SafeIoT Logo

Open-Source Ecosystem

SafeIoT Center: Continuously Verifying and Benchmarking Security and Privacy in IoT Standards and Systems

SafeIoT is a non-profit initially funded by NSF to advance security and privacy assurance for IoT standards and their real-world implementations through open-source tools and community-driven research.

Our Vision

Consumers increasingly rely on IoT products for home safety, health, and everyday convenience. Yet a critical gap persists: popular IoT standards, their open-source implementation, and IoT vendors' implementation lack holistic, rigorous security and privacy verification — from empirical and human-centered evaluation, to vulnerability detection grounded in systematic or mathematical formal methods. The SafeIoT center addresses this gap by establishing a community-driven open-source ecosystem with a CI/CD infrastructure that continuously verifies open-source IoT standards and IoT vendor's implementations, with an initial focus on the Matter standard and SBOM in IoT context.

We envision that every IoT standard and standardization update is accompanied by timely, rigorous, and human-centered security verification — covering specification documents, technical design, implementation, configuration, and cybersecurity labels.

SafeIoT's CI/CD infrastructure will be maintained by a distributed community of contributors from industry, academia, government, and the open-source community, ensuring continuous security assurance as IoT standards and their real-world implementations evolve.

SafeIoT Open-Source CI/CD Pipeline

SafeIoT Center maintains an open-source pipeline that incorporates and operationalizes state-of-the-art tools and systems to continuously verify the security and privacy of IoT standards, such as Matter, and consumer IoT products and systems, such as Google Home, Apple Home, and SmartThings.

SafeIoT CI/CD pipeline overview
SafeIoT CI/CD pipeline for continuously verifying IoT standards, products, and implementations.

Examples of Open-Source Tools Deployed on the SafeIoT CI/CD Pipeline

Implementation Verification

UMCCI Checker

Automatically identifies security vulnerabilities in IoT vendors' Matter SDK integrations. The flaws it found have been fixed by CSA, Apple, Google, SmartThings, Comcast, and Tuya.

Protocol Design Verification

VerioT

Formally verifies the design of standard IoT protocols via automated model checking. Reported 30+ vulnerabilities adopted by 100+ IoT vendors.

Configuration Verification

P-Verifier

Formally verifies IoT access control policies. Adopted by AWS as part of AWS IoT Device Defender; also adopted by the UK Ministry of Defence.

Cybersecurity Label Verification

Lalaine

Verifies cybersecurity labels of mobile apps. Has detected thousands of non-compliant iOS apps from the Apple App Store. Adopted by the FTC.

Support

SafeIoT Center is supported by NSF, UIUC, UNC Charlotte, and Indiana University.

Community Building

SafeIoT Hackathon

As part of the SafeIoT community engagement effort, we host a series of online competitions inviting engineers, researchers, and students to contribute tools and approaches that can be added to the SafeIoT CI/CD pipeline and applied to real-world IoT security and privacy challenges.

Submission Deadline

November 30, 2026 — 11:59pm (AoE)

SafeIoT Hackathon submissions are due by 11:59pm on November 30, 2026, Anywhere on Earth (AoE) — your submission is on time as long as it is still November 30 somewhere in the world (UTC−12).

Info Webinar

September 15th, 2026 — 9–10am CDT

Organizers will host a live session walking through the hackathon — tracks, submission requirements, and evaluation criteria — and answering questions from participants.

  • Who Should Join: Students, security researchers, software engineers, and IoT developers.
  • What You'll Build: Open-source tools or prototypes that can be integrated into the SafeIoT pipeline to verify specific security or privacy issues in consumer IoT, IoT standards, and implementations of those standards.
  • Impact: Your work will directly improve security assurance for IoT standards used by hundreds of millions of consumer devices worldwide.

Hackathon Tracks

Track 1

IoT Vulnerability Detection

Tools and systems that identify vulnerabilities from IoT standards and implementations of those standards, including open-source projects and commodity IoT products such as Google Home, Apple Home, and SmartThings.

Full track requirements →

Track 2

IoT SBOM, CBOM, and AI-BOM Verification

Tools and systems that identify security, privacy and compliance issues related to Software Bills of Materials (SBOMs), Cryptographic Bills of Materials (CBOMs), and AI Bills of Materials (AI-BOMs) for IoT systems, products, or open-source projects.

Full track requirements →

Competition Rules

The hackathon is a project competition. Any open-source software related to security and privacy in IoT standards and systems is eligible. Your submission must align with one of the two tracks above and show how the tool or approach could fit into the SafeIoT pipeline — see each track for its detailed requirements.

A complete submission has three parts: a scientific paper, a public code repository, and a pitch video. All three are required to be considered for an award.

  1. Scientific paper, up to 5 pages — a PDF in double-column ACM format presenting your work as a research contribution.
  2. Code repository — publicly accessible by the deadline, with setup, usage, and reproducibility instructions.
  3. Pitch video, max 5 minutes — using the official slides template.

Evaluation Criteria

Technical Innovation

How novel the approach is, and what it can verify that existing tools cannot.

Methodological Rigor

Clear rules and ground truth, representative data, comparison against baselines, and quantitative results.

Impact Potential

Usefulness to manufacturers, auditors, regulators, and buyers — and how well it scales across IoT domains.

Clarity and Presentation

A clear end-to-end pipeline, and honesty about what is automated, what needs manual review, and what stays unverifiable.

Prizes

Prizes are awarded across both hackathon tracks combined, not separately per track: first, second, and third place will be selected from all participants. Issuing of the monetary prizes is subject to final security and compliance checks, while the certificates for winners will be guaranteed. To qualify for the award, award winners should agree to deploy their tool/artifacts as open-source components to the SafeIoT CI/CD pipeline, under a permissive open-source license (e.g., MIT, Apache 2.0, or BSD).

1st Place

$2,500

Certificate of Excellence + invitation to present at SDIoTSec '27 workshop

2nd Place

$1,000

Certificate of Excellence + invitation to present at SDIoTSec '27 workshop

3rd Place

$800

Certificate of Excellence + invitation to present at SDIoTSec '27 workshop

Organizers

Luyi Xing headshot

Luyi Xing

Associate Professor of Computer Science, UIUC

Jean Camp headshot

Jean Camp

Distinguished Professor, UNC Charlotte

Xiaojing Liao headshot

Xiaojing Liao

Associate Professor of Computer Science, UIUC

Yue Xiao headshot

Yue Xiao

Assistant Professor of Computer Science, William & Mary

Long Cheng headshot

Long Cheng

Associate Professor, Clemson University

Industry Mentor

Brian LaMacchia headshot

Brian LaMacchia

Industry Mentor

Hackathon Judges

The judging team will include leading experts from industry and academia, with the full roster to be announced soon.

FAQ

Who can participate?

Anyone with an interest in IoT security — students, professionals, and researchers.

Is it free to enter?

Yes, participation is completely free.

Do I need a team?

You can apply solo or as a team of up to 4.

What background do I need?

Familiarity with software security, systems programming, or IoT is helpful. We will provide onboarding materials and mentor support throughout the event.

Who can I contact with questions?

Please email sdiotsec@gmail.com with any questions.