Wireless Sensor Networks · Study deck
Node Behaviour: Evidence and Taxonomy
A quiet node may be asleep, out of power, cut off, or selfish.
Packet Pete is your guide for this deck.

After studying this chapter
Evidence before a behaviour label
Node classification is a claim about observed behaviour with explicit limits.
- A behaviour label needs observations from the affected role.Link, power, clock, and route evidence help explain why the field sensor missed its expected reports.
- Missing messages and misleading readings are different decision problems.The room dashboard must distinguish an unavailable temperature source from a reporting source whose values cannot be trusted.
- Forwarding counts need the number of observed opportunities.A missing relay packet means little until the watchdog records how much shared work the node could have performed.
- A useful review connects confidence, action, and a retest trigger.The team can protect the affected decision while another observation tests the temporary behaviour label.
Major section
Three missed reports begin an investigation
A quiet field sensor needs a cause investigation before a blame label.
- Three missed reports are evidence of a symptom without a confirmed cause.Sleep, lost power, a weak link, stored data, and route behaviour are possible explanations for the quiet field sensor.
- The expected send plan defines which reports are actually missing.The last sound report and nearby nodes provide context for deciding whether this absence is local or shared.
- Power and clock evidence can coexist with a forwarding problem.A low cell and a missed forward may both be real, so the review may need a mixed or open label.
- A direct check can challenge the first explanation.A visit, new route, wake event, or later data return can disprove the temporary label before it becomes accepted blame.
Major section
A temporary label permits a narrow action
A temporary classification should permit a safe response while the evidence remains incomplete.
- Silence supports missing-data protection before any claim about intent.The operator can mark one stream stale while checking sleep, power, and the reporting path.
- Faulty sensing needs evidence about the readings themselves.A quiet radio alone cannot show whether the local sensor produces bad measurements or merely cannot deliver them.
- Selfish behaviour needs evidence of preserved own work and refused cooperation.The relay hypothesis becomes stronger when local reports arrive but agreed forwarding repeatedly fails under observed opportunities.
- The smallest safe action preserves useful network functions.Holding one stream, trying another route, or visiting the node can protect service without blocking a whole group.
Major section
Availability and trust are separate questions
Packet availability cannot establish whether the measurement deserves trust.
- A reporting node can still mislead the application.Packets that arrive on schedule may carry implausible values, invalid metadata, or contradictions that affect downstream decisions.
- Silence is usually easier to detect than believable but wrong data.The monitor can notice a missing report directly, while misleading values need validation and comparison evidence.
- Recent messages provide only part of the classification evidence.Plausible values, agreement with related nodes, assigned roles, and recovery state must also support the current decision.
- The behaviour label records the strength of the current evidence.Healthy, silent, suspect, and misleading describe an observed state that may change after further checks.
Major section
Plausibility does not establish correctness
A possible value still needs agreement with the context of the current decision.
- Plausibility rejects readings that cannot fit the known context.Impossible values, wrong units, stuck readings, and values outside the accepted band need a data-quality response.
- Consistency tests whether a possible reading fits related observations.A nearby node, repeated sample, reference observation, or linked process signal can expose a believable but incorrect measurement.
- A misleading source can keep influencing decisions while remaining available.Successful packet delivery cannot justify using a reading that repeatedly contradicts trustworthy related evidence.
- The review stays incomplete without an action and retest condition.The record must connect its evidence and confidence to a bounded response and the observation that could change that response.
Major section
Observations lead to a bounded decision
The classification path links questions to evidence and action; follow the checks downward and the dashed retest loop back.
- The top questions can separate observation, support, and safe action.The classification path asks what the monitor saw before deciding which label and response the evidence can justify.
- The evidence checks can examine both delivery and data trust.Message presence, plausibility, consistency, role behaviour, and recovery state contribute different observations to the classification.
- Confidence limits the action beneath the evidence checks.A missing message or contradictory value supports a scoped decision while uncertainty about cause remains recorded.
- The retest loop keeps the label open to revision.A reference check can restore a suspect node, while repeated contradictions can reopen a previously healthy classification.
Major section
Healthy, silent, and suspect describe evidence
The basic labels distinguish accepted evidence, missing reports, and unresolved doubts.
- Healthy needs expected reporting, trustworthy readings, and correct role behaviour.Plausibility and related observations must agree before the current decision can rely on the node.
- Silent means expected messages no longer reach the monitor.The record needs the last accepted message, expected schedule, and affected path so missing-data protection matches the actual absence.
- Suspect means the available evidence is weak or contradictory.Late messages, noise, inconsistency, or missing metadata justify reduced confidence while the team requests another observation.
- A suspect reading does not invalidate every function of its node.Corroboration can protect the affected decision without automatically removing the device from unrelated network work.
Major section
Misleading and unknown need different responses
Untrustworthy data and insufficient evidence require different next steps.
- Misleading describes available data that should not guide the current decision.Impossible values, repeated peer contradictions, invalid metadata, or conflicting role behaviour can support this bounded label.
- Unknown preserves uncertainty when the evidence cannot support a classification.The monitor may need another observation, a reference check, or a configuration audit before choosing a more specific state.
- Suspect evidence needs corroboration before stronger reliance.A contradictory reading can receive less weight while a repeated sample or reference check resolves the conflict.
- Labels can change when the supporting observations change.A successful reference check can clear suspicion, while repeated contradictions can remove confidence from a previously accepted source.
Activity 1 · Match
✎ Match the observation to its label

