ACKNOWLEDGMENT: REBECCA project is supported by the Chips Joint Undertaking and its members, including the top-up funding by National Authorities under grant agreement n° 101097224. Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the granting authority. Neither the European Union nor the granting authority can be held responsible for them.



Leveraging Intrusion Detection in Low-Power ASICs at the Edge

As organizations increasingly adopt distributed architectures powered by cloud computing, IoT devices, and remote workforces, the traditional network perimeter is gradually disappearing. This shift creates a new security reality, where protection mechanisms must move closer to the locations where data is generated, processed, and transmitted.
The REBECCA project recognizes this need and addresses it through the integration of intrusion detection capabilities directly at the edge. By deploying an Intrusion Detection System (IDS) close to the source of data, REBECCA aims to improve the ability of edge devices to detect potentially malicious activity in real time, while operating within the constraints of low-power embedded systems.
Edge computing improves performance and reduces latency by processing data near its source. However, it also introduces new security challenges. Edge devices may become attractive targets for cyber attackers seeking entry points into larger networks. In other cases, attackers may attempt to force devices to malfunction, report false data, or crash entirely.
This is where intrusion detection becomes particularly important. IDS mechanisms can identify suspicious host behaviour, abnormal network traffic, or known attack patterns that may indicate a potential threat. This capability is especially valuable in today’s rapidly evolving threat landscape, where edge devices are increasingly exposed to sophisticated attacks.
Within REBECCA, a signature-based IDS module has been introduced into the ASIC design. It is one of the three main functional modules that complement the RISC-V-based subsystem, alongside a neuromorphic processor and a near-memory processor. The IDS module contributes to the security capabilities of the REBECCA architecture by enabling the detection of known attacks at the edge.
The IDS module was initially verified using FPGA-based emulation prototypes, including platforms such as the Alveo U55 and the ALINX AXKU15. It was developed using HLS tools and then integrated into the broader REBECCA architecture for verification. During the early stages, dummy data were used for initial validation. Subsequently, real-life datasets were employed to verify the module’s functional behaviour against attacks such as Denial of Service, Man-in-the-Middle, IP spoofing, and other common threat scenarios.
This work is particularly important for REBECCA, as two of the project’s use cases are related to unmanned drones, where security, reliability, and real-time response are critical.
Key outcomes
Development of an intrusion detection module for edge devices
Integration of the IDS module into the REBECCA ASIC architecture
Verification of the IDS module using real-life datasets covering known attacks such as DoS, MITM, and IP spoofing