FICConvNet: A Privacy-Preserving Framework for Malware Detection Using CKKS Homomorphic Encryption
Si Pang, Jing Wen, Shaoling Liang, Baohua Huang · Electronics · 2025
Recent advancements in cloud computing, edge computing, and Internet of Things (IoT) have increased the complexity of network environments and provided fertile ground for malicious attacks. Existing DL-based malware detections, while making progress in detection accuracy and generalization ability, face serious challenges in user data privacy protection. To address this problem, this paper proposed a non-interactive malware detection system based on CKKS homomorphic encryption (FICConvNet). The system effectively achieves end-to-end data privacy protection, ensures that sensitive data uploaded by users are processed in an encrypted state, prevents data leakage, and protects the privacy of detection results. The key technology of FICConvNet is its innovative lightweight ciphertext inference architecture, which combines DS Conv and structured sparse projection to significantly reduce the complexity of homomorphic computation. Meanwhile, in this paper, an adaptive learnable activation function (ALPolyAct) is designed to replace the traditional fixed polynomial activation function to enhance the expressive power and inference accuracy of the model. In addition, the privacy protection of user data and the security of detection results are optimized by the zero-decryption inference process. Experimental results show that FICConvNet achieves a detection accuracy of 95.86%, which significantly outperforms the existing ciphertext inference model CryptoNets (15.5% improvement) and approaches the performance of the plaintext model ResNet-18. In addition, FICConvNet reduces ciphertext inference time by about 80% compared to Conv2d structures. The research in this paper provides an effective privacy-preserving solution in the field of malware detection and explores new research directions for the application of homomorphic encryption in malware detection.