dynamic, ad-hoc networks (e.g., VANETs) Static, low-power networks with stable links
Key Drawback Complex gateway management High resource overhead on constrained sensors Single point of failure; high latency
In centralized architectures, central controller collects interaction evidence, computes trust, and disseminates the result top-down through blacklists, trust tokens, or policy updates. This model simplifies management and benefits from global visibility, but it introduces latency, a single point of failure, and scalability bottlenecks when all raw telemetry must be uploaded for analysis [133]. In decentralized architectures, computation is shifted to intermediate nodes such as edge gateways, fog brokers, or cluster heads. These nodes evaluate trust locally, aggregate neighborhood reputation, and share summaries horizontally with peer managers while synchronizing with upper tiers.. In distributed architectures, there is no fixed trust coordinator: individual nodes evaluate peers directly and propagate updates through broadcast or consensus protocols. This supports ad-hoc and vehicular environments, but it imposes additional communication and computation costs on constrained devices. Manuscript submitted to ACM
10
Aydin et al.
2.2.4 Trust Maintenance. Trust assessments made at the beginning should not be considered permanent. Trust must be maintained via update triggers and decay factors. Updates can be executed in three options. Event-driven updates trust values quickly upon an event, such as a packet exchange, service invocation, or incoming recommendation. For instance, [62] uses event-driven updates to maintain trust ratings after every client-server communication. Time-driven updates refresh scores at predetermined intervals, which is straightforward to manage. However, it may result in stale trust between updates. Hybrid methods integrate both techniques, updating on interaction when evidence is available and periodically updating otherwise [3, 70]. Although frequently overlooked, trust decay is essential for history-based frameworks, as maintenance remains fundamentally incomplete without a temporal aging mechanism: fresh occurrences update the score, but old evidence may still dominate the outcome. Decay mechanisms discount older data to prioritize current conditions over past history. This is important in IoT because devices may become inactive, environments change rapidly, and attackers may exploit outdated high trust through on-off behavior. Decay is often implemented using forgetting factors such as sliding time windows, or separate trust terms. [102] includes a recent trust in their suggestion, whereas [58] uses historical trust, where the final trust value is based on the current trust and the average of previous trust values. 2.3
Trust-Related Attacks
In the literature, several taxonomies have been proposed to categorize trust-related attacks. [117] employs a basic taxonomy: internal, external attacks and their intersection. In addition to classification based on attacker location, [46] suggests a taxonomy of three more classes: device specification, information damage level, and host compromise. Both [99] and [76, 79] use two-dimensional classifications: the former categorizes attacks as individual or collusive, while the latter groups them by target (service/recommendation) and impact scope (single/group).
Target
IoT Layer
Attack Type
Abbr.
Device Trust
Network/Application Physical Physical
Sybil Attack Node Capture Sleep Deprivation
SA NC SDA
Data Trust
Application Application Application Application Physical/Network Physical/Network Physical
Bad-mouthing Good-mouthing (Ballot-stuffing) Self-promoting Data Poisoning False Data Injection Jamming Sensor Spoofing
BMA GMA SPA DP FDI JA SS
Service Trust
Table 3. Classification of Trust-Related Attacks by Target and Architectural IoT Layer
Application Application Application Application Network/Application Network Network Network
Opportunistic Service Discriminatory Attack Whitewash Attack Malicious with Everyone Attack On-Off Attack Selective Forwarding Black-hole Gray-hole
OSA DA WA ME OOA SFA BHA GHA
Moreover, [135] focuses specifically on data trust-related attacks and proposes a taxonomy based on three dimensions: attack methodology, attacker type (non-strategic vs. strategic), and attack scope (local vs. network-wide). While their approach may provide understanding of adversarial behavior, it only addresses trustworthiness of information within Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
11
navigation systems. Finally, while [57] maps trust attacks strictly to single IoT layers, our proposed taxonomy allows for hybrid layer assignments. As shown in Table 3, we classify each threat by its architectural layer and specific trust target (device, data, or service). Furthermore, Table 4 maps the same attacks onto the process in Figure 2. It records where the compromise occurs, its primary effect, whether the attack is internal or external, the behavior of attacker, and how difficult the attack is to detect. Table 4. Trust-Related Attacks Across The Trust Management Process in Figure 2 Abbr. Targeted Trust Management Process
Primary Effect
Attack Origin
Attacker Behavior
Detection Difficulty
SA NC SDA
Evidence flow; Trust flow; Maintenance Evidence flow Evidence flow
Fake identities bias evidence and disseminated scores A captured node becomes a false evidence source Honest nodes are exhausted and stop reporting
I&E I&E I&E
Persistent Persistent Persistent
■■■ ■■□ ■■□
BMA GMA SPA DP FDI JA SS
Acquisition Acquisition; Trust flow Acquisition; Trust flow Evidence flow; Computation Evidence flow; Aggregation Evidence flow; Trust flow Evidence flow
False recommendations slander honest nodes Colluding nodes inflate shared reputation A node inflates the score that others receive about it Corrupted samples bias the trust model itself False observations enter the evidence stream Evidence collection and score dissemination are disrupted Fabricated sensor readings replace genuine measurements
I I I I&E I&E E E
Persistent Strategic Persistent Persistent Persistent Persistent Persistent
■■□ ■■■ ■■□ ■■■ ■■□ ■□□ ■■□
OSA DA WA ME OOA SFA BHA GHA
Trust-driven decision flow Service is degraded after the node has been selected Trust-driven decision flow Only selected requesters receive poor service Maintenance Identity reset discards prior distrust Trust-driven decision flow Every trust-based request is served maliciously Trust-driven decision flow; Maintenance Alternating behaviour keeps the node selectable Trust-driven decision flow Trusted forwarding is applied only to some packets Trust-driven decision flow Trusted routing delivers traffic that is then dropped Trust-driven decision flow Trusted routing is violated only part of the time I = Internal Attack, E = External Attack, I & E = Both Applicable
I I I I I I I I
Strategic ■■■ Intermittent ■■■ Strategic ■■■ Persistent ■□□ Intermittent ■■■ Persistent ■■□ Persistent ■□□ Intermittent ■■■
Table 4 reveals that trust-related attacks can compromise the trust management process at multiple stages rather than targeting trust computation alone. Evidence-related attacks such as SS, FDI, and BMA primarily corrupt the information used to establish trust, whereas OSA, DA, SFA, BHA, and GHA exploit trust-based decisions after a node has already been considered trustworthy. Attacks such as SA, DP, and OOA are particularly broad in their impact, spanning multiple stages of the process and potentially influencing both trust assessment and subsequent decisions. There is also a correlation between attacker behavior and detection difficulty. Persistent attacks generally leave continuous behavioral evidence and are therefore comparatively easier to detect, while intermittent and strategic attacks, including OOA, GHA, DA, GMA, OSA, and WA, deliberately preserve or recover favorable trust levels and are consequently harder to identify. This is especially evident for attacks that manipulate trust without continuously violating expected behavior. Overall, this representation shows that attack resilience should be evaluated at the process level, since a trust mechanism may accurately compute trust from its inputs yet remain vulnerable when those inputs, trust-based decisions, or subsequent trust updates are manipulated. 3
Review Methodology
To provide a comprehensive assessment of the current state of trust management in IoT, we adopt a systematic literature review approach. The primary repositories selected for this study are Web of Science (WoS) and Scopus. Constructed search queries given in Figure 3. Manuscript submitted to ACM
12
Aydin et al. Database: Web of Science (WoS) Date Range: 2020–2026
Database: Scopus Date Range: 2020–2026
("Trust Management" OR "Trust Evaluation" OR "Trust Model" OR "Trust Mechanism" OR "Reputation System" OR "Behavior-based Trust") AND ("IoT" OR "Internet of Things" OR "IoT device*" OR "edge-enabled IoT" OR "edge-assisted IoT") AND ("edge-ai" OR "ai" OR "Artificial Intelligence" OR "ml" OR ("agent" AND "learning")) AND (Publication Date: 2020/2027) NOT ("survey") NOT (Document Type: Review) AND Language: English
(TITLE-ABS-KEY("Trust Management" OR "Trust Evaluation" OR "Trust Model" OR "Trust Mechanism" OR "Reputation System" OR "Behavior-based Trust")) AND (TITLE-ABS-KEY("IoT" OR "Internet of Things" OR "IoT device*" OR "edge-enabled IoT" OR "edge-assisted IoT")) AND (TITLE-ABS-KEY("edge-ai" OR "ai" OR "Artificial Intelligence" OR "ml" OR ("agent" AND "learning"))) AND (PUBYEAR > 2019 AND PUBYEAR < 2027) AND NOT TITLE-ABS-KEY("survey") AND NOT DOCTYPE(re) AND ( LIMIT-TO ( LANGUAGE,"English" ) )
(a)
(b)
Fig. 3. Search Queries Applied to the Two Indexing Databases: (a) Web of Science (WoS) , and (b) Scopus
The review technique follows PRISMA framework to promote reproducibility and transparency in the article selection process. Figure 4 illustrates the steps involved in the literature screening and selection process. Research included in qualitative synthesis are examined in steps (i) scope identification, (ii) trust-design evaluation, and (iii) operational and attack coverage. Records identified through database search (n=256)
Duplications are removed (n=237)
Articles assessed for survey eligibility (n=237)
Research included in qualitative synthesis (n=55)
Records Exluded with reasons: Out of scope (73) Insufficient trust-model detail (102) Limited Rigor (7)
Fig. 4. PRISMA Flow Diagram From Identification To Screening, Eligibility, And Inclusion Steps
Step 1: Scope identification. Each state-of-the-art study is first assigned to one of the four IoT application domains considered in this survey: Consumer, Commercial, Industrial, or Infrastructure IoT. This classification is based on the primary operational context and type of IoT system investigated in the study. The study is then positioned according to the IoT layer at which trust is primarily computed, updated, or enforced, using the three-layer model of physical, network, and application layers. When trust mechanisms span multiple layers, a hybrid placement is recorded. This two-level classification establishes both the application context and architectural location of the trust mechanism. Step 2: Trust-design evaluation. Each study is further classified according to the five orthogonal trust-design dimensions presented in Figure 5. These dimensions capture what is trusted, how trust is computed, which evidence is used, how trust is updated or maintained. This stage enables the comparison of the underlying design choices. Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions Device Data
TRUST TARGET
ARCHITECTURE How trust management functions are distributed
TRUST DESIGN
What is being evaluated?
Dimensions for the State-of-the-Art TMS
Service
13
Distributed Hierarchical
Blockchain
Experience Direct Evidence Observation Recommendations
Centralized
Subjective logic / belief-
TRUST INPUTS Where does the evidence come from?
based reasoning
COMPUTATION How is the trust estimated/calculated?
Indirect Evidence
Reputation/Consensus Hybrid
Game Theory Machine Learning Probabilistic/Statistical
Event-Driven Time-Driven
When does trust change?
Fuzzy Logic
UPDATE MECHANISM Weighted Sum
Hybrid
Fig. 5. Trust-Design Taxonomy for Classifying Trust Management Schemes
Step 3: Operational and Attack Coverage. The operational roles of trust are examined and results are given in Table 11. For each study, we record how trust is used to securely guide IoT operations, such as routing, service selection, access control, data aggregation, or intrusion detection. The attacks reported as mitigated by each study are then extracted from the original paper and categorized according to the attack taxonomy in Table 12. 4
Current IoT Trust Based Frameworks
We examine state-of-the-art trust management frameworks using the four-step classification from Section 3. The comparative taxonomies are organized by IoT application domain (consumer, commercial, industrial, infrastructure) and ordered top-down by operational layer (application to physical). Cross-layer mechanisms are explicitly indicated. Notably, most surveyed literature targets the application and network layers, where node cooperation and interaction primarily occur. The distribution respect to application domains is balanced across the four domains, although some years have limited coverage in specific domains as given in Figure 6.
Infrastructure IoT 34,5%
Commercial IoT 25,5% Industrial IoT 18,2%
(a)
Number of surveyed studies per publication year
Consumer
Consumer IoT 21,8%
Commercial
Industrial
Infrastructure
20 17 15
17 5
8 2
10
10
8
4
2 5 3
4
3
4
3 5
2 0
2
2
2020&2021
2022
5
2 2023
2024
2025
(b)
Fig. 6. Surveyed Literature Overview: (a) Distribution Across IoT Application Domains, and (b) Annual Distribution By Domain From 2020 to 2025
To start with, Table 5 lists the investigated IoT trust frameworks in consumer IoT application domain. The main goal in consumer IoT is to make everyday connected systems more dependable without sacrificing usability in general. In this domain, a large share of this research focuses primarily on device trust [6, 14, 16, 75, 98], while service trust and Manuscript submitted to ACM
14
Aydin et al. Table 5. Comparative Taxonomy of Trust Management in Consumer IoT Research Scope
Trust Design Trust Inputs
Evaluation & Security
Ref. (Year)
Evaluation Trust Layer Target
Computation Model
[36] (2022)
Application
Device & Service
[75] (2025)
Application
Device
Weighted feedback ag- Peer feedback, resource E gregation, clustering, relevance, interaction multi-agent frequency-recency, trustorprior reputation Logarithmic trust func- Application transactions, au- E & T tion, time-gated up- thentication, timing gap, recdate ommendations
[79] (2025)
Application
Service
MLP, FL
Direct, recommendations
[98] (2025)
Application
Device
Hybrid fuzzy logic, FL
Sensor data, user behavior, E & T context, historical interactions, real-time feedback
[60] (2024)
Application & Network
Device & Data
Direct one-hop behavior, rec- T ommendations, belief trust, reputation from network features
[64] (2022)
Application & Network
Device & Data
Direct, recommended, belief-based trust with threshold classification, clustering, RNN classifier GAN, VAE, FL, blockchain consensus, reputation/datasimilarity trust
[140] (2021)
Application & Network
Device & Data
Feedforward NN, blockchain (Merkletree trust archiving)
[14] (2020)
Network
Device
Explainable Bayesian trust scoring with severity-aware weighting
[16] (2025)
Network
Device
2D Markov chain, weighted-sum trust score, AHP/TOPSIS
[81] (2022)
Network
Device & Data
HMM behavior prediction, stake-based voting game
[12] (2024)
Network & Physical
Device & Data
[6] (2025)
Physical
Device
Weighted direct and indirect trust with sigmoid function, threshold classification FL, feed-forward ANN, Z-score/MAD outlier detection
Historical interactions, neighbor opinions, data similarity, signal strength, voting, social trust, computation contribution 18 NN inputs (vehicle/incident location, visibility distance, current trust, RSU range, traffic direction), message context, LTL/GTL trust Service-access matches, access violations, access uncertainty, cumulative uncertain volume, access violation diversity, MUD/ACL baselines CPU/RAM usage, security level (TEE/PUF RoT), OS/package age, packet loss, risk/reputation, vulnerability index, IDS score HMM global trust, neighbor recommendations, past interactions, stake/deposit, vote validity, data skewness GTS-request patterns, received vs requested packets, channel capacity, neighbor trust RSSI, LQI, internal temperature, battery level, MAC, radio channel, antenna orientation
Update Attacks Mitigated
E
Validation
Code?
