DeepIncept: Diversify Performance Counters with Deep Learning to Detect Malware
Zhuoran Li, Dan Zhao · 2024
To tackle the challenge of detecting Internet of Things (IoT) malware, we design a lightweight and non-intrusive detection engine that on-the-fly analyzes hardware performance counters (HPC) to improve deep learning-based detection performance. Specifically, our method employs in-depth correlation analysis to identify HPC events that possess two key characteristics: high representativeness and diverse attributes. To achieve on-device real-time detection, we introduce DeepIncept, a compact network architecture that takes advantage of depth-aware deconstruction and streamlined contextual filtering. This architecture integrates efficient depthwise separable convolutions and 1-dimensional Convolutional Neural Network (CNN) kernels to create an inception-like structure, enabling accurate extraction of event-specific and multievent-combined features. The experimental results demonstrate that DeepIncept outperforms the current state-of-the-art by over 5% while achieving an accuracy of 98.58% and 98.31% in detecting existing and unknown malware, respectively. Furthermore, DeepIncept shows a 3~4% improvement over the classical CNN model while achieving a $3 \times$ faster detection speed of approximately 2ms.