The rapid proliferation of Internet of Things (IoT) devices under sixth-generation (6G) networks introduces a highly dynamic, decentralized environment in which static, perimeter-based security models are no longer adequate. This paper proposes AZTM-v3 an adaptive Zero Trust framework that couples behavior-driven trust management with a Random Forest classifier to identify and isolate malicious nodes in real time. The framework is evaluated on an NS-3 simulation of a 150-node 6G IoT network subjected to Sybil, Denial-of-Service (DoS), spoofing, replay and ON-OFF attacks. Unlike prior trust-management proposals that report only qualitative or partial outcomes this work quantifies performance across five dimensions i.e detection accuracy, F1-score, false-positive rate, end-to-end latency and consensus-convergence time and benchmarks AZTM-v3 against PKI-based, centralized-trust and static-blockchain baselines. AZTM-v3 attains a 98.1% overall detection accuracy with a 1.6% false-positive rate at 150 nodes and sustains 95.4% accuracy at 200 nodes outperforming the PKI baseline by 12–18 percentage points across all tested loads. These results indicate that combining tiered trust evaluation with machine learning based classification yields a measurably more scalable and resilient security layer for 6G-enabled IoT deployments than existing static or purely cryptographic approaches.
Introduction
The text presents AZTM-v3 (Adaptive Zero Trust Manager v3), a security framework designed for the rapidly expanding and highly dynamic IoT environments expected in 6G networks.
The main problem is that traditional IoT security relies on static trust policies, predefined rules, or centralized authorities, which are poorly suited to networks where devices frequently join, leave, or change their behavior. Such environments are vulnerable to attacks including Sybil, DoS, spoofing, and replay attacks.
AZTM-v3 addresses these challenges by combining:
Dynamic, behavior-based trust scoring based on communication behavior, packet handling, and anomaly history.
A three-tier trust assessment mechanism to identify normal, suspicious, and malicious nodes.
Random Forest machine learning to classify node behavior and detect attacks.
Automatic quarantine or isolation of nodes whose trust scores fall below a predefined threshold.
Adaptive trust updates, allowing the system to respond to both gradual behavioral changes and sudden attacks.
NS-3 simulation using approximately 150 nodes to evaluate the framework under different attack scenarios.
The related-work analysis shows that previous approaches often focus on only one aspect of security, such as blockchain, lightweight encryption, physical-layer protection, or trust management. They also suffer from problems such as scalability, latency, implementation complexity, static trust models, and limited simulation-based validation.
The research therefore aims to integrate machine learning, dynamic trust management, attack simulation, and quantitative performance evaluation into one lightweight framework. Performance is assessed using measures such as accuracy, F1-score, AUC, latency, false-positive rate, convergence time, throughput, packet loss, and packet delivery ratio, with comparisons against existing PKI, centralized-trust, and static-blockchain approaches.
Conclusion
AZTM-v3 is an adaptive trust management system designed to secure 6G-enabled IoT networks against both traditional and evolving cyberattacks. It outperforms static blockchain, centralized trust, and traditional PKI methods in detection ratio, false-positive reduction, latency, and consensus efficiency. The system effectively detects Sybil, DoS, spoofing, replay, and ON-OFF (sleeper) attacks, making it especially valuable for healthcare IoT, where delayed or disguised threats are most dangerous. By integrating machine learning with adaptive trust scoring, AZTM-v3 moves beyond fixed metrics to continuously refine trust evaluation, accurately flagging malicious devices while preserving trust in legitimate ones. Overall, AZTM-v3 offers a scalable, dynamic, and future-ready security solution for next-generation smart healthcare IoT. Future work includes incorporating federated learning, lightweight blockchain, and real-world deployment in healthcare sensor networks.
References
[1] D. P. Moya Osorio et al., \"Towards 6G-enabled Internet of Vehicles: Security and privacy,\" IEEE Open J. Commun. Soc., vol. 3, pp. 82–105, 2022.
[2] Y. Liu, J. Wang, Z. Yan, Z. Wan, and R. Jäntti, \"A survey on blockchain-based trust management for Internet of Things,\" IEEE Internet Things J., vol. 10, no. 7, pp. 5898–5922, Apr. 2023.
[3] L. Zhi et al., \"Self-powered absorptive reconfigurable intelligent surfaces for securing satellite-terrestrial integrated networks,\" China Commun., vol. 21, no. 9, pp. 276–291, Sep. 2024.
[4] I. Ahmad, F. Shahid, I. Ahmad, J. Islam, K. N. Haque, and E. Harjula, \"Adaptive lightweight security for performance efficiency in critical healthcare monitoring,\" in Proc. 18th Int. Symp. Med. Inf. Commun. Technol. (ISMICT), 2024, pp. 78–83.
[5] H. Moudoud, Z. Abou El Houda, and B. Brik, \"Zero trust security architecture for 6G open radio access networks (ORAN),\" IEEE Netw. Lett., vol. 6, no. 4, pp. 272–275, Dec. 2024.
[6] A. Pathak, I. Al-Anbagi, and H. J. Hamilton, \"SATI: Sidechain-based access control & trust mechanism for IoT networks,\" IEEE Trans. Netw. Service Manag., vol. 21, no. 5, pp. 5888–5903, Oct. 2024.