Collusion, GMA, SPA, BMA, OOA, OSA
Simulation
No
GMA, BMA, DoS/DDoS, flooding, SA, replay, JA, cloning OOA, WA, OSA, BMA, GMA, SPA, DA, ME OOA, WA, DDoS, GMA, BMA
Simulation on Cooja, vs LightTrust, ETES
No
Simulation on Python
No
Simulation on MATLAB, vs MetaCIDS, MetaverseAuth, TrustITS External attacks, Experimental evaluadouble-spending, tion on Python collusion
Available upon request
–
SA, DP, FDI, eaves- Conceptual, healthcare dropping, OSA HAR use-case
No
E&T
SA, BMA, OOA, Simulation on SUMO, fake/tampered mes- NS-2 sages, compromised RSU
No
T
DDoS, reflection at- Experimentation on tacks, flooding, mal- real PCAP datasets ware (UNSW, CTU), SVM threshold classification
No
E
DDoS, NC, FDI, GMA, BMA, SPA, APTs
No
E&T
FDI, single-point-of- Simulation on Python, failure FDI dataset; compared with LSTM, GRU, RSS, Sec5G Slot-capturing DoS, Simulation, vs FCFS, RR, impersonation, FDI SJF, LJF,
E&T
T
SS, replay, SA, DoS
Real-time testbed
Available upon request
No
No
Zigbee Z1 testbed No dataset (347,200 instances)
E = Event-driven Update, T = Time-driven Update, E & T = Hybrid, - = Not Reported
data trust receive comparatively less attention. A second group assess trustworthiness of data together with device trust [12, 60, 64, 81, 140]. Only [36] jointly considers service trust and device trust, and [79] is the only research we surveyed that addresses service trust alone in this application area. The choice of trust inputs closely follows the usage of which trust target in evaluation layer. Physical-layer schemes such as [6] use link and device-state signals and Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
15
therefore focus on device trust. Network-layer works including [14, 16] assess device trust from communication and operational evidence, while [12, 81] extend this to data trust when integrity-related inputs such as data skewness or received-versus-requested packets are added. Application-layer studies such as [75, 98] mainly target device trust using transactions, authentication, and contextual analytics; [36] and [79] are the main exceptions that explicitly consider service trust. Cross-layer schemes [60, 64, 140] evaluate device and data trust simultaneously. [60, 64] are both in the healthcare field, while [140] uses trust management specifically for vehicular networks. [60] recommends using direct one-hop behavior, neighbor recommendations, and belief-based reputation from network features as trust inputs. Furthermore, these are aggregated with threshold rules and clustering before trust gates access to electronic health records. Similarly, [64] uses neighbor opinions, signal strength, voting, and data-similarity signals as inputs, then combines FL, GAN/VAE sanitization, and blockchain-supported reputation to judge health-activity data trust. In [140], authors feed location, mobility, RSU range, message context, and prior local/global trust inputs into a feedforward neural network, while blockchain stores updated trust values for later validation of traffic and incident messages. Computation models in consumer IoT fall into three overlapping groups. The largest group applies weighted aggregation of direct and indirect evidence [12, 16, 36, 60, 75]. A second group uses probabilistic or statistical inference [14, 16, 81], and a third learns the mapping from behavior to trust [6, 60, 64, 79, 98, 140]. The groups differ mainly in how the score is shaped and what it estimates. Within weighted aggregation, [75] applies a logarithmic function so that trust accumulates slowly, whereas [12] applies a logistic function that sharpens the decision boundary, and [36] places the security property in the weights themselves by scaling feedback with resource relevance, interaction frequency, and trustor reputation to resist collusion. Weights are otherwise hand-tuned, and [16] is the only study deriving them formally through AHP and TOPSIS. In the probabilistic group, [14] scores past behavior through Bayesian updating with severity-aware discounting, while [16, 81] predict future behavior through Markov and hidden Markov models, which is valuable where interaction history is short and sparse. Where learning is used, the architectures are typically small feed-forward networks over low-dimensional feature vectors [6, 79, 140], whereas deeper generative and recurrent models appear only in [60, 64]. Only [98] adds fuzzy inference with fractional-order dynamics for stability guarantees, and only [81] makes honest participation explicit through stake-based voting, while subjective logic and evidence-theoretic fusion are absent. Earlier works rely on Bayesian scoring, neural inference, and blockchain reputation, whereas federated designs primarily in 2025. Federated and edge-local training is therefore the most recent trend in this domain, consistent with the privacy sensitivity of consumer-related evidence. Among the studies in Table 5, BMA [16, 36, 75, 79, 98, 140] and GMA [16, 36, 75, 79, 98] are the most common, together with OOA [36, 79, 98, 140]. Among conventional threats, SA [6, 64, 75, 140], DDoS [14, 16, 75, 98], and FDI [12, 16, 64, 81] receive the most attention, while other attack classes appear only rarely. Routing attacks such as blackhole, grayhole, and selective forwarding are largely absent from Consumer IoT studies, indicating that they are treated as more relevant to multi-hop networking domains such as Industrial IoT or Infrastructure IoT. Secondly, Table 6 lists the investigated IoT trust frameworks in the commercial IoT application domain. Commercial IoT trust work mainly aims to keep enterprise services dependable: filter bad devices, select good services, and support efficient edge/cloud operation. Unlike consumer IoT, the emphasis is less on privacy and more on service reliability, scalability, and institutional trust in business environments. Device trust is still the most popular trust target in commercial IoT, as seen in [3, 21, 39, 62, 95, 100, 114, 115, 137]. Similar attention is given to assessing trust considering both device and data [39, 100, 103, 137]. For example, [39] computes data trust as the matching degree between a vehicle’s reported data and UAV-collected ground-truth baselines, updating the score through bounded increase and decrease rules that converge as it approaches its limits. However, data trust is underexplored in this domain. Frameworks Manuscript submitted to ACM
16
Aydin et al. Table 6. Comparative Taxonomy of Trust Management in Commercial IoT Research Scope
Trust Design
Evaluation & Security
Ref. (Year)
Evaluation Trust Layer Target
Computation Model
Trust Inputs
Update Attacks Mitigated
Validation
[3] (2025) [95] (2025)
Application
Device
Behavior-based trust
Reputation
T
Application
Device
[120] (2025) [110] (2024)
Application
Service
Sensor behavior, energy con- T sumption, forwarding behavior, activeness, delay, information accuracy Hybrid E
Application
Service
[62] (2022)
Application
Device & Service
[71] (2024)
Application
Service
4-dimensional trust mechanism, blockchain surveillance Weighted trust evaluation Interval MADM trust evaluation, deviationmaximization weighting MCDA (QoS-weighted ratings), incremental SVD collaborative filtering Blockchain-based reputation, short-term incentives, HRL service optimization
Implementation on No Raspberry Pi, ESP32 Simulation on MAT- Available LAB upon request
[114] (2025)
Network
Device
[115] (2025)
Network
Device
[103] (2024) [21] (2023)
Network
Device & Data Device
[137] (2023)
Network
Device & Data
[39] (2022)
Network
Device & Data
[40] (2022)
Network
Service
[100] (2022)
Network & Physical
Device & Data
Network
QoS attributes via SLO, interval-valued monitoring values
E
QoS params, peer post- E communication ratings
Service-provision E&T records, service collaboration frequency, direct/indirect reputation, rewards/punishments, edge resources Weighted sum, ML- Latency, throughput, capac- E & T enhanced genetic ity, energy efficiency, cost, algorithm reliability Weighted multi- Direct, indirect, and recent T parameter trust on trust blockchain, FL Kmeans clustering, multi-agent RL T Multi-level weighted Direct & Indirect trust aggregation Reputation-record Resource request count, task- E trust (request-count completion ability under dethresholding), multi- lay constraint, channel state agent DRL Neural network, fuzzy Direct/virtual interaction E logic metrics, fuzzy attributes Ground-truth match- Direct & Indirect E&T ing, recommenderweighted indirect trust Delay-based reputa- Service delay, historical rep- E tion, RPBFT, A3C DRL utation, QoS/praise Weighted sum of be- Packet/forwarding rates, en- T havioral metrics ergy, residual energy, distance, BS feedback
SA, OOA, replay, DoS, MiTM Abnormal device behavior, control-command, coordinated threats BMA, GMA, DA Not reported
Code?
Simulation
No
Case study on QWS dataset
No
DoS, DDoS, mali- Simulation on Edge- No cious edge nodes, CloudSim, MATLAB FDI OSA, unreli- Simulation on Python, able/malicious PyTorch, train-control SP case study
No
Not reported
Simulation
No
Tampering, eavesdropping, privacy, single-point-offailure, compromised nodes BMA, GHA, FDI, replay, eavesdropping Resource preemption, interference, JA, data tampering
Simulation on NS-3, vs EDDC, LSTM, GRADE
Yes
Simulation with LT-FS- No ID dataset Simulation, Lee/Hata No channels, vs KNN, A2C
FDI, malicious termi- Simulation on MATnal detection LAB with SmartSantander dataset FDI Simulation on Python with T-Drive Beijing taxi dataset Byzantine/malicious Simulation on Python, nodes Hyperledger Fabric, vs PBFT, DQN, RD Sinkhole, inter- Simulation on MATnal/external attacks, LAB known/chosenplaintext attacks
No
No
No
No
E = Event-driven Update, T = Time-driven Update, E & T = Hybrid, - = Not Reported
assessing service trust [40, 62, 71, 110, 120] are more visible than the number of frameworks in consumer IoT. When compared to consumer IoT, a greater attention is given to service trust. It is incorporated in 36% of the surveyed commercial IoT studies, compared with only 17% in Consumer IoT. In the research by [62], QoS-driven peer ratings are aggregated into community trust and supports cold-start prediction for new devices. More, [40] applies delay-based service reputation to cross-domain service orchestration and consensus leader selection. Moreover, application layer is the primary deployment point for service trust mechanisms. For example, [110] ranks edge/cloud providers using QoS Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
17
evidence such as availability, latency, and response time through a trust-as-a-service broker, while [120] evaluates edge service collaboration with multi-level trust, whitelist/blacklist control, and reputation attacks such as BMA and GMA. [71] further uses blockchain-based service reputation and collaboration records to schedule trustworthy edge services in train-control environments. In contrast, network layer more often evaluates device and data trustworthiness jointly. For example, [103] considers interaction, data, and transmission trust between the members of a cluster, and identity and validation trust at the cluster-head and the base-station levels. They utilized direct observation across a sliding time window and, in the absence of interaction history, from neighbor input. The aggregated score is then used to drive cluster-head selection and routing. Overall, they try to mitigate GHA, OOA, WA, and BMA. Besides [137] evaluates terminal trust from interaction accuracy and response quality to detect FDI in smart-city sensing. In [100], forwarding behavior is linked with trusted data aggregation to prevent sinkhole attacks in cluster-based networks. [114] reframes trustworthiness as a multi-criteria operational metric for 6G mesh node selection using latency, cost, and capacity evidence, but it is not security-oriented and includes no attack model. Consequently, trust inputs such as packet delivery rate [115] forwarding rate and packet success [100], latency, cost, and capacity [114], channel gain and task completion under delay [21] are the trust inputs considered in these groups of frameworks. The trust model in [115] combines direct trust derived from observed node behavior and packet delivery rate with indirect trust obtained from neighboring nodes’ opinions, while recent trust values are further derived from the direct and indirect trust assessments. With respect to computation, the commercial IoT literature can be summarized in three groups. The largest group derives trust from weighted, multiple attribute decision making (MADM), or rule-based aggregation of behavioral and QoS evidence [3, 95, 100, 103, 110, 120]. A second group employs learning only to optimize a downstream decision, such as offloading, service orchestration, clustering, or topology formation [21, 40, 71, 114, 115]. A third, much smaller group estimates trust itself with a learned model: [62] uses SVD for cold-start prediction, and [137] combines a NN with fuzzy attributes. Where blockchain is used, it serves as a logging or consensus mechanism [40, 71, 95, 115]. Three contrasts follow from this grouping. First, relative to consumer IoT, commercial studies give more attention to service-oriented MADM and reputation, yet none adopt a probabilistic or Bayesian computation. Second, within the domain, application-layer schemes typically rank services or providers, whereas network-layer schemes combine weighted device and data scores with an optimizer. Third, in commercial IoT, event-driven trust updates are a common approach by 43% [21, 40, 62, 110, 120, 137]. In these frameworks, trust scores are revised after service collaboration, provider interaction, or QoS change. Time-driven mechanisms are also slightly more frequent in commercial IoT by 36% particularly in schemes that require continuous monitoring of device behavior [3, 95, 100, 103, 115]. Thirdly, frameworks we investigated that fall into industrial IoT domain are listed in Table 7. These frameworks mainly aim to preserve safe and continuous cyber-physical operation in factory, and sensor-network environments. Although the studies target different entities, they collectively seek to ensure that only trustworthy devices, data, edge services, and communication paths participate in industrial monitoring and control. Device trust is the dominant target in all three domains, but industrial IoT shows the strongest concentration on standalone device trust by 70% in all layers. [23, 58, 66, 119, 124, 129, 138] assess device trustworthiness, in addition to that, [141] extends this by including data trustworthiness and [35] by integrating digital twins and blockchain, where trust scores guide autonomous service and server selection to support self-healing Edge-AI IIoT. The only research focus solely on data trust is [96] where it addresses a core limitation of blockchain-enabled IoT: blockchain ensures tamper-resistant storage, on the other hand, it does not guarantee that uploaded sensor data is accurate or trustworthy. The authors therefore aim to evaluate data trust at the point of submission by combining blockchain-based past device reputation with real-time SVM-assisted data classification at the edge, and validator-driven ML ensemble verification for uncertain records. Although this Manuscript submitted to ACM
18
Aydin et al. Table 7. Comparative Taxonomy of Trust Management in Industrial IoT Research Scope
Trust Design
Evaluation & Security
Ref. (Year)
Evaluation Trust Layer Target
Computation Model
Trust Inputs
[96] (2024) [129] (2025)
Application
Data
Application
Device
MLP, random forest, KNN Weighted sum (direct + indirect)
Reputation score, SVM deci- E sion score Decryption feedback, E interaction outcomes-timefrequency
[23] (2024)
Application
Device
[138] (2024)
Application
[35] (2023)
Application
[66] (2023)
Reliability, communication success, node importance, interaction time, feedback Satisfaction, interaction history, time decay, operation counts, behavioral similarity Prediction accuracy/timeliness, device feedback, running-state changes, periodic feedback FL with LSTM anom- Consensus participation, aly detection, weighted behavior detection, traffic trust anomaly score, historical trust SVM, dynamic weight- Payload size, reputation, ining tegrity, network statistics
Update Attacks Mitigated
Feedback-based trust, Mahalanobis similarity, median filtering Device Feedback-based weighted trust (direct + indirect) Device & Blockchain-based Service trust, threshold, majority aggregation
E&T
Application
Device
[58] (2025)
Network
Device
[141] (2023)
Network
Device & Data
Blockchain consensus trust, BLS-based PoRep via VDF
Replica proofs, storage ca- E pacity, VDF verification, BLS signatures
[119] (2024)
Network & Physical
Device
[124] (2020)
Physical
Device
PKI-based trusted authentication, behavior trust Probabilistic graphical model, approximation algorithm
Identity/certificates, plat- E & T form integrity, network behavior Behavior on Data-collection- communication, direct interactions
Validation
Code?
