Malware Classification and Detection in Untrusted Cloud via SGX and ORAM

Zongmin Wang, Guanming Che, Qiang Wang, Fucai Zhou, Jian Feng Xu, Fanchao Meng · 2025

The widespread adoption of mobile internet has positioned mobile devices as prime targets for sophisticated malware attacks. While cloud-based detection services offer computational efficiency, their reliance on untrusted cloud providers introduces critical security vulnerabilities, including potential result manipulation for financial gain and unauthorized leakage of sensitive malware repositories. To address these challenges, we propose a secure cloud-based malware classification and detection scheme integrating Intel SGX and Oblivious RAM (ORAM). First, we construct a deep learning-based malware family classification model through convolutional neural networks (CNN) to achieve high-precision detection. Then, we leverage Intel SGX to establish a trusted execution environment (TEE), ensuring the integrity and confidentiality of the detection process. To mitigate SGX’s memory constraints, the encrypted malware sample library is stored in the cloud, and we employ ORAM to enable oblivious access during data interactions, thereby preventing sample leakage. Experimental results demonstrate that our scheme achieves strong privacy protection while maintaining high performance in real-world scenarios.

Read the paper · More papers on PaperTik