I need a label that fits each observation before choosing an action.
Match healthy, silent, suspect, misleading, and unknown to these cases: expected messages with agreeing evidence; no expected messages; weak conflicting evidence; repeated untrustworthy readings; insufficient evidence to classify. Add a bounded response to each.
4 minutes · Pen and paper · Answer: Activity 1
Major section
Role evidence limits the stronger labels
The taxonomy map connects expected role to response; follow evidence and confidence into the label, action, and retest trigger.
- The map’s starting points are the expected role and observed evidence.A relay must be judged against its forwarding work as well as its own reporting behaviour.
- Related checks and confidence can constrain the behaviour label.One missed relay cannot distinguish ordinary limits from a pattern of preserving local traffic while refusing shared work.
- The action follows the supported label and affected responsibility.Selfish evidence limits reliance on cooperation, while false routing state or tampering requires stronger corroboration for a malicious label.
- The retest trigger follows the action to keep recovery review open.A limited-capability node may provide little diagnostic detail, so stale-data protection and a clear recovery condition remain necessary.
Major section
N17 needs a window before a stronger label
The observed packet window limits what the team can claim about N17.
- N17 should send five packets in the five-minute window.The gateway is expecting one health packet every 60 seconds, so zero received packets show absence from this decision path.
- Working neighbours can narrow the investigation without proving deliberate harm.Two neighbouring nodes report and the parent forwards other traffic, but N17 may still have a local power or link problem.
- Five own readings beside 0 of 20 forwards support a different hypothesis.Preserved local reporting with absent shared work points toward selfish forwarding when the watchdog can observe those relay opportunities.
- A relay label stays separate from a still-plausible temperature report.The response should target unsupported cooperation unless additional evidence shows the local data or route state is also harmful.
Major section
Each check answers a different question
Each evidence check should contribute a distinct observation to the behaviour review.
- Message presence can compare the latest report with the decision deadline.The monitor records whether the missing state is temporary, repeated, or unexplained instead of treating every gap as identical.
- Plausibility can examine the value while consistency examines its relationships.A possible reading can still disagree with a nearby node, repeated sample, reference observation, or related process signal.
- Assigned roles determine which behaviours count as expected work.A relay, sampler, actuator-adjacent node, and observer need different checks because their responsibilities differ.
- Recovery history can explain uncertainty without automatically restoring trust.A restart, rejoin, configuration change, or metadata loss needs current evidence before the application relies on the recovered source.
Major section
Own reports and shared work need separate counters
Local sensing and shared forwarding can support different conclusions about the same node.
- A watchdog can observe forwards while reputation combines observations across time.The monitor still needs separate counters for own reports, relay opportunities, overheard forwards, plausibility failures, and peer contradictions.
- Moisture values near neighbouring observations can support local cooperation.Reports of 44%, 45%, and 44% are consistent with nearby 43% and 46% readings for the reviewed decision.
- Repeated disagreement makes an available source suspect or misleading.A node reporting 99% for six samples while adjacent probes stay near 45% needs a reference or consistency review.
- Broad failure and selective non-cooperation can suggest different responses.Missing own reports and relay work support fault recovery, while preserved local traffic with absent forwarding raises a selfish hypothesis.
Major section
Forwarding evidence needs denominators
Relay opportunities and own reports give a dropped-packet claim its necessary context.
- A forwarding count has meaning only beside its observed opportunities.The watchdog example has 20 relay opportunities, 2 forwards, and 10 of 10 own reports.
- Selective forwarding failure supports a role-specific hypothesis.The separate example has 18 child packets, one forward, and five timely own packets, providing evidence for a cooperation review.
- Repeated windows help distinguish a pattern from one weak observation.The chapter’s suggested rule is a warning on the first weak window and action when the second window repeats the pattern.
- A poor relay score does not automatically condemn plausible local readings.Reputation can age old observations and separate roles so the response remains attached to the evidence that actually failed.
Activity 2 · Predict
✎ Predict the narrow forwarding response