FDI, data manipula- Dataset-based experi- No tion ments, prototype FDI Formal proofs, JPBC No benchmarks, Python simulation with synthetic data Simulation, vs TFL-DT, No BMA, OOA LTrust
T
BMA, GMA, OOA, Collusion
Simulation on NetLogo
No
E&T
SPA, data tampering, false predictions, BMA
Simulation
Available upon request
E&T
SA, impersonation, insider, collusion
Experiments on Hyper- No ledger Fabric/Docker, ZTE traffic
E
Spoofing, SA, NC, re- Prototype, Contiki-NG, play, DDoS synthetic dataset Storage cheating, data tampering/deletion, TTP risk FDI, SFA, replay, eavesdropping, impersonation, MitM Insider, hidden data, malicious/damaged nodes
Experiments on C++/MIRACL library
Available upon request Available upon request
Simulation on NS-3 & MATLAB
No
Simulation MATLAB,NS-3
No
on
E = Event-driven Update, T = Time-driven Update, E & T = Hybrid, - = Not Reported
context dominated by device trust, FDI remains the most frequently addressed attack [35, 96, 119, 129, 141]. It is because compromised industrial devices are seen as the main source of corrupted process data. Data quality and service-output validity are used as an additional evidences for device trustworthiness [35, 119, 129]. Only [96] accept data trust in its evaluation scope, whereas the remaining device-trust studies mainly address reputation [23, 138], insider [66, 124], collusion [66, 138], or network attacks [58]. [138] jointly models device interaction and communication behavior to broaden attack coverage, but it still treats the edge broker as implicitly trusted; the authors therefore suggest future direction of a trusted execution environment at the edge device. Computationally, industrial IoT trust is less a single modeling tradition than a set of mechanisms aligned with process integrity. Weighted feedback remains the most common formulation, aggregating terminal and device interaction evidence at the edge [23, 138]. Commercial IoT uses similar aggregation, but typically to rank services or allocate resources through QoS and MCDA criteria [62, 110]. Industrial schemes instead filter MEC feedback and process data, treating trust as a gate on operational evidence rather than as a service-selection score. In learning-based models, Consumer IoT frameworks more often combines FL with fuzzy inference, generative sanitization, or probabilistic predictors for home and healthcare settings [64, 98]. In industrial IoT, by contrast, it is used mainly for anomaly detection and rejection of corrupted sensor readings [66, 96]. Blockchain appears in all three domains, yet its role differs. Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
19
In industrial deployments, it supports cross-domain federation, digital-twin validation, and storage-consensus trust [35, 141], rather than the reputation archiving typical of consumer IoT [140] or the service-market logging typical of commercial IoT [71]. Trust updates in industrial IoT are mainly event-driven or hybrid (40% each). Scores change when data are submitted, interactions occur, or consensus proofs complete. Effective maintenance is important not to leave old trust score in the loop. Table 8. Comparative Taxonomy of Trust Management in Infrastructure IoT Research Scope
Trust Design
Ref. (Year)
Evaluation Trust Layer Target
Computation Model
[27] (2025)
Application
Device
FL, GenAI
[131] (2025)
Application
Data
[49] (2024) [70] (2024)
Application
Device
Application
Device
[22] (2024)
Application
Device & Data
[68] (2023) [136] (2023)
Application
Device
Application
Device & Service
[122] (2025)
Application & Physical
Device & Data
Trust Inputs
Evaluation & Security Update Attacks Mitigated
Vehicle behavior, communi- E cation patterns, telemetry, recommendations, data credibility Weighted sum (di- Interaction satisfaction- E rect+recommendation success/failure, recommentrust), DL anomaly dations, data correctness detection ML-based Direct T Bayesian probabilistic trust model based on Beta distribution UAV ground-truth accuracy, EWMA decay, Gaussian-based data rectification Challenge-based Dirichlet reputation, time decay, punishmentrevocation, direct/indirect trust Weighted multidimensional trust with TOPSIS
Hybrid
E
Insider
Validation
Code?
Simulation on City- No Pulse dataset, realworld urban traffic
NC, FDI, OOA, BMA, Trust-convergence impersonation, re- simulation, formal RoR play, MitM, ESL analysis
No
Insider, DoS
No
BMA, OOA, SFA, SA
Simulation on WSN-DS dataset Simulation
Available upon request Experiments on 3 syn- Yes thetic MCS datasets
Reported data, per- T timestep/historical accuracy
FDI, DP, collusion
Hybrid
Betrayal, SOOA, Simulation, real net- No PMFA work False messages, Simulation on real- No BMA, OOA world Chongqing taxi GPS dataset
E
Service ratings, rating E freshness, interaction success/failure, reputation
Direct
T
Malware/virus prop- Simulation on MAT- No agation, deceptive LAB, OMNeT++ node attacks, DoS
E = Event-driven Update, T = Time-driven Update, E & T = Hybrid, - = Not Reported
Lastly, research in infrastructure IoT trust are given in Table 8 and Table 9. This domain is the most device-centric domain in the reviewed set, with device trust appearing in 95%. However, unlike Industrial IoT, infrastructure studies more often combine multiple trust scope. Assessing device and data together 26%, reflects the need to validate both participating entities and mobility-generated observations in large-scale deployments. The evaluation focus also shifts downward to the network layer 53% of studies, where trust supports secure routing, relay selection, clustering, virtualnetwork embedding, and grid communication [5, 42, 52, 70, 80]. [5] introduces link-history-based trust penalization as a load-balancing mechanism which is useful for routing/forwarding trust and edge-security sections. In addition to routing decisions, some frameworks further integrate trust with network resource management. For example, [5] incorporates link-history-based trust into load-balancing decisions, demonstrating that trust can also mitigate congestion and denial-of-service conditions by avoiding overloaded forwarding paths. Trust inputs are strongly mobility and resource-aware, using packet-forwarding behavior, interaction history, energy, link reliability, and location evidence. Computationally, infrastructure frameworks frequently couple trust with optimization or game-theoretic decision-making [18, 67, 91, 143]. FDI remains the most common attack by 37%, but reputation and forwarding attacks are also visible in vehicular and routing frameworks [70, 91, 131, 136]. Overall, the Manuscript submitted to ACM
20
Aydin et al. Table 9. Continue Tab. 6
Research Scope
Trust Design
Evaluation & Security
Ref. (Year)
Evaluation Trust Layer Target
Computation Model
Trust Inputs
Update Attacks Mitigated
[18] (2025)
Network
Device
Game theory
Interaction history, reputa- E & T tion, location, resources
[80] (2025)
Network
Device
Probabilistic
Digital signatures, ID cre- E & T dentials, energy usage data, timestamps
[52] (2024)
Network
Device
Packet-forwarding ratio, rec- E ommendations
[67] (2024)
Network
Device
Weighted sum, forgetting factor, reward/penalty Interaction success/failure
[143] (2024)
Network
Device
[144] (2024)
Network
Device & Service
[5] (2022)
Network
Device
[25] (2022)
Network
Device & Data
[44] (2022)
Network
Device & Data
[91] (2022)
Network
Device
[42] (2024)
Network & Physical
Device & Data
Historical interaction suc- E & T cess/failure, real-time taskexecution outcomes, node attributes Weighted sum, DRL for Security level, node activity, E trust-constrained VNE communication status, VNR participation Subjective logic, dis- Ownership, honesty, social E & T counting/consensus, relationships, latency, PDR DQN energy prediction Beta distribu- Communication behavior, E & T tion, weighted energy, data similarity, link direct+cumulative history, recommendations trust, recommendation aggregation Blockchain authentica- Identity credentials, signa- E tion, Merkle-tree/SHA- tures, block hashes, consen256 verification sus votes, timestamps Link quality, delay, energy, T Weighted direct trust relay trust, distance, mobility Weighted hybrid trust, Packet forwarding, availabil- T differential evolution ity, residual energy, connecfitness tivity, queue congestion RL Q-learning self- Energy, activity, interaction E & T trust, signature-based frequency-success rate, data backtracking reliability, signatures
Malicious nodes interference, selfish behavior Single point of failure, unauthorized access, data tampering, privacy leaks Malicious nodes (false reports, misbehaving CH) Malicious edge nodes, network/data/migration disruption, errors Malicious host node, data tampering/leakage Collusion, GMA, OOA, malicious recommendations DoS, energy-based node compromise
Validation
Code?
Simulation, hedonic coalition, Stackelberg games Ethereum testbed
Yes
Simulation on Python, Freeway mobility
No
No
Simulation on Java, Net- No Logo
Simulation workX
on
Net- No
Simulation on MAT- No LAB, vs TwI-FTM, TTLA, MTTM Simulation on MAT- No LAB, vs BLTM
Identity theft, mas- PoC with synthetic data querading, SA, FDI
No
FDI, malicious node Simulation on NS-3, vs attacks, confidential- fuzzy-IoT, CPSLP ity/auth threats BHA Simulation on NS-2, vs LEACH, TMS, eeTMFO/GA NC, data tampering, Simulation SFA
No
No
No
E = Event-driven Update, T = Time-driven Update, E & T = Hybrid, - = Not Reported
shared goal of infrastructure IoT trust management is to preserve dependable large-scale operation under mobility, multi-stakeholder governance, and critical-service availability constraints. In summary, Table 10 compares four application domains into a side-by-side comparison of how the surveyed frameworks differ in edge placement, evaluation layer, trust target, trust evidence acquisition, computation method, update pattern, and reproducibility aspects. For the edge utilization, studies in commercial and industrial IoT most often place trust computation at MEC brokers, service gateways, or Edge-AI nodes. Because service ranking and process-data filtering are latency-sensitive. Studies in consumer IoT have shifted toward federated and device-local training to keep household and health evidence off a central server. Infrastructure frameworks, despite our edge-enabled scope, more often evaluate trust on the forwarding path itself; UAV, RSU, or load-balancing edges appear, but many routing schemes remain node-local. Trust targets follow the operational object of each domain. Device trust dominates everywhere, yet commercial IoT is the only domain in which service trust is the most common design goal (36% versus 17%, 10%, and 11%). Data trust Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
21
Table 10. Cross-Domain Comparison of Characteristic Trust-Design Choices (𝑁 = 55) Design Item
Consumer IoT (𝑁 =12)
Commercial IoT (𝑁 =14)
Industrial IoT (𝑁 =10)
Infrastructure IoT (𝑁 =19)
Edge Utilization
Federated or local training, cloud-edge reputation.
Highest fog/MEC placement, service brokers and offloading.
Edge filters feedback, Edge-AI and digital twins.
Path-level computation, UAV/RSU edges, often nodelocal.
Evaluation Layer
App 33%, cross-layer 33%, net 25%.
Net 50% and app 43%, service/device split.
App 60%, gates industrial control.
Net 53% for routing and clustering, app 37%.
Trust Target
Device 92%, data 42%, service 17%.
Device 71%, service 36%, data 29%.
Standalone device 70%, service 10%.
Device 95%, data 26%.
Trust Evidence
Direct & recommendation, link and context signals.
Hybrid and QoS/SLO attributes and delay.
Edge-aggregated feedback, data quality as device proof.
Mobility and resource metrics, PDR, energy, location.
Adaptive Computation
50% learning-based, weighted aggregation.
50% with DRL, FL, MCDA alternatives.
40% for anomaly detection and sensor rejection.
Lowest at 32%, defaults to Beta/Dirichlet and game theory.
Trust Update
Hybrid 42%, event or time 25% each.
Event 43%, time 36%, hybrid 21%.
Event and hybrid 40% each, transaction-driven.
Event 42%, hybrid 32%, mobility-driven handover.
Code Availability
None public, 2 upon request, simulation-heavy.
1 public, 1 upon request, simulator-heavy.
