SafeIoT Logo

Open-Source Ecosystem

SafeIoT Center: Continuously Verifying and Benchmarking Security and Privacy in IoT Standards and Systems

SafeIoT is a non-profit initially funded by NSF to advance security and privacy assurance for IoT standards and their real-world implementations through open-source tools and community-driven research.

Our Vision

Consumers increasingly rely on IoT products for home safety, health, and everyday convenience. Yet a critical gap persists: popular IoT standards, their open-source implementation, and IoT vendors' implementation lack holistic, rigorous security and privacy verification — from empirical and human-centered evaluation, to vulnerability detection grounded in systematic or mathematical formal methods. The SafeIoT center addresses this gap by establishing a community-driven open-source ecosystem with a CI/CD infrastructure that continuously verifies open-source IoT standards and IoT vendor's implementations, with an initial focus on the Matter standard and SBOM in IoT context.

We envision that every IoT standard and standardization update is accompanied by timely, rigorous, and human-centered security verification — covering specification documents, technical design, implementation, configuration, and cybersecurity labels.

SafeIoT's CI/CD infrastructure will be maintained by a distributed community of contributors from industry, academia, government, and the open-source community, ensuring continuous security assurance as IoT standards and their real-world implementations evolve.

SafeIoT Open-Source CI/CD Pipeline

SafeIoT Center maintains an open-source pipeline that incorporates and operationalizes state-of-the-art tools and systems to continuously verify the security and privacy of IoT standards, such as Matter, and consumer IoT products and systems, such as Google Home, Apple Home, and SmartThings.

SafeIoT CI/CD pipeline overview
SafeIoT CI/CD pipeline for continuously verifying IoT standards, products, and implementations.

Examples of Open-Source Tools Deployed on the SafeIoT CI/CD Pipeline

Implementation Verification

UMCCI Checker

Automatically identifies security vulnerabilities in IoT vendors' Matter SDK integrations. Adopted by CSA, Apple, Google, SmartThings, Comcast, and Tuya.

Protocol Design Verification

VerioT

Formally verifies the design of standard IoT protocols via automated model checking. Reported 30+ vulnerabilities adopted by 100+ IoT vendors.

Configuration Verification

P-Verifier

Formally verifies IoT access control policies. Adopted by AWS as part of AWS IoT Device Defender; also adopted by the UK Ministry of Defence.

Cybersecurity Label Verification

Lalaine

Verifies cybersecurity labels of mobile apps. Has detected thousands of non-compliant iOS apps from the Apple App Store. Adopted by the FTC.

Support

SafeIoT Center is supported by NSF, UIUC, UNC Charlotte, and Indiana University.

Community Building

SafeIoT Hackathon

The details of the Hackathon are subject to changes.

As part of the SafeIoT community engagement effort, we host a series of online competitions inviting engineers, researchers, and students to contribute tools and approaches that can be added to the SafeIoT CI/CD pipeline and applied to real-world IoT security and privacy challenges.

Submission Deadline

11:59pm, October 23rd, 2026 (AoE)

SafeIoT Hackathon submissions are due by 11:59pm on October 23rd, 2026 (AoE).

  • Who Should Join: Students, security researchers, software engineers, and IoT developers.
  • What You'll Build: Open-source tools or prototypes that can be integrated into the SafeIoT pipeline to verify specific security or privacy issues in consumer IoT, IoT standards, and implementations of those standards.
  • Impact: Your work will directly improve security assurance for IoT standards used by hundreds of millions of consumer devices worldwide.

Hackathon Tracks

Track 1

IoT Vulnerability Detection

Tools and systems that identify vulnerabilities from IoT standards and implementations of those standards, including open-source projects and commodity IoT products such as Google Home, Apple Home, and SmartThings.

Track 2

IoT SBOM, CBOM, and AI-BOM Verification

Tools and systems that identify security, privacy and compliance issues related to Software Bills of Materials (SBOMs), Cryptographic Bills of Materials (CBOMs), and AI Bills of Materials (AI-BOMs) for IoT systems, products, or open-source projects.

Competition Rules

The hackathon is a project competition. Any open-source software related to security and privacy in IoT standards and systems is eligible. Submissions should align with one of the two hackathon tracks, demonstrate how the tool or approach could fit into the SafeIoT pipeline, and may include:

  • Automated IoT vulnerability detection
  • Formal modeling and verification of IoT systems or protocols
  • IoT privacy compliance analysis
  • IoT application configuration checking

Evaluation Criteria

Metric 1

Innovation Value
  • Significance of contribution to real-world IoT ecosystem security
  • Novelty and creativity of the approach
  • Potential for adoption or integration into existing security pipelines

Metric 2

Engineering Quality
  • Code quality, clarity, and documentation
  • Reliability and robustness for real-world IoT systems and use cases.
  • Ease of use and reproducibility

Prizes

Issuing of the monetary prizes is subject to final security and compliance checks, while the certificates for winners will be guaranteed. To qualify for the award, award winners should agree to deploy their tool/artifacts as open-source components to the SafeIoT CI/CD pipeline, under one of our designated open-source licenses such as MIT license.

1st Place

$2,500

Certificate of Excellence + invitation to present at SDIoTSec '27 workshop

2nd Place

$1,000

Certificate of Excellence + invitation to present at SDIoTSec '27 workshop

3rd Place

$800

Certificate of Excellence + invitation to present at SDIoTSec '27 workshop

Organizers

Luyi Xing headshot

Luyi Xing

Associate Professor of Computer Science, UIUC

Jean Camp headshot

Jean Camp

Distinguished Professor, UNC Charlotte

Xiaojing Liao headshot

Xiaojing Liao

Associate Professor of Computer Science, UIUC

Brian LaMacchia headshot

Brian LaMacchia

Industry Mentor

Yue Xiao headshot

Yue Xiao

Assistant Professor of Computer Science, William & Mary

Long Cheng headshot

Long Cheng

Associate Professor, Clemson University

FAQ

Who can participate?

Anyone with an interest in IoT security — students, professionals, and researchers.

Is it free to enter?

Yes, participation is completely free.

Do I need a team?

You can apply solo or as a team of up to 4.

What background do I need?

Familiarity with software security, systems programming, or IoT is helpful. We will provide onboarding materials and mentor support throughout the event.

What is the Matter standard?

Matter is a major industry-unifying open-source standard for IoT design and implementation, backed by Amazon, Apple, Google, and hundreds of other vendors. SafeIoT's initial verification efforts focus on Matter.

Who can I contact with questions?

Please email sdiotsec@gmail.com with any questions.