TY - GEN
T1 - DeepIncept
T2 - 29th Asia and South Pacific Design Automation Conference, ASP-DAC 2024
AU - Li, Zhuoran
AU - Zhao, Dan
N1 - Publisher Copyright:
© 2024 IEEE.
PY - 2024
Y1 - 2024
N2 - To tackle the challenge of detecting Internet of Things (IoT) malware, we design a lightweight and non-intrusive detection engine that on-the-fly analyzes hardware performance counters (HPC) to improve deep learning-based detection performance. Specifically, our method employs in-depth correlation analysis to identify HPC events that possess two key characteristics: high representativeness and diverse attributes. To achieve on-device real-time detection, we introduce DeepIncept, a compact network architecture that takes advantage of depth-aware deconstruction and streamlined contextual filtering. This architecture integrates efficient depthwise separable convolutions and 1-dimensional Convolutional Neural Network (CNN) kernels to create an inception-like structure, enabling accurate extraction of event-specific and multievent-combined features. The experimental results demonstrate that DeepIncept outperforms the current state-of-the-art by over 5% while achieving an accuracy of 98.58% and 98.31% in detecting existing and unknown malware, respectively. Furthermore, DeepIncept shows a 34% improvement over the classical CNN model while achieving a 3 × faster detection speed of approximately 2ms.
AB - To tackle the challenge of detecting Internet of Things (IoT) malware, we design a lightweight and non-intrusive detection engine that on-the-fly analyzes hardware performance counters (HPC) to improve deep learning-based detection performance. Specifically, our method employs in-depth correlation analysis to identify HPC events that possess two key characteristics: high representativeness and diverse attributes. To achieve on-device real-time detection, we introduce DeepIncept, a compact network architecture that takes advantage of depth-aware deconstruction and streamlined contextual filtering. This architecture integrates efficient depthwise separable convolutions and 1-dimensional Convolutional Neural Network (CNN) kernels to create an inception-like structure, enabling accurate extraction of event-specific and multievent-combined features. The experimental results demonstrate that DeepIncept outperforms the current state-of-the-art by over 5% while achieving an accuracy of 98.58% and 98.31% in detecting existing and unknown malware, respectively. Furthermore, DeepIncept shows a 34% improvement over the classical CNN model while achieving a 3 × faster detection speed of approximately 2ms.
KW - Hardware Performance Counters
KW - IoT Malware Detection
KW - Lightweight Deep Learning
KW - Multicollinearity
UR - https://www.scopus.com/pages/publications/85189324961
UR - https://www.scopus.com/pages/publications/85189324961#tab=citedBy
U2 - 10.1109/ASP-DAC58780.2024.10473871
DO - 10.1109/ASP-DAC58780.2024.10473871
M3 - Conference contribution
AN - SCOPUS:85189324961
T3 - Proceedings of the Asia and South Pacific Design Automation Conference, ASP-DAC
SP - 362
EP - 367
BT - ASP-DAC 2024 - 29th Asia and South Pacific Design Automation Conference, Proceedings
PB - Institute of Electrical and Electronics Engineers Inc.
Y2 - 22 January 2024 through 25 January 2024
ER -