None public, 3 upon request, some prototypes
2 public, 1 upon request, simulation and Ethereum tests.
is rarely standalone: it is evaluated together with device trust in consumer IoT, used as a process-integrity check in industrial IoT, and paired with mobility observations in 26% of infrastructure IoT studies. In trust evidence acquisition, consumer and commercial IoT research typically take into consideration direct observations with recommendations, industrial IoT schemes weight interaction feedback at the edge whereas infrastructure IoT schemes rely more on direct network observables such as packet delivery, energy, and link quality. Adaptive computation, meaning models that revise weights or thresholds from observed behavior rather than from a fixed formula, reaches about half of consumer and commercial IoT studies. This includes federated learning, DRL offloading, fuzzy inference based works. But it is less common in industrial (40%) and infrastructure IoT (32%), where weighted, probabilistic, and game-theoretic rules still critical choice. Event-driven or hybrid updates are the majority pattern in all four domains; purely periodic updates remain a minority. This survey reveals that only three of 55 studies release public code, and seven more offer it upon request. Therefore, cross-paper comparison still depends on incompatible simulators and author-built traces. 4.1
Roles of Trust in IoT Operations
We investigate many state-of-art studies focusing how trust values obtained and computed. It is equally important to examine how these trust scores are actually utilized in operational decision-making. Instead of just saying a device, data or service is trusted, we need to map that trust to specific actions. This work surveys representative trust-supported IoT operations, summarized in Table 11 and illustrated in Figure 7. The obtained results show that trust is most frequently integrated into routing and forwarding and as well service selection decisions, indicating that trust management is primarily used to regulate which entities an IoT node should interact with. Access control and intrusion detection are also prominent, extending this role from selecting communication partners to deciding whether an entity should be admitted or considered malicious. Together, these categories show that current frameworks use trust as a preventive or selective mechanism for controlling interactions with potentially unreliable IoT entities. In contrast, trust is less frequently incorporated into computation offloading, secure clustering, and data aggregation. These applications require trust to be combined with additional operational objectives such as resource allocation, energy efficiency, data quality, or group formation, suggesting that trust is less often treated Manuscript submitted to ACM
22
Aydin et al. Table 11. Taxonomy of Trust-Supported Decisions in IoT Operations Category
Trust-Guided Question
Operational Action
References
Service Selection
Which provider should be invoked?
Choose service instance or supplier
[16, 17, 35, 40, 47, 71, 72, 91, 108, 110, 114, 120, 125, 137, 138]
Secure Routing & For- Who should relay packets next? warding
Select next hop or path
[5, 7, 26, 34, 37, 42, 44, 45, 52, 54, 97, 102, 103, 119, 144]
Access Control
Should the entity be allowed in?
Grant, deny, or revoke access
[4, 6, 8, 12, 25, 30, 32, 62, 88, 119, 130, 131, 144]
Intrusion Detection
Is the entity malicious?
Computation Offloading
Where should the task execute?
Detect, classify, or isolate misbehav- [12, 14, 15, 42, 66, 69, 81, 95, 98, 118, ior 126] Offload to local, edge, or cloud node [5, 18, 21, 33, 67, 71, 108, 143, 145]
Secure Clustering Grouping
Which nodes form a stable team?
Form clusters; elect cluster head
[36, 52, 60, 77, 89, 91, 100, 115, 132]
Data Aggregation
Which reports should be fused?
Accept, reject, or weight sensor data
[10, 39, 55, 81, 96, 100, 103, 122, 140]
Privacy Preservation
What must stay hidden?
Anonymize or restrict sensitive dis- [37, 38, 64, 70, 87, 96, 139] closure
Trusted Data Sharing
To whom should data be sent?
Select trusted relay, peer, or cloud endpoint
&
[31, 38, 53, 58, 60, 129]
Service Selection
15
Secure Routing & Forwarding
15
Access Control
13
Intrusion Detection
11
Computation Offloading
9
Secure Clustering & Grouping
9
Data Aggregation
9
Privacy Preservation Trusted Data Sharing
7 6
Fig. 7. Distribution of Operational Decisions Supported by Trust Management in the Surveyed Literature
as the primary decision criterion when multiple system-level objectives must be optimized. Data-oriented decisions are particularly limited: trusted data sharing, data aggregation and privacy preservation receive less attention than communication and device-related decisions. This shows that trust is more often used to evaluate devices than the data they provide or share. 4.2
Attack Mitigation in State-of-the-Art Frameworks
We examine how state-of-the-art trust management frameworks use trust to mitigate attacks. It is equally important to identify which attacks these frameworks address and how broadly their security mechanisms are evaluated. Table 12 summarizes the attacks considered by the surveyed frameworks. FDI is the most frequently addressed attack, followed by BMA, GMA, SA, and OOA. Within the literature analyzed by [57], BMA, GMA, and SPA emerge as the most frequently addressed trust-related attacks, while OOA and OSA receive less attention. These attacks affect the evidence used to assess entities or directly alter their perceived behavior. DP is also repeatedly considered particularly in learning-based and data-driven trust mechanisms. Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
23
Table 12. Mapping of Studies to Mitigated Trust-Related Attacks Study
NC
SDA
SA
FDI
JA
BMA
GMA
SPA
DP
OOA
SFA
BHA
GHA
OSA
DA
WA
[3] [6] [15] [21] [22] [42] [48] [49] [56] [58] [64] [66] [75] [79] [89] [94] [98] [103] [118] [126] [131] [139] [16, 81] [91, 100] [36, 144] [25, 135] [69, 138] [32, 137] [136, 140] [8, 106, 111] [10, 55, 125] [31, 39, 44, 47, 62, 124, 129]
– – – – – ✓ – – – ✓ – – – – – – ✓ – – – ✓ – – – – – – – – ✓ – –
✓ – – – – – – – – – – – – ✓ – – – – – – – – – – – – – – – – – –
✓ ✓ ✓ – – – ✓ ✓ – ✓ ✓ ✓ – – ✓ – – – ✓ – – ✓ – – – ✓ – – – ✓ – –
– – ✓ – ✓ ✓ ✓ – ✓ – ✓ – – – – – – ✓ – ✓ ✓ ✓ ✓ – – ✓ – ✓ ✓ ✓ – ✓
– – – ✓ – – – – – – – – – – – ✓ – – – – – ✓ – – – – – – – – – –
– – – – – – – – ✓ – – – ✓ ✓ ✓ – ✓ ✓ – ✓ – – ✓ – ✓ – ✓ – ✓ – – –
– – – – – – – – ✓ – – – ✓ ✓ ✓ – ✓ – – – – – ✓ – ✓ – ✓ – – – – –
– – – – – – – – ✓ – – – – ✓ – – – – ✓ – – – ✓ – ✓ – – – – – – –
– – – – ✓ – – – – – ✓ – – – – – – – – – – – ✓ – – – – – – – ✓ –
✓ – – – – – – – – – – ✓ – ✓ – – ✓ – – – – – – – ✓ – ✓ ✓ ✓ – – –
– – ✓ – – ✓ – ✓ – – – – – – – – – – – ✓ – – – – – – – – – – – –
– – – – – – – – – – – – – – – ✓ – – – – – – – ✓ – – – – – – – –
– – – – – – – – – – – – – – – – – ✓ – – – – – – – – – – – – – –
– – ✓ – – – ✓ – – – – – – ✓ – – – – – – – – – – – – – – – – – –
✓ ✓ ✓ – – – – – ✓ ✓ – – – ✓ – – ✓ – – – – – – – – – – – – – – –
– – – – – – – – – – – – – – ✓ – – – ✓ – – – – – – – – – – – – –
The remaining attacks NC, JA, SFA, BHA, GHA, OSA, DA, and WA appear in only a small number of studies. This does not directly indicate that they are less relevant to trust management. But, for example, NC can change the trust status of an entity after compromise. JA can affect the evidence available for trust assessment. SFA, BHA, and GHA can directly alter the observed forwarding behavior of an entity. Similarly, OSA, DA, and WA can manipulate service behavior or the historical evidence associated with an entity. Thus, the reviewed attacks can all be interpreted as threats to the trust assessment, trust evidence, or trust-driven decision process. The main difference is where they affect this process and which trust evidence they manipulate. Therefore, we studied this issue in Table 4. A notable gap is that relatively few frameworks evaluate several of these attack types together. For example, [79] addresses SDA, BMA, GMA, SPA, OOA, OSA, and DA, while [16, 81] jointly consider FDI, BMA, GMA, SPA, and DP. However, this shows that recent frameworks increasingly evaluate trust under multiple forms of adversarial behavior rather than a single attack model. 5
The Road Ahead: Building a Trustworthy IoT Ecosystem
As IoT devices increasingly make autonomous, localized decisions at the edge, trust management can no longer rely on simple scalar values. It must consistently evaluate devices, data, and services across the edge-cloud continuum while withstanding mobility, resource constraints, and trust-related attacks. Although emerging paradigms like edge AI, federated learning, blockchain, and 6G enable distributed trust, they also introduce novel complexities. Manuscript submitted to ACM
24 5.1
Aydin et al. Research Challenges
In order to critically evaluate the current state of the art and map the trajectory of trust management research, we review the recurring limitations in trust-model design, security, deployment, and ecosystem readiness, as summarized in Figure 8. Trust Model Design and Algorithmic Robustness
Architectural and Deployment Challenges C1: Edge/fog/cloud orchestration
17
C2: Centralization and trust bottlenecks
13
C3: Mobility and dynamic topologies
9
C4: Scalability and large-scale deployment
8
C5: Blockchain scalability and decentralization trade-offs
13
C6: Communication and trust-update overhead
6
C7: Trust-model design (cold start, dynamics, sparse history)
26
C8: Data integrity, quality, and trusted sensing
13
C15: Evaluation methodology, datasets, and reproducibility
4
C9: Multi-dimensional and context aware trust assessment
29
C16: Resource constraints (energy, computation, storage, bandwidth)
27
C10: AI/ML and federated learning integration
27
C17: Standardization, governance, and regulatory alignment
2
C11: Defense strategies beyond exclusion and isolation
8
C18: Industrial IoT and cyber-physical constraints
2
C19: Device and network heterogeneity
3
34
C20: Smart cities, crowdsourcing, and macro-scale trust ecosystems
2
C13: Privacy preservation in trust evaluation
10
C21: Social IoT and recommendationbased trust
13
C14: Authentication, authorization, and access-control integration
17
Adversarial Threats, Privacy, Trust-Aware Security C12: Security attacks and trust poisoning
Ecosystem Readiness & Practical Constraints
Fig. 8. Frequency Distribution of Specific Research Challenges Identified in the Surveyed Literature (N=55)
5.1.1 Architectural and Deployment Challenges. Maintaining consistent trust across distributed edge, fog, and cloud infrastructures (C1) has gained increasing attention over the years. It emerges as the most cited architectural challenge in the state-of-art studies. This challenge has grown from a minority concern in 2020–2021 to a central focus by 2025 as edge AI, digital twins, and cloud–edge–terminal architectures become the dominant deployment paradigm [29, 55, 57, 94]. The challenge here is not just the physical placement of computing, but also ensuring the consistency of trust state across these different tiers. Closely related to this challenge, the degree of centralization that trust management should adopt is another important research challenge (C2). This challenge arises because fully distributed peer-based trust mechanisms converge slowly and rely on sparse local observations, whereas centralized authorities provide globally consistent trust decisions at the cost of higher latency and single points of failure [38]. Beyond maintaining trust consistency in an appropriate trust management architecture, trust mechanisms must also adapt to constantly changing network topologies. Supporting mobility and dynamic topologies (C3) becomes essential especially in between vehicles, or UAV. Because in mobile networks, trust evidence can quickly become outdated due to handovers, intermittent connectivity, and network partitions. Therefore, maintaining accurate and timely trust assessment is challenging [34, 97, 142]. Trust management in IoT must also remain efficient at large scale. Ensuring scalability (C4) requires controlling the communication, computation, and storage overhead introduced by trust management as IoT deployments grow. The first thing that comes to mind when scalability is addressed is generally the size of the network. However, it is important to emphasize that scalability issues are also due to various types of traffic, topology changes due to mobility, and the need to perform trust evaluation, routing, and quality of service simultaneously [97, 133]. In the research by [57], it is noted that IoT nodes may accumulate large volumes of trust-related information, yet storage complexity analysis is almost absent. Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
25
One frequently proposed response to the scalability limitations of trust management systems is the use of blockchainbased infrastructures. Evaluating blockchain trade-offs (C5) therefore becomes an important challenge on its own. While blockchain can provide tamper-evident trust records and decentralized consensus mechanisms [30, 35, 49, 50, 57], its practical deployment introduces additional overhead through ledger growth, consensus latency, and on-chain trust-state storage. These costs are often difficult to accommodate on constrained IoT devices, and existing hybrid solutions rarely provide comprehensive cost models spanning computation, communication, and storage resources. Whenever trust information is shared beyond a single device, the network must carry additional control traffic, including reputation broadcasts, certificate or token exchanges, blockchain transactions, and federated or edge-AI model updates. This overhead consumes the same constrained LPWAN and low-power mesh links used for application data, increasing latency, packet loss, and energy consumption even when the underlying trust algorithm is computationally lightweight [82, 125, 130]. Although only six studies among surveyed research explicitly identify communication and trust-update overhead (C6) as an open research challenge. Because in state-of-art research many suggestions assume that trust is spread on a regular basis, but they do not report how often messages are sent, how big updates are, or how this affects network overall. Maintaining trust is not cost-free. Update propagation add communication and energy overhead to IoT nodes [136]. Nevertheless, current literature often prioritizes the initial trust computation over the development of sustainable, ongoing maintenance mechanisms. 5.1.2 Trust Model Design and Algorithmic Robustness. Beyond architectural considerations, trust management fundamentally depends on the ability to derive reliable trust scores from incomplete and changing evidence. Designing robust trust models (C7) therefore remains a major research challenge. Trust models must cope with cold-start conditions, sparse interaction histories [39], dynamic trust updates, and indirect recommendations while adapting to rapidly changing IoT topologies, workloads, and device roles [77, 121]. Trust models often ignore evaluating transmitted information. The difference between device misbehavior and data untrustworthiness is frequently ignored by many research [58]. [57, 112, 131] highlight the data integrity problem (C8). For instance, an IoT device can execute routing protocols perfectly but still send noisy crowdsourced labels, or falsify sensor readings. These issues require data-driven trust assessment. Most schemes still incorrectly infer data quality based solely on a device’s network-layer behavior, making systems vulnerable to false data from trusted nodes. Moreover, trust management should also account for the context in which trust is established. Supporting multi-dimensional and context-aware trust (C9) recognizes that a single trust score is often insufficient for IoT systems. A device may be trustworthy for one task but not for another. Likewise, changes in location, or operating conditions should not always be interpreted as malicious behavior. Although fuzzy and policy-based trust models consider these factors, there is still no common framework for representing and managing context-aware trust across IoT environments [98, 111]. Integrating AI/ML and FL (C10) introduces a new set of challenges. AI-based trust models can better detect malicious behavior and adapt to changing network conditions using techniques such as ensemble learning, graph neural networks, and deep reinforcement learning [10, 21, 64]. However, these approaches are also vulnerable to poisoning attacks, adversarial inputs, and limited model interpretability. Defining trust-aware response policies (C11) extends beyond simply identifying malicious participants. Most existing trust schemes react by excluding or isolating nodes once their trust falls below a threshold. However, this approach is often unsuitable for sparse, mobile, or safety-critical IoT networks, where removing a participant may reduce network connectivity or service availability. More flexible response strategies, such as graduated sanctions, temporary quarantine with recovery, and distinguishing unreliable from intentionally malicious behavior, remain largely unexplored [12, 33, 128]. Manuscript submitted to ACM
26
Aydin et al.