I want a response that follows the counters without assuming an attack.
A watchdog observes 20 relay opportunities, hears 2 forwards, and sees 10 of 10 own reports. Predict the leading behaviour hypothesis and a bounded response. State what a malicious label would additionally need.
3 minutes · Pen and paper · Answer: Activity 2
Major section
Each matrix row connects evidence to action
The matrix pairs labels with evidence and responses; read across each row before comparing silent, suspect, misleading, and unknown.
- The healthy row can permit use while preserving freshness and validity evidence.Expected reports and trustworthy readings support the current decision, but normal monitoring and retest rules still apply.
- The silent row requires a missing-data response.The affected dashboard cannot copy an old temperature forward and present that stale value as a current measurement.
- The suspect and misleading rows limit reliance on disputed readings.Weak evidence calls for corroboration, while untrustworthy data should be rejected for the affected decision and reviewed.
- The unknown row needs the missing observation before classification.A conservative state can prevent a confident label while the monitor lacks enough evidence to distinguish the possible explanations.
Major section
The classroom dashboard must show missing evidence
A classroom value must stop appearing current when its expected source goes silent.
- One room has no current temperature and humidity packet.Nearby rooms continue reporting, so the dashboard needs an explicit missing state for the affected room.
- The last accepted message is too old for the current decision.Message presence is insufficient even if the stored value still looks reasonable for classroom comfort.
- The supported label is silent rather than a guessed hardware cause.The review can request node health evidence without assuming whether power, scheduling, or communication caused the absence.
- Missing evidence changes the downstream rule and belongs in the record.The application must not infer a temperature trend from stale data while the local condition remains unobserved.
Deck summary
Labels are revisable decisions backed by evidence
The supported response should change when fresh evidence changes the classification.
- Silence and misleading readings need different protections.The dashboard must show absent current data and separately reject available readings that fail the relevant trust checks.
- A forwarding hypothesis needs counters for both local and shared traffic.Own reports, relay opportunities, and overheard forwards establish whether the observed pattern is broad failure or selective non-cooperation.
- Intent requires stronger evidence than an isolated missing packet.False claims, identity conflict, route manipulation, or tampering need corroboration before the record supports a malicious label.
- Confidence, bounded action, and retest keep classification useful.Fresh observations can clear a suspect node or reopen a healthy label without turning a temporary state into a permanent identity.
Retrieval practice
Recall check 1 of 2

Packet Pete says: answer from memory, then check your reasoning.
Q1A sensor node keeps sending readings on schedule, but validation and peer comparison show the values are implausible. Which behavior label fits best?
Show answer
Answer: A The hardest classification is a node that stays available but sends untrustworthy data, not one that goes silent.
Retrieval practice
Recall check 2 of 2

Packet Pete says: answer from memory, then check your reasoning.
Q2A watchdog sees a node send its own data reliably but forward almost none of its neighbours' packets. Which label and response best fit the evidence?
Show answer
Answer: C Selfish relay behavior is a role-specific pattern: the node preserves its own traffic while avoiding shared work, so the response should be scoped to that evidence.
Print reference
Answers
Answer key.
- A · The hardest classification is a node that stays available but sends untrustworthy data, not one that goes silent.
- C · Selfish relay behavior is a role-specific pattern: the node preserves its own traffic while avoiding shared work, so the response should be scoped to that evidence.
Print reference
Activity 1 answer
Model answer.
Match: Healthy: use with normal monitoring. Silent: mark missing or stale and investigate. Suspect: reduce confidence and request corroboration. Misleading: reject the affected data and review. Unknown: collect the missing observation and preserve a conservative state.
Print reference
Activity 2 answer
Model answer.
Predict: The asymmetry supports a selfish forwarding hypothesis. Reduce reliance on this node for shared work while checking observation quality and repeated cooperation evidence. Malicious behaviour needs corroborated active harm such as false routing state, identity conflict, or tampering.