ThermoTrust: Self-Supervised Thermal Vision for Runtime Detection of Hardware Trojans and Malicious Firmware in Edge Devices

Authors

  • Mahmoud AlJamal Department of Cybersecurity, Irbid National University, Irbid, Jordan.
  • Ahmad Alkhatib Cyber security department, Alzaytoonah university of Jordan.
  • Mohammad Anakrh Department of Cybersecurity, Irbid National University, Irbid, Jordan.
  • Ayoub Alsarhan Department of Data Science and Artificial Intelligence, Faculty of Information Technology, Al-Ahliyya Amman University, Amman 19111, Jordan & Department of Information Technology, Faculty of Prince Al-Hussien bin Abdullah, The Hashemite University, Zarqa 13133, Jordan.
  • Ahmed Al Nuaim Department of Management Information Systems, School of Business, King Faisal University, Al Ahsa 31982, Saudi Arabia.
  • Abdullah Al Nuaim Department of Management Information Systems, School of Business, King Faisal University, Al Ahsa 31982, Saudi Arabia.
  • Naif Almusallam Department of Management Information Systems, School of Business, King Faisal University, Al Ahsa 31982, Saudi Arabia.
  • Mohammed Alnaeem Department of Computer Networks and Communications, College of Computer Sciences & Information, King Faisal University, Al Ahsa 31982, Saudi Arabia.

DOI:

https://doi.org/10.56979/1101/2026/1484

Keywords:

hardware Trojan detection, malicious firmware, thermal imaging, self-supervised learning, edge-device security, side-channel analysis

Abstract

Attackers can alter the runtime behavior of edge devices through Hardware Trojans and malicious firmware without producing clearly observable changes in network traffic or file-system activity. Existing integrity-monitoring approaches commonly depend on golden references, labeled attack traces, static firmware inspection, or intrusive side-channel instrumentation. This study proposes ThermoTrust, an integrated self-supervised thermal-vision framework that learns device-specific normal thermal behavior and detects previously unseen integrity deviations through spatial-temporal residual learning and firmware-state consistency analysis. The framework is evaluated using a controlled thermal protocol aligned with the publicly available Hardware Trojan Power and Electromagnetic Side-Channel Dataset, which includes twelve Trust-Hub AES Trojan benchmarks under disabled, enabled, and triggered operating conditions. ThermoTrust combines emissivity-normalized thermal frames, masked spatial-temporal reconstruction, persistent residual scoring, and firmware-state mismatch estimation to generate a composite runtime integrity score and localized thermal evidence. The experimental evaluation comprises 12,000 thermal windows distributed across normal operation, firmware deviation, and Trojan activation conditions. ThermoTrust achieves 97.44% accuracy, 97.55% precision, 97.33% recall, a 97.44% F1-score, an area under the receiver operating characteristic curve of 0.992, and an inference latency of 18.6 ms. The results demonstrate that combining self-supervised thermal normality learning with firmware-aware consistency analysis provides accurate, lightweight, and contactless runtime integrity monitoring for edge devices.

Downloads

Published

2026-06-01

How to Cite

Mahmoud AlJamal, Ahmad Alkhatib, Mohammad Anakrh, Ayoub Alsarhan, Ahmed Al Nuaim, Abdullah Al Nuaim, Naif Almusallam, & Mohammed Alnaeem. (2026). ThermoTrust: Self-Supervised Thermal Vision for Runtime Detection of Hardware Trojans and Malicious Firmware in Edge Devices. Journal of Computing & Biomedical Informatics, 11(01). https://doi.org/10.56979/1101/2026/1484