5.1.3 Adversarial Threats, Privacy, and Trust-Aware Security. Trust management should also protect the trust process from attacks. Defending against trust-targeted attacks (C12) requires securing different parts of the trust ecosystem. Attackers may target the trust pipeline by manipulating how trust evidence is collected, shared, updated, or aggregated, leading to incorrect trust decisions even when individual devices are not compromised. Although many studies discuss these attacks, most evaluate only a single attack type [79, 97]. While C12 focuses on protecting the trust process from attacks, trust management should also protect the sensitive information used to establish trust. Preserving privacy (C13) is challenging because trust evaluation relies on sensitive information and may subject to privacy regulations [37, 87]. Techniques such as FL and differential privacy reduce data exposure, but they also limit the information available for trust assessment and remain vulnerable to poisoning attacks [35]. As a result, balancing privacy and trust accuracy remains an open research problem. The challenge in authentication and access-control integration (C14) in trust management frameworks defines a third barrier at the security boundary: cryptographic authentication does not detect compromised insiders, while behavioral trust alone lacks strong identity binding [46, 75, 82, 130]. 5.1.4 Ecosystem Readiness and Practical Constraints. Although resource constraints (C16), standardization and governance (C17), industrial deployment (C18), heterogeneity (C19), large-scale smart city ecosystems (C20), and Social IoT environments (C21) have long been recognized as fundamental IoT challenges, they continue to be highlighted in recent trust management research. These are not new challenges to the IoT community; however, recent studies continue to identify them as major barriers to deploying practical trust management systems. In addition to these ecosystem challenges, trust management still lacks reliable evaluation methods. Establishing reproducible evaluation methodologies (C15) remains a persistent challenge, although only a few studies identify it explicitly. Previous surveys report inconsistent benchmarks, incompatible simulators, limited public code, and evaluation settings that differ in topology, attack models, and performance metrics, making fair comparison difficult [9, 20, 24, 51]. Public trust datasets are also limited, often lacking interaction history or recommendation data. As a result, many studies prefer relying on synthetic data or custom datasets [22, 112, 126]. Figure 9 groups the 55 surveyed papers into four broad area over 2020-2025. The trend suggests a shift from designing trust models toward deploying and securing them in realistic IoT environments. Trust-model challenges remain dominant, while architectural and adversarial challenges increase notably by 2025. This reflects growing attention to edge AI, distributed trust computation, model poisoning, and other attacks that can manipulate trust evidence or learning processes. In contrast, ecosystem-related challenges show limited growth. Resource constraints are frequently considered, but interoperability, standardization, evaluation, and cross-domain deployment remain less explored. These results indicate that the field is moving beyond trust-score design, while practical questions about how trust mechanisms operate across heterogeneous IoT environments and remain reliable under evolving attacks are still insufficiently addressed. 5.2
Future Directions
After the challenges discussed in Section 5.1 what remains open is how the community should tackle them in specific IoT trust designs. Through this perspective, future directions are given below to provide broad technology trends. 5.2.1 Privacy-Preserving Trust Computation. Trust calculation requires behavioral and contextual information that may also be valuable to attackers. A central direction is privacy-preserving trust computation, where nodes share abstract trust information instead of raw evidence [113]. Semantic trust can reduce direct data exposure by expressing which Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions 2020-2021
2022
Mention count in state-of-the-art
35
2023
2024
Arch. & deploy. (C1-C6)
2025
35 32
30 25
25
24 20 15
15 12
10 5
15
13
11
8
6
4 0 Arch. & deploy. (C1-C6)
Ecosystem (C15-C21)
19
17
Trust model (C7-C10)
Adversarial (C12-C14)
120 100 80 60 40 20 0
Trust model (C7-C10)
15 11
10
3
27
7 1 Ecosystem (C15-C21)
(a)
Adversarial (C12-C14)
(b)
Fig. 9. Research Challenge Trends in the Reviewed Literature by (a) Yearly Distribution and (b) Broad Areas
device capability, data category, or service role is trusted under a given policy; however, semantic representations may still allow sensitive information to be inferred. FL and cryptographic mechanisms could complement semantic trust to further protect the underlying evidence while keeping identifiers, location traces, and rating histories local. These kind of mechanisms are specifically valuable in applications in consumer IoT domain. 5.2.2 Sustainable Trust Management in 6G. 6G introduces new requirements for both sustainability and ubiquitous connectivity. Future trust mechanisms should reduce communication, computation, and energy costs, especially in infrastructure IoT. Non Terrestrial Networks, including satellites, UAVs, HAPs, and LEOs can support trust dissemination and computation, but designs must account for mobility, intermittent connectivity, propagation delay, and overhead [74]. Validation must report message rate, update size, latency, and energy per trust score computation and dissemination. 5.2.3 Agent-to-Agent Trust. IoT systems are moving from device-centric networks toward autonomous agents, including AI-integrated end devices. A future direction is agent-to-agent trust [104], where agents evaluate one another’s behavior, authority, and reliability from operational evidence rather than identity alone. An emerging extension is to use agents themselves as trust parties: regional trust checkers and managers at the edge could issue short-lived claims, admit or revoke nearby devices, and continuously re-verify peers as their behavior or goals change. Commercial IoT is a favorable choice for this approach, where trust can directly support decisions such as which agent may provide a service, accept a task, or access a resource. However, introducing trust managers also creates a new type of vulnerability: a compromised checker could manipulate trust claims and influence decisions within its region. Future work should therefore examine how such trust authorities can be secured and contained without disrupting the wider network. 5.2.4 Trust in Virtual, Immersive and Generative IoT Environments. Future research should investigate how trust management changes when IoT systems increasingly rely on virtual models and AI-generated information. Digital twins can provide additional evidence for trust assessment by simulating device behavior, testing attack scenarios, and supporting trust bootstrapping for entities even with limited interaction history [101]. However, the trustworthiness of twin-generated evidence itself remains an open question. Similarly, generative AI can support trust prediction and evidence analysis while also introducing new risks through synthetic or manipulated sensor data, identities, and recommendations. Therefore, future trust mechanisms should distinguish between physical and generated evidence and assess their consistency and reliability before using them in trust decisions [43]. This is particularly relevant in large-scale Industrial and Infrastructure IoT, where virtual observations may influence routing, service selection, Manuscript submitted to ACM
28
Aydin et al.
data aggregation, and other operational decisions. Hybrid physical-virtual testbeds could provide a suitable basis for evaluating these mechanisms under false-data and synthetic-evidence attacks.
6
Conclusion
Trust management in edge-enabled IoT requires defining precisely who is trusted, for what operational decision, and against which specific threat. Because prior literature reviews have predominantly restricted their scope to device trust or isolated application domains, this survey adopts a multifaceted analysis to establish a unified perspective. We introduced a comprehensive taxonomy encompassing device, data, and service trust, mapped across a complete trust lifecycle from evidence acquisition to maintenance. Following PRISMA, we systematically analyzed 55 recent studies to evaluate their structural design dimensions across four key IoT domains (consumer, commercial, industrial, and infrastructure) and three architectural layers (application, network, physical). Our findings indicate that while device-centric frameworks continue to dominate, domain-specific priorities are evolving. Commercial IoT increasingly emphasizes service-level trust, whereas infrastructure deployments frequently integrate device and data trust to support high-mobility environments. In terms of mechanics, trust evidence is primarily derived from interaction histories, reputation metrics, and network observables. Computation models remain largely weighted or probabilistic, though they are increasingly augmented by machine learning and blockchain architectures, with updates handled predominantly through event-driven mechanisms. Consequently, while the research community has largely converged on how to compute trust values, a fundamental consensus regarding what specific target those scores should represent remains missing. Furthermore, the operational utilization of trust remains significantly narrower than its theoretical design space. Computed trust scores currently function primarily as gatekeepers for basic service selection, secure routing, and access control. Crucial system-level operations such as data aggregation, computation offloading, and privacy-preserving evaluations are rarely integrated, meaning many generated trust metrics are never fully leveraged to drive the decisions that justify their collection. The results for attack coverage reveal that False Data Injection (FDI) emerges as the most frequently addressed vulnerability, followed closely by Sybil attacks (SA), bad-mouthing (BMA), on-off (OOA), and good-mouthing (GMA) attacks. This hierarchy reflects the prevalence of device-oriented schemes, where anomalous data readings are typically penalized as node misbehavior rather than treated as distinct data-trust failures. Meanwhile, routing and service-layer exploits such as black-hole and selective forwarding attacks remain critically underexplored. To design edge-enabled IoT trust management systems into robust, deployable ecosystems, future research must prioritize: (i) maintaining clear, structural distinctions between device, data, and service trust under active attack; (ii) benchmarking trust overheads against measured energy, latency, computation and communication costs; (iii) engineering targeted defenses against decision-flow and resource-exhaustion exploits rather than focusing solely on evidence poisoning; (iv) adopting reproducible evaluation frameworks supported by public datasets and open source code; and (v) validating proposed designs within agent-based, 6G-supported and physically-virtually coupled environments.
Acknowledgements This research was supported by Odine and OdineLabs as part of ImAgSLab Project under the 1773 ITU TTO Project No: 202500303, and by the ZHAW EELISA Sonderfinanzierung SePRIO project. Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
29
References [1] Muhammad Aaqib, Aftab Ali, Liming Chen, and Omar Nibouche. 2023. IoT trust and reputation: a survey and taxonomy. Journal of Cloud Computing 12, 1 (2023), 42. [2] Muhammad Aaqib, Aftab Ali, Liming Chen, and Omar Nibouche. 2024. Behavior-Based Interpretable Trust Management for IoT Systems. In 2024 35th Irish Signals and Systems Conference, ISSC 2024, H Zheng, I Cleland, A Moore, H Wang, D Glass, J Rafferty, R Bond, and J Wallace (Eds.). IEEE, Belfast, United Kingdom. doi:10.1109/ISSC61953.2024.10602957 [3] Ijaz Ahmad, Shakthi Gimhana, Ijaz Ahmad, and Erkki Harjula. 2025. Adaptive Trust Architecture for Secure IoT Communication in 6G. IEEE Networking Letters 7, 2 (2025), 113–116. doi:10.1109/LNET.2025.3566909 [4] Kamran Ahmad Awan, Ikram Ud Din, Ahmad Almogren, Zhu Han, and Mohsen Guizani. 2025. TrustAware-GNN: Graph-Neural-Network-Based Trust Management for IoT Anomaly Detection. IEEE Internet of Things Journal 12, 18 (2025), 37670–37681. doi:10.1109/JIOT.2025.3584653 [5] Aneeqa Ahmed, Kashif Naseer Qureshi, Muhammad Anwar, Farhan Masud, Junaid Imtiaz, and Gwanggil Jeon. 2022. Link-based penalized trust management scheme for preemptive measures to secure the edge-based internet of things networks. Wireless Networks 30, 5 (2022), 4237–4259. doi:10.1007/s11276-022-02948-4 [6] Kazi Istiaque Ahmed, Mohammad Tahir, Sian Lun Lau, Mohamed Hadi Habaebi, Abdul Ahad, and Amna Mughees. 2025. Trust-Aware Authentication and Authorization for IoT: A Federated Machine Learning Approach. IEEE Internet of Things Journal 12, 8 (2025), 9889–9904. doi:10.1109/JIOT.2024. 3512657 [7] David Airehrour, Jairo A Gutierrez, and Sayan Kumar Ray. 2019. SecTrust-RPL: A secure trust-aware RPL routing protocol for Internet of Things. Future Generation Computer Systems 93 (2019), 860–876. [8] Lukman Adewale Ajao and Simon Tooswem Apeh. 2023. Secure edge computing vulnerabilities in smart cities sustainability using petri net and genetic algorithm-based reinforcement learning. Intelligent Systems with Applications 18 (2023), 200216. doi:10.1016/j.iswa.2023.200216 [9] Assiya Akli and Khalid Chougdali. 2023. A survey on machine learning for iot trust management. In 2023 IEEE Global Conference on Artificial Intelligence and Internet of Things (GCAIoT). IEEE, IEEE, Dubai, United Arab Emirates, 59–65. [10] Noora Al-Maslamani, Mohamed Abdallah, and Bekir Sait Ciftler. 2022. Secure Federated Learning for IoT using DRL-based Trust Mechanism. In 2022 International Wireless Communications and Mobile Computing, IWCMC. IEEE, Dubrovnik, Croatia, 1101–1106. doi:10.1109/IWCMC55113.2022. 9824672 [11] Somya Abdulkarim Alhandi, Hazalila Kamaludin, and Nayef Abdulwahab Mohammed Alduais. 2023. Trust evaluation model in IoT environment: a comprehensive survey. Ieee Access 11 (2023), 11165–11182. [12] Haider Ali, Ahmad Naseem Alvi, Mohammed Alkhathami, Deafallah Alsadie, and Fatamh Alashaib. 2024. TIHCS: Trust-Based Improved QoS for Health Care Systems in Smart Cities. IEEE Access 12 (2024), 108755–108769. doi:10.1109/ACCESS.2024.3438608 [13] Mishri AlMarshoud, Mehmet Sabir Kiraz, and Ali H. Al-Bayatti. 2024. Security, privacy, and decentralized trust management in VANETs: A review of current research and future directions. Comput. Surveys 56, 10 (2024), 1–39. [14] Hussein Alsheakh and Shameek Bhattacharjee. 2020. Towards a Unified Trust Framework for Detecting IoT Device Attacks in Smart Homes. In 2020 IEEE 17th International Conference on Mobile Ad Hoc and Smart Systems (MASS 2020). IEEE COMPUTER SOC, Delhi, India, 613–621. doi:10.1109/MASS50613.2020.00080 [15] Raja Waseem Anwer, Mohammad Abrar, Abdu Salam, and Faizan Ullah. 2025. TEAD: trust-enhanced anomaly detection framework for intrusion detection in IoT-enabled wireless sensor networks (WSNs). Wireless Networks 31, 6 (2025), 4179–4197. doi:10.1007/s11276-025-03987-3 [16] Michail Bampatsikos, Ilias Politis, Thodoris Ioannidis, and Christos Xenakis. 2025. Trust Score Prediction and Management in IoT Ecosystems Using Markov Chains and MADM Techniques. IEEE Transactions on Consumer Electronics 71, 1 (2025), 862–882. doi:10.1109/TCE.2025.3531045 [17] Hind Bangui, Barbora Buhnova, Mouzhi Ge, and Simone Kriglstein. 2025. Leveraging the Internet of Behaviors for Mutual Trust in Digital Ecosystems. In Companion Proceedings of the 2025 Conference on Intelligent User Interfaces, IUI 2025. ASSOC COMPUTING MACHINERY, 82–86. doi:10.1145/3708557.3716344 [18] Soumaya Bounaira, Ahmed Alioua, Anna Maria Vegni, and Ibraheem Shayea. 2025. Trustworthy computation offloading in digital twin edge networks: A hierarchical game-based approach. Ad Hoc Networks 179 (2025). doi:10.1016/j.adhoc.2025.104008 [19] Krishna Chaitanya Chaganti. 2025. A Scalable, Lightweight AI-Driven Security Framework for IoT Ecosystems: Optimization and Game Theory Approaches. IEEE Access 13 (2025), 72235–72247. doi:10.1109/ACCESS.2025.3558623 [20] Senthil Kumar Chandrasekaran and Vijay Anand Rajasekaran. 2024. Trust evaluation model in IoT environment: a review. Environment, Development and Sustainability (2024), 1–32. [21] Miaojiang Chen, Meng Yi, Mingfeng Huang, Guosheng Huang, Yingying Ren, and Anfeng Liu. 2023. A novel deep policy gradient action quantization for trusted collaborative computation in intelligent vehicle networks. Expert Systems with Applications 221 (2023), 119743. doi:10. 1016/j.eswa.2023.119743 [22] Zhicheng Chen, Zhenzhe Qu, Nicholas Xiong, Anfeng Liu, Mianxiong Dong, Tian Wang, and Shaobo Zhang. 2024. UITDE: A UAV-Assisted Intelligent True Data Evaluation Method for Ubiquitous IoT Systems in Intelligent Transportation of Smart City. IEEE Transactions on Intelligent Transportation Systems 25, 8 (2024), 9597–9607. doi:10.1109/TITS.2024.3373411 [23] Minglong Cheng, Wei Chen, Weidong Fang, Jueting Liu, Tingting Xu, and Zehua Wang. 2024. Feedback Mechanism-Based Trust Evaluation Model for Mobile Edge Computing in Industrial IoT. In Advanced Intelligent Computing Technology and Applications, PT VIII, ICIC 2024, DS Huang, W Chen, and Manuscript submitted to ACM
30
Aydin et al.
