Robust Model and Training Method for Malware Recognition in IoT Devices

В’ячеслав Васильович Москаленко · 2025

The object of the chapter is the process of malware detection in Internet of Things devices, which is usually resource-constrained and characterized by a wide variety of hardware platforms and operating systems. The subject of the chapter is a resource-efficient trainable model and training method for robust and platform-independent malware recognition on IoT devices. A resource-efficient model based on the backbone of well-known MobileNet architecture and a prototype-based classifier head with pseudo hyperspherical decision boundaries is proposed. A multi-stage training method for platform-independent classification analysis of malware for IoT devices is designed. The training process employs a regularized loss function based on the information measure, which is embedded in the loss function to ensure that the residual uncertainty is minimized after making decisions using pseudo hyperspherical decision boundaries and is expressed as a function of smoothed accuracy characteristics. In order to increase the compactness of the class distribution and buffer zone between classes in the embedding feature space, geometric regularization based on contrastive-center loss is used at the class prototyping stage, and a cross-entropy function with fixed binary class prototypes is used at the fine-tuning stage. The optimization of radii of pseudo hyperspherical decision boundary for each class with fixed feature extractor weights is carried out in accordance with Shannon’s entropy-based Information Criterion. Experiments confirmed that the obtained accuracy under the proposed approach is 98%, which is 4% greater than under the traditional approach with the same feature extractor structure. The accuracy obtained with the proposed approach is 3.87% higher than the accuracy obtained in the state-of-the-art approach for the same dataset. In addition, the obtained accuracy under the proposed approach on an adversarial test set with L2-perturbation magnitude bounded by 0.3 is 83%, which is 53% greater than under the traditional approach.

Read the paper · More papers on PaperTik