Y Pan (Eds.). Lecture Notes in Computer Science, Vol. 14869. SPRINGER-VERLAG SINGAPORE PTE LTD, 461–469. doi:10.1007/978-981-97-5603-2_38 [24] François De Keersmaeker, Yinan Cao, Gorby Kabasele Ndonda, and Ramin Sadre. 2023. A survey of public IoT datasets for network security research. IEEE Communications Surveys & Tutorials 25, 3 (2023), 1808–1840. [25] Vasudev Dehalwar, Mohan Lal Kolhe, Shreya Deoli, and Mahendra Kumar Jhariya. 2022. Blockchain-based trust management and authentication of devices in smart grid. Cleaner Engineering and Technology 8 (2022), 100481. doi:10.1016/j.clet.2022.100481 [26] Min Deng, Yuanlin Lyu, Chunmeng Yang, Fang Xu, Manzoor Ahmed, Na Yang, Ze Xu, and Can Ke. 2024. Lightweight Trust Management Scheme Based on Blockchain in Resource-Constrained Intelligent IoT Systems. IEEE Internet of Things Journal 11, 15 (2024), 25706–25719. doi:10.1109/JIOT.2024.3380850 [27] Ikram Ud Din, Ahmad Almogren, Zhu Han, and Mohsen Guizani. 2025. Building Reliable IoT Ecosystems: A Generative AI-Enabled Federated Learning-Based Trust Management Approach. IEEE Internet of Things Journal 12, 10 (2025), 13353–13366. doi:10.1109/JIOT.2024.3511634 [28] Chengzu Dong, Shantanu Pal, Qi An, Ailing Yao, Frank Jiang, Zhiyu Xu, Jianhua Li, Meiqu Lu, Yangxu Song, Shiping Chen, and Xiao Liu. 2023. Securing Smart UAV Delivery Systems Using Zero Trust Principle -Driven Blockchain Architecture. In 2023 IEEE International Conference on Blockchain, Blockchain. IEEE, 315–322. doi:10.1109/Blockchain60715.2023.00056 [29] Giuseppe D’aniello and Lidia Fotia. 2025. Blockchain and AI-based methods for trust management in IoT: A comprehensive survey. Internet of Things (2025), 101755. [30] Bhaskara S. Egala, Ashok K. Pradhan, Prasenjit Dey, Venkataramana Badarla, and Saraju P. Mohanty. 2023. Fortified-Chain 2.0: Intelligent Blockchain for Decentralized Smart Healthcare System. IEEE Internet of Things Journal 10, 14 (2023), 12308–12321. doi:10.1109/JIOT.2023.3247452 [31] Driss El Majdoubi, Hanan El Bakkali, and Souad Sadki. 2020. Towards Smart Blockchain-Based System for Privacy and Security in a Smart City environment. In Proceedings of 2020 5th International Conference on Cloud Computing and Artificial Intelligence: Technologies and Applications (Cloudtech’20), M Essaaidi, M Zbakh, and A Ouacha (Eds.). IEEE, 117–123. doi:10.1109/CloudTech49835.2020.9365905 [32] He Fang, Angie Qi, and Xianbin Wang. 2020. Fast Authentication and Progressive Authorization in Large-Scale IoT: How to Leverage AI for Security Enhancement. IEEE Network 34, 3 (2020), 24–29. doi:10.1109/MNET.011.1900276 [33] Fatimah Faraji, Amir Javadpour, Arun Kumar Sangaiah, and Hadi Zavieh. 2024. A solution for resource allocation through complex systems in fog computing for the internet of things. Computing 106, 7, SI (2024), 2107–2131. doi:10.1007/s00607-023-01199-1 [34] Umer Farooq, Muhammad Asim, Noshina Tariq, Thar Baker, and Ali Ismail Awad. 2022. Multi-mobile agent trust framework for mitigating internal attacks and augmenting RPL security. Sensors 22, 12 (2022), 4539. [35] Xinzheng Feng, Jun Wu, Yulei Wu, Jianhua Li, and Wu Yang. 2023. Blockchain and digital twin empowered trustworthy self-healing for edge-AI enabled industrial Internet of things. Information Sciences 642 (2023). doi:10.1016/j.ins.2023.119169 [36] Giancarlo Fortino, Lidia Fotia, Fabrizio Messina, Domenico Rosaci, and Giuseppe M. L. Sarne. 2023. A Social Edge-Based IoT Framework Using Reputation-Based Clustering for Enhancing Competitiveness. IEEE Transactions on Computational Social Systems 10, 4 (2023), 2051–2060. doi:10.1109/TCSS.2022.3208376 [37] Mehdi Gheisari, Hamid Tahaei, Christian Fernandez-Campusano, Mazhar Malik, Ernest Mnkandla, Zenghui Wang, Malusi Sibiya, Julian L. Webber, Muhammad Rizwan Mughal, Cheng-Chi Lee, Panjun Sun, and Abolfazl Mehbodniya. 2025. A Flexible Software-Defined Networking-Based Privacy-Preserving Method for Internet of Things-Based Smart City Environment Based on the Neighbors Situation. Computer 58, 5 (2025), 27–36. doi:10.1109/MC.2024.3506700 [38] R. Gnanajeyaraman, U. Arul, G. Michael, A. Selvakumar, S. Ramesh, and T. Manikandan. 2023. VANET security enhancement in cloud navigation with Internet of Things-based trust model in deep learning architecture. Soft Computing (2023). doi:10.1007/s00500-023-08180-2 [39] Jialin Guo, Anfeng Liu, Kaoru Ota, Mianxiong Dong, Xiaoheng Deng, and Naixue Xiong. 2022. ITCN: An Intelligent Trust Collaboration Network System in IoT. IEEE Transactions on Network Science and Engineering 9, 1 (2022), 203–218. doi:10.1109/TNSE.2021.3057881 [40] Shaoyong Guo, Yuanyuan Qi, Yi Jin, Wenjing Li, Xuesong Qiu, and Luoming Meng. 2022. Endogenous Trusted DRL-Based Service Function Chain Orchestration for IoT. IEEE Trans. Comput. 71, 2 (2022), 397–406. doi:10.1109/TC.2021.3051681 [41] Sahibzada Saadoon Hammad and Sergio Trilles. 2025. Anomaly Detection for Trust Management in Internet of Things Systems. In Distributed Computing and Artificial Intelligence, Special Sessions II, 21st International Conference, G Marreiros, L Grande, JP Llerena, L Conceicao, H Ko, M Plaza, and M Ricca (Eds.). Lecture Notes in Networks and Systems, Vol. 1151. SPRINGER INTERNATIONAL PUBLISHING AG, 286–291. doi:10.1007/978-3-031-80946-0_29 [42] Guangjie Han, Ying Huang, Yu He, Feiyan Li, Aohan Li, and Jinlin Peng. 2024. A Data Transmission Scheme Based on Reinforcement-Learning-Aided Two-Stage Trust Evaluation for UASNs. IEEE Internet of Things Journal 11, 21 (2024), 35155–35166. doi:10.1109/JIOT.2024.3435365 [43] Haya R. Hasan, Khaled Salah, Raja Jayaraman, Ibrar Yaqoob, and Mohammed Omar. 2024. NFTs for combating deepfakes and fake metaverse digital contents. Internet of Things 25 (2024), 101133. doi:10.1016/j.iot.2024.101133 [44] Khalid Haseeb, Tanzila Saba, Amjad Rehman, Zara Ahmed, Houbing Herbert Song, and Huihui Helen Wang. 2022. Trust Management With Fault-Tolerant Supervised Routing for Smart Cities Using Internet of Things. IEEE Internet of Things Journal 9, 22 (2022), 22608–22617. doi:10.1109/ JIOT.2022.3184632 [45] Jawad Hassan, Adnan Sohail, Ali Ismail Awad, and M. Ahmed Zaka. 2024. LETM-IoT: A lightweight and efficient trust mechanism for Sybil attacks in Internet of Things networks. Ad Hoc Networks 163 (2024). doi:10.1016/j.adhoc.2024.103576 [46] Mahmud Hossain, Golam Kayas, Ragib Hasan, Anthony Skjellum, Shahid Noor, and SM Riazul Islam. 2024. A holistic analysis of internet of things (IoT) security: principles, practices, and new perspectives. Future Internet 16, 2 (2024), 40. Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
31
[47] Mingfeng Huang, Anfeng Liu, Neal N. Xiong, and Athanasios V. Vasilakos. 2025. Towards intelligent and trustworthy task assignments for 5G-enabled industrial communication systems. Digital Communications and Networks 11, 1 (2025), 246–255. doi:10.1016/j.dcan.2023.11.003 [48] Rafiqul Islam, Rajesh Bose, Sandip Roy, Arfat Ahmad Khan, Shrabani Sutradhar, Sujan Das, Farman Ali, and Ahmad Ali Alzubi. 2025. Decentralized trust framework for smart cities: a blockchain-enabled cybersecurity and data integrity model. Scientific Reports 15, 1 (2025). doi:10.1038/s41598025-06405-y [49] Shereen Ismail, Muhammad Nouman, Diana W. Dawoud, and Hassan Reza. 2024. Towards a lightweight security framework using blockchain and machine learning. Blockchain-Research and Applications 5, 1 (2024), 100174. doi:10.1016/j.bcra.2023.100174 [50] Raouf Jmal, Mariam Masmoudi, Ikram Amous Ben Amor, and Florence Sèdes. 2025. Blockchain-powered trust management methodology in siot: A survey. Peer-to-Peer Networking and Applications 18, 4 (2025), 194. [51] Satish Kamble, Surendra Mahajan, Deepak D Sapkal, and Kimi Ramteke. 2024. Research Challenges and Opportunities for Trust Management Systems in IoT Networks. Grenze International Journal of Engineering & Technology (GIJET) 10 (2024). [52] Gurjot Kaur and Deepti Kakkar. 2024. DRIVE: Dual rider-remora optimization for vehicular routing. Peer-to-Peer Networking and Applications 17, 2 (2024), 834–857. doi:10.1007/s12083-024-01638-6 [53] Amjad Rehman Khan, Kamran Ahmad Awan, Fahad F. Alruwaili, Anees Ara, Houbing Herbert Song, and Tanzila Saba. 2025. Trust-Enhanced Lightweight Security Framework for Resource-Constrained Intelligent IoT Systems. IEEE Internet of Things Journal 12, 8 (2025), 10175–10182. doi:10.1109/JIOT.2024.3514374 [54] Muhammad Ali Khan, Rao Naveed Bin Rais, Osman Khalid, and Sanan Ahmad. 2024. Trust-Based Optimized Reporting for Detection and Prevention of Black Hole Attacks in Low-Power and Lossy Green IoT Networks. Sensors 24, 6 (2024), 1775. doi:10.3390/s24061775 [55] Sohrab Khan, Nayab Imtiaz, Arnab Kumar Biswas, Zeeshan Bin Siddique, and Qaisar Ali Khan. 2025. An Expert Hybrid Federated Learning and Trust Management for Security, Efficiency, and Power Optimization in Smart Health Systems. IEEE Access 13 (2025), 58191–58210. doi:10.1109/ ACCESS.2025.3556628 [56] Parisa Khoshvaght, Musaed Alhussein, Khursheed Aurangzeb, Mohammad Sadegh Yousefpoor, Jan Lansky, and Mehdi Hosseinzadeh. 2025. An intelligent fuzzy logic based-trust system in underwater acoustic sensor networks. Engineering Applications of Artificial Intelligence 159, B (2025). doi:10.1016/j.engappai.2025.111558 [57] Alyzia Maria Konsta, Alberto Lluch Lafuente, and Nicola Dragoni. 2022. Trust management for internet of things: A systematic literature review. arXiv preprint arXiv:2211.01712 (2022). [58] Rajesh Kumar and Rewa Sharma. 2025. AI-driven dynamic trust management and blockchain-based in industrial IoT. Computers & Electrical Engineering 123, C (2025). doi:10.1016/j.compeleceng.2025.110213 [59] Aparna Kumari, Rajesh Gupta, Sudeep Tanwar, and Neeraj Kumar. 2020. Blockchain and AI amalgamation for energy cloud management: Challenges, solutions, and future directions. J. Parallel and Distrib. Comput. 143 (2020), 148–166. doi:10.1016/j.jpdc.2020.05.004 [60] Ramesh Kuppusamy and Anbarasan Murugesan. 2024. IoT-based external attacks aware secure healthcare framework using blockchain and SB-RNN-NVS-FU techniques. Technology and Health Care 32, 4 (2024), 2711–2731. doi:10.3233/THC-231895 [61] Abdullah Lakhan, Mazin Abed Mohammed, Dilovan Asaad Zebari, Karrar Hameed Abdulkareem, Muhammet Deveci, Haydar Abdulameer Marhoon, Jan Nedoma, and Radek Martinek. 2024. Augmented IoT Cooperative Vehicular Framework Based on Distributed Deep Blockchain Networks. IEEE Internet of Things Journal 11, 22 (2024), 35825–35838. doi:10.1109/JIOT.2024.3362981 [62] Rabia Latif, Malik Uzair Ahmed, Shahzaib Tahir, Seemab Latif, Waseem Iqbal, and Awais Ahmad. 2022. A novel trust management model for edge computing. Complex & Intelligent Systems 8, 5, SI (2022), 3747–3763. doi:10.1007/s40747-021-00518-3 [63] Rabia Latif, Bello Musa Yakubu, and Tanzila Saba. 2023. MarketTrust: blockchain-based trust evaluation model for SIoT-based smart marketplaces. Scientific Reports 13, 1 (2023), 11571. doi:10.1038/s41598-023-38078-w [64] Tan Le and Sachin Shetty. 2022. Artificial intelligence-aided privacy preserving trustworthy computation and communication in 5G-based IoT networks. Ad Hoc Networks 126 (2022), 102752. doi:10.1016/j.adhoc.2021.102752 [65] Teri Lenard, Anastasija Collen, Meriem Benyahya, Niels Alexander Nijdam, and Béla Genge. 2023. Exploring trust modeling and management techniques in the context of distributed wireless networks: A literature review. IEEE access 11 (2023), 106803–106832. [66] Chao Li, Hui Yang, Zhengjie Sun, Qiuyan Yao, Bowen Bao, Jie Zhang, and Athanasios V. V. Vasilakos. 2023. Federated Hierarchical Trust-Based Interaction Scheme for Cross-Domain Industrial IoT. IEEE Internet of Things Journal 10, 1 (2023), 447–457. doi:10.1109/JIOT.2022.3200854 [67] Juan Li, Zhiwei Qin, Wei Liu, and Xiao Yu. 2024. Energy-Aware and Trust-Collaboration Cross-Domain Resource Allocation Algorithm for Edge-Cloud Workflows. IEEE Internet of Things Journal 11, 4 (2024), 7249–7264. doi:10.1109/JIOT.2023.3315339 [68] Wenjuan Li, Christian Stidsen, and Tobias Adam. 2023. A blockchain-assisted security management framework for collaborative intrusion detection in smart cities. Computers & Electrical Engineering 111, A (2023), 108884. doi:10.1016/j.compeleceng.2023.108884 [69] Wenjuan Li, Jiao Tan, and Yu Wang. 2020. A Framework of Blockchain-Based Collaborative Intrusion Detection in Software Defined Networking. In Network and System Security, NSS 2020, M Kutylowski, J Zhang, and C Chen (Eds.). Lecture Notes in Computer Science, Vol. 12570. SPRINGER INTERNATIONAL PUBLISHING AG, 261–276. doi:10.1007/978-3-030-65745-1_15 [70] Yibing Li, Yangjie Cao, Yan Zhuang, Jie Li, Gangxin Du, and Jianhuan Chen. 2024. Blockchain-Enabled Trust Management With Location Privacy Preservation in Vehicular Ad Hoc Networks. IEEE Internet of Things Journal 11, 14 (2024), 24659–24671. doi:10.1109/JIOT.2024.3350694 [71] Hao Liang, Li Zhu, and F. Richard Yu. 2024. Collaborative Edge Intelligence Service Provision in Blockchain Empowered Urban Rail Transit Systems. IEEE Internet of Things Journal 11, 2 (2024), 2211–2223. doi:10.1109/JIOT.2023.3294400 Manuscript submitted to ACM
32
Aydin et al.
[72] Dianjie Lu, Guijuan Zhang, Yu Guo, and Xiaohua Jia. 2025. Towards a Trust Ecosystem for Crowdsourcing IoT Services: A Macro Perspective. IEEE Transactions on Services Computing 18, 5 (2025), 3292–3306. doi:10.1109/TSC.2025.3604379 [73] Rim Magdich, Hanen Jemal, and Mounir Ben Ayed. 2022. A resilient Trust Management framework towards trust related attacks in the Social Internet of Things. Computer Communications 191 (2022), 92–107. doi:10.1016/j.comcom.2022.04.019 [74] Shahid Mahmood, Moneeb Gohar, Osama A. Khashan, Naif Alzahrani, Anwar Ghani, and Fadi Al-Turjman. 2025. Securing Edge Devices in IoT and 6G: A Trust-Based Approach for Resource-Constrained Environments. IEEE Open Journal of the Communications Society 6 (2025), 6568–6610. doi:10.1109/OJCOMS.2025.3597556 [75] Shahid Mahmood, Moneeb Gohar, Seok-Joo Koh, Muhammad Usman Tariq, and Anwar Ghani. 2025. Application Level Trust Authority (APPLETA) for Resource-Constrained Edge Devices in IoT and 6G. IEEE Transactions on Consumer Electronics 71, 2 (2025), 4934–4948. doi:10.1109/TCE.2025. 3571817 [76] Claudio Marche and Michele Nitti. 2020. Trust-related attacks and their detection: A trust management model for the social IoT. IEEE Transactions on Network and Service Management 18, 3 (2020), 3297–3308. [77] Fabrizio Messina, Domenico Rosaci, and Giuseppe M. L. Sarne. 2025. Forming Teams of Smart Objects to Support Mobile Edge Computing for IoT-Based Connected Vehicles. Applied Sciences-Basel 15, 17 (2025). doi:10.3390/app15179483 [78] Fabrizio Messina, Domenico Rosaci, and Giuseppe M. L. Sarne. 2025. A Neural-Symbolic Approach to Extract Trust Patterns in IoT Scenarios. Future Internet 17, 3 (2025), 116. doi:10.3390/fi17030116 [79] Elham Moeinaddini, Eslam Nazemi, and Amin Shahraki. 2025. A new approach on self-adaptive trust management for social Internet of Things. Computer Networks 263 (2025). doi:10.1016/j.comnet.2025.111187 [80] Bhabendu Kumar Mohanta, Ali Ismail Awad, Tarek Elsaka, Hamza Kheddar, and Ezedin Baraka. 2025. Smart-contract-based blockchain-enabled decentralized scheme for improving smart-grid security. Internet of Things 34 (2025). doi:10.1016/j.iot.2025.101811 [81] Hajar Moudoud, Zoubeir Mlika, Lyes Khoukhi, and Soumaya Cherkaoui. 2022. Detection and Prediction of FDI Attacks in IoT Systems via Hidden Markov Model. IEEE Transactions on Network Science and Engineering 9, 5 (2022), 2978–2990. doi:10.1109/TNSE.2022.3161479 [82] Syeda M Muzammal, Raja Kumar Murugesan, and Noor Zaman Jhanjhi. 2020. A comprehensive review on secure routing in internet of things: Mitigation methods and trust-based approaches. IEEE Internet of Things Journal 8, 6 (2020), 4186–4210. [83] Warsun Najib, Selo Sulistyo, et al. 2019. Survey on trust calculation methods in Internet of Things. Procedia Computer Science 161 (2019), 1300–1307. [84] Nishit Narang and Subrat Kar. 2021. A hybrid trust management framework for a multi-service social IoT network. Computer Communications 171 (2021), 61–79. doi:10.1016/j.comcom.2021.02.015 [85] Muhammad Imam Nashiruddin and Amriane Hidayati. 2019. Coverage and capacity analysis of LoRa WAN deployment for massive IoT in urban and suburban scenario. In 2019 5th International Conference on Science and Technology (ICST), Vol. 1. IEEE, 1–6. [86] Faria Nawshin, Devrim Unal, Mohammad Hammoudeh, and Ponnuthurai N. Suganthan. 2024. AI-powered malware detection with Differential Privacy for zero trust security in Internet of Things networks. Ad Hoc Networks 161 (2024). doi:10.1016/j.adhoc.2024.103523 [87] Walid Osamy, Oruba Alfawaz, Ahmed M. Khedr, and Ahmed Aziz. 2025. TAGSCS: Trust aware data gathering technique based slicing and Compressive Sensing for IoT based WSN. Ad Hoc Networks 178 (2025). doi:10.1016/j.adhoc.2025.103954 [88] V. Padmavathi and R. Saminathan. 2025. A federated edge intelligence framework with trust based access control for secure and privacy preserving IoT systems. Scientific Reports 15, 1 (2025). doi:10.1038/s41598-025-19712-1 [89] Anup Patnaik, Banitamani Mallik, and M. Vamsi Krishna. 2023. Blockchain based holistic trust management protocol for ubiquitous and pervasive IoT network. Journal of Experimental & Theoretical Artificial Intelligence 35, 5 (2023), 629–648. doi:10.1080/0952813X.2021.1960641 [90] Behrouz Pourghebleh, Karzan Wakil, and Nima Jafari Navimipour. 2019. A comprehensive study on the trust management techniques in the Internet of Things. IEEE Internet of Things Journal 6, 6 (2019), 9326–9337. [91] Shahana Gajala Qureshi and Shishir Kumar Shandilya. 2022. Nature-inspired adaptive decision support system for secured clustering in cyber networks. Multimedia Tools and Applications (2022). doi:10.1007/s11042-022-13336-7 [92] Mohamed Abdel Rahman, Ahmed Dahroug, and Sherin M. Moussa. 2023. Using Artificial Intelligence for Trust Management Systems in Fog Computing: A Comprehensive Study. In Progress in Artificial Intelligence, EPIA 2023, PT II, N Moniz, Z Vale, J Cascalho, C Silva, and R Sebastiao (Eds.). Lecture Notes in Artificial Intelligence, Vol. 14116. SPRINGER INTERNATIONAL PUBLISHING AG, 453–466. doi:10.1007/978-3-031-49011-8_36 [93] Subash Rajendran and R. Jebakumar. 2022. Friendliness Based Trustworthy Relationship Management (F-TRM) in Social Internet of Things. Wireless Personal Communications 123, 3 (2022), 2625–2647. doi:10.1007/s11277-021-09256-8 [94] Tharindu Ranathunga, Alan McGibney, and Susan Rea. 2021. The convergence of Blockchain and Machine Learning for Decentralized Trust Management in IoT Ecosystems. In Proceedings of the 2021 the 19th ACM Conference on Embedded Networked Sensor Systems, SENSYS 2021. ASSOC COMPUTING MACHINERY, 499–504. doi:10.1145/3485730.3493375 [95] Geetanjali Rathee, Hemraj Saini, Selvaraj Praveen Chakkravarthy, and Rajagopal Maheswar. 2025. An Intelligent and Trust-Enabled Farming Systems With Blockchain and Digital Twins on Mobile Edge Computing. International Journal of Network Management 35, 1 (2025). doi:10.1002/nem.2299 [96] Rashmi Ratnayake, Madhusanka Liyanage, and Liam Murphy. 2024. Machine Learning for Data Trust Evaluations in Blockchain-Enabled IoT Systems. In 2024 IEEE International Conference on Blockchain and Cryptocurrency, ICBC 2024. IEEE. doi:10.1109/ICBC59979.2024.10634433 [97] M. Venkata Krishna Reddy, Sivaneasan Bala Krishnan, Amjan Shaik, and Prasun Chakrabarti. 2025. AI-integrated adaptive MANET framework for IoT-driven healthcare systems: enhancing scalability, security, and real-time communication. European Physical Journal Plus 140, 9 (2025). doi:10.1140/epjp/s13360-025-06863-3 Manuscript submitted to ACM
Trust in Edge-Enabled IoT Security: Features, Challenges and Research Directions
33
[98] Amjad Rehman, Kamran Ahmad Awan, Amal Al-Rasheed, Anees Ara, Fahad F. Alruwaili, Shaha Al-Otaibi, and Tanzila Saba. 2025. A novel hybrid fuzzy logic and federated learning framework for enhancing cybersecurity and fraud detection in IoT-enabled metaverse transactions. Egyptian Informatics Journal 30 (2025). doi:10.1016/j.eij.2025.100668 [99] Subhash Sagar, Adnan Mahmood, Quan Z Sheng, Wei Emma Zhang, Yang Zhang, and Jitander Kumar Pabani. 2024. Understanding the trustworthiness management in the social internet of things: A survey. Computer Networks 251 (2024), 110611. [100] Ahmed Salim, Walid Osamy, Ahmed Aziz, and Ahmed M. Khedr. 2022. SEEDGT: Secure and energy efficient data gathering technique for IoT applications based WSNs. Journal of Network and Computer Applications 202 (2022), 103353. doi:10.1016/j.jnca.2022.103353 [101] A. Sasikumar, Subramaniyaswamy Vairavasundaram, Ketan Kotecha, V. Indragandhi, Logesh Ravi, Ganeshsree Selvachandran, and Ajith Abraham. 2023. Blockchain-based trust mechanism for digital twin empowered Industrial Internet of Things. Future Generation Computer Systems-The International Journal of eScience 141 (2023), 16–27. doi:10.1016/j.future.2022.11.002 [102] Sachin Sharma, Mohammad Yahya, Anupriya Jain, Ahmed I. Alutaibi, Abdullah Baihan, Papiya Dutta, and Ahed Abugabah. 2025. Evaluation of Legitimacy of IoT Devices Based on an Energy-Efficient Trust Management Scheme in Information-Centric Networking. International Journal of Communication Systems 38, 9 (2025). doi:10.1002/dac.70085 [103] Vishal Sharma, Rohit Beniwal, and Vinod Kumar. 2024. Multi-level trust-based secure and optimal IoT-WSN routing for environmental monitoring applications. Journal of Supercomputing 80, 8 (2024), 11338–11381. doi:10.1007/s11227-023-05875-z [104] Xuanzhu Sheng, Yang Zhou, and Xiaolong Cui. 2024. Graph Neural Network Based Asynchronous Federated Learning for Digital Twin-Driven Distributed Multi-Agent Dynamical Systems. Mathematics 12, 16 (2024). doi:10.3390/math12162469 [105] Mirsaeid Hosseini Shirvani and Mohammad Masdari. 2023. A survey study on trust-based security in Internet of Things: Challenges and issues. Internet of Things 21 (2023), 100640. [106] Sushil Kumar Singh and Jong Hyuk Park. 2023. TaLWaR: Blockchain-Based Trust Management Scheme for Smart Enterprises With Augmented Intelligence. IEEE Transactions on Industrial Informatics 19, 1 (2023), 626–634. doi:10.1109/TII.2022.3204692 [107] Avishek Sinha, Samayveer Singh, and Harsh K. Verma. 2024. AI-Driven Task Scheduling Strategy with Blockchain Integration for Edge Computing. Journal of Grid Computing 22, 1 (2024), 13. doi:10.1007/s10723-024-09743-9 [108] Alireza Souri, Yanlei Zhao, Mingliang Gao, Asghar Mohammadian, Jin Shen, and Eyhab Al-Masri. 2024. A Trust-Aware and Authentication-Based Collaborative Method for Resource Management of Cloud-Edge Computing in Social Internet of Things. IEEE Transactions on Computational Social Systems 11, 4 (2024), 4899–4908. doi:10.1109/TCSS.2023.3241020 [109] Panjun Sun, Yi Wan, Zongda Wu, Zhaoxi Fang, and Qi Li. 2025. A survey on privacy and security issues in IoT-based environments: Technologies, protection measures and future directions. Computers & Security 148 (2025), 104097. [110] Wenjie Sun, Guodong Peng, Wenchao Pan, Junlei Deng, Xuemei Cui, and Feng Lin. 2024. Trust Management as a Service for RFID Based Applications in Edge Enabled Cloud. In Computer Networks and IoT, PT 3, IAIC 2023, H Jin, Y Pan, and J Lu (Eds.). Communications in Computer and Information Science, Vol. 2060. SPRINGER-VERLAG SINGAPORE PTE LTD, 44–55. doi:10.1007/978-981-97-1332-5_4 [111] Tidiane Sylla, Mohamed Aymen Chalouf, Francine Krief, and Karim Samake. 2021. SETUCOM: Secure and Trustworthy Context Management for Context-Aware Security and Privacy in the Internet of Things. Security and Communication Networks 2021 (2021), 6632747. doi:10.1155/2021/6632747 [112] Timothy Tadj, Reza Arablouei, and Volkan Dedeoglu. 2023. On Evaluating IoT Data Trust via Machine Learning. Future Internet 15, 9 (2023), 309. doi:10.3390/fi15090309 [113] Taichi Takemura, Ryo Yamamoto, and Kuniyasu Suzaki. 2024. TEE-PA: TEE Is a Cornerstone for Remote Provenance Auditing on Edge Devices With Semi-TCB. IEEE Access 12 (2024), 26536–26549. doi:10.1109/ACCESS.2024.3366344 [114] Vasileios Tsekenis, Sokratis Barmpounakis, and Panagiotis Demestichas. 2025. Flexible Topologies for Efficient Network Coverage Expansion, Sustainability and Trust. In 2025 IEEE Wireless Communications and Networking Conference, WCNC, IEEE (Ed.). IEEE. doi:10.1109/WCNC61545. 2025.10978603 [115] Yusuf Kursat Tuncel and Kasim Oztoprak. 2025. SAFE-CAST: secure AI-federated enumeration for clustering-based automated surveillance and trust in machine-to-machine communication. PeerJ Computer Science 11 (2025). doi:10.7717/peerj-cs.2551 [116] Victoriia Turkina and Dmytro Ihnatiev. 2020. Approach to Sustainable Trust and Reputation Evaluation in Distributed Mobile Networks of the Internet of Things. In 2020 IEEE 11th International Conference on Dependable Systems, Services and Technologies (DESSERT): IoT, Big Data and AI for a Safe & Secure World and Industry 4.0. IEEE, 117–121. doi:10.1109/dessert50317.2020.9125015 [117] Himani Tyagi, Rajendra Kumar, and Santosh Kr Pandey. 2023. A detailed study on trust management techniques for security and privacy in IoT: Challenges, trends, and research directions. High-Confidence Computing 3, 2 (2023), 100127. [118] Richa Verma and Shalini Chandra. 2023. RepuTE: A soft voting ensemble learning framework for reputation-based attack detection in fog-IoT milieu. Engineering Applications of Artificial Intelligence 118 (2023), 105670. doi:10.1016/j.engappai.2022.105670 [119] Bingquan Wang, Jin Peng, and Meili Cui. 2024. Secure access technology for industrial internet of things. Concurrency and Computation-Practice & Experience 36, 25 (2024). doi:10.1002/cpe.8231 [120] Bo Wang, Jiesheng Wang, and Mingchu Li. 2025. A Method for Trust-Based Collaborative Smart Device Selection and Resource Allocation in the Financial Internet of Things. Sensors 25, 13 (2025). doi:10.3390/s25134082 [121] Chenyu Wang, Zhipeng Cai, Daehee Seo, and Yingshu Li. 2023. TMETA: Trust Management for the Cold Start of IoT Services With Digital-TwinAided Blockchain. IEEE Internet of Things Journal 10, 24 (2023), 21337–21348. doi:10.1109/JIOT.2023.3285108 Manuscript submitted to ACM
34
Aydin et al.
[122] Chengna Wang, Jiahao Zhang, Sen Zhang, and Xingze Wu. 2025. Trust evaluation mechanism for data collection in smart cities. Discover Computing 28, 1 (2025). doi:10.1007/s10791-025-09577-3 [123] Jie Wang, Zheng Yan, Haiguang Wang, Tieyan Li, and Witold Pedrycz. 2022. A survey on trust models in heterogeneous networks. IEEE Communications Surveys & Tutorials 24, 4 (2022), 2127–2162. [124] Tian Wang, Hao Luo, Weijia Jia, Anfeng Liu, and Mande Xie. 2020. MTES: An Intelligent Trust Evaluation Scheme in Sensor-Cloud-Enabled Industrial Internet of Things. IEEE Transactions on Industrial Informatics 16, 3 (2020), 2054–2062. doi:10.1109/TII.2019.2930286 [125] Tian Wang, Bing Sun, Liang Wang, Xi Zheng, and Weijia Jia. 2023. EIDLS: An Edge-Intelligence-Based Distributed Learning System Over Internet of Things. IEEE Transactions on Systems Man Cybernetics-Systems 53, 7 (2023), 3966–3978. doi:10.1109/TSMC.2023.3240992 [126] Tian Wang, Pan Wang, Shaobin Cai, Xi Zheng, Ying Ma, Weijia Jia, and Guojun Wang. 2021. Mobile edge-enabled trust evaluation for the Internet of Things. Information Fusion 75 (2021), 90–100. doi:10.1016/j.inffus.2021.04.007 [127] Yingxun Wang, Adnan Mahmood, Mohamad Faizrizwan Mohd Sabri, and Hushairi Zen. 2026. Trust Management in the Internet of Vehicles: A Survey of the State-of-the-Art. IEEE Open Journal of Intelligent Transportation Systems (2026). [128] Yingxun Wang, Hushairi Zen, Mohamad Faizrizwan Mohd Sabri, Xiang Wang, and Lee Chin Kho. 2022. Towards Strengthening the Resilience of IoV Networks-A Trust Management Perspective. Future Internet 14, 7 (2022), 202. doi:10.3390/fi14070202 [129] Zihao Wang, Yusun Fu, and Xin Lin. 2025. Attribute-Based Bilateral Access Control With Sanitization and Trust Management for IIoT. IEEE Internet of Things Journal 12, 8 (2025), 10818–10833. doi:10.1109/JIOT.2024.3513454 [130] Mohammad Wazid, Ashok Kumar Das, and Sachin Shetty. 2022. TACAS-IoT: Trust Aggregation Certificate-Based Authentication Scheme for Edge-Enabled IoT Systems. IEEE Internet of Things Journal 9, 22 (2022), 22643–22656. doi:10.1109/JIOT.2022.3181610 [131] Xinyin Xiang, Jin Cao, and Weiguo Fan. 2025. Secure Authentication and Trust Management Scheme for Edge AI-Enabled Cyber-Physical Systems. IEEE Transactions on Intelligent Transportation Systems 26, 3 (2025), 3237–3249. doi:10.1109/TITS.2025.3529691 [132] Zebin Xiang, Jiujun Cheng, Cong Liu, Qichao Mao, Guiyuan Yuan, and Shangce Gao. 2025. Privacy-Preserving Autonomous Vehicle Group Formation in a Collusive Attack Scenario. IEEE Internet of Things Journal 12, 13 (2025), 25576–25586. doi:10.1109/JIOT.2025.3559151 [133] Ruoting Xiong, Wei Ren, Xiaohan Hao, Jie He, and Kim-Kwang Raymond Choo. 2023. BDIM: A Blockchain-Based Decentralized Identity Management Scheme for Large Scale Internet of Things. IEEE Internet of Things Journal 10, 24 (2023), 22581–22590. doi:10.1109/JIOT.2023.3303922 [134] Qian Xu, Lei Zhang, Yixiao Liu, and Zhenning Li. 2026. Enhancing Trust Management System for Connected Autonomous Vehicles Using Machine Learning Methods: A Survey. IEEE Transactions on Intelligent Transportation Systems 27, 4 (2026), 3862–3893. doi:10.1109/TITS.2025.3647284 [135] Ya-Ting Yang, Haozhe Lei, and Quanyan Zhu. 2025. PRADA: Proactive Risk Assessment and Mitigation of Misinformed Demand Attacks on Navigational Route Recommendations. IEEE Transactions on Information Forensics and Security 20 (2025), 10879–10892. doi:10.1109/TIFS.2025. 3615726 [136] Zhigang Yang, Ruyan Wang, Dapeng Wu, Boran Yang, and Puning Zhang. 2023. Blockchain-Enabled Trust Management Model for the Internet of Vehicles. IEEE Internet of Things Journal 10, 14 (2023), 12044–12054. doi:10.1109/JIOT.2021.3124073 [137] Chaodong Yu, Geming Xia, Linxuan Song, Wei Peng, Jian Chen, Danlei Zhang, and Hongfeng Li. 2023. CET-AoTM: Cloud-Edge-Terminal Collaborative Trust Evaluation Scheme for AIoT Networks. In Service-Oriented Computing, ICSOC 2023, PT II, F Monti, S Rinderle-Ma, AR Cortes, Z Zheng, and M Mecella (Eds.). Lecture Notes in Computer Science, Vol. 14420. SPRINGER INTERNATIONAL PUBLISHING AG, 143–158. doi:10.1007/978-3-031-48424-7_11 [138] Ya Yu, Qiucheng Lu, and Yusun Fu. 2024. Dynamic Trust Management for the Edge Devices in Industrial Internet. IEEE Internet of Things Journal 11, 10 (2024), 18410–18420. doi:10.1109/JIOT.2024.3361914 [139] Susan Zehra, Syed R. Rizvi, and Samy El-Tawab. 2024. A Novel Framework to Safeguard Inter-Vehicular Communication and Privacy. In 2024 IEEE Global Conference on Artificial Intelligence and Internet of Things, GCAIOT. IEEE, 44–51. doi:10.1109/GCAIOT63427.2024.10833585 [140] Chenyue Zhang, Wenjia Li, Yuansheng Luo, and Yupeng Hu. 2021. AIT: An AI-Enabled Trust Management System for Vehicular Networks Using Blockchain Technology. IEEE Internet of Things Journal 8, 5 (2021), 3157–3169. doi:10.1109/JIOT.2020.3044296 [141] Feng Zhang, Hao Wang, Lu Zhou, Dequan Xu, and Liang Liu. 2023. A blockchain-based security and trust mechanism for AI-enabled IIoT systems. Future Generation Computer Systems-The International Journal of eScience 146 (2023), 78–85. doi:10.1016/j.future.2023.03.011 [142] Rui Zhang, Anfeng Liu, Tian Wang, Neal N. Xiong, and Athanasios V. Vasilakos. 2024. A trust active and Trace back based trust Management system about effective data collection for mobile IoT services. Information Sciences 664 (2024). doi:10.1016/j.ins.2024.120329 [143] Yi Zhang, Chunxiao Jiang, and Peiying Zhang. 2024. Security-Aware Resource Allocation Scheme Based on DRL in Cloud-Edge-Terminal Cooperative Vehicular Network. IEEE Internet of Things Journal 11, 1 (2024), 95–104. doi:10.1109/JIOT.2023.3293497 [144] Yan Zhang, Yun Yu, Wujie Sun, and Zaihui Cao. 2024. Towards an energy-aware two-way trust routing scheme in fog computing environments. Telecommunication Systems 87, 4 (2024), 973–989. doi:10.1007/s11235-024-01226-2 [145] Xiaogang Zhu, Feicheng Ma, Feng Ding, Zhiwei Guo, Junchao Yang, and Keping Yu. 2024. A Low-Latency Edge Computation Offloading Scheme for Trust Evaluation in Finance-Level Artificial Intelligence of Things. IEEE Internet of Things Journal 11, 1 (2024), 114–124. doi:10.1109/JIOT.2023. 3297834
Manuscript submitted to ACM