arXiv:2503.04302cs.CRcs.AI2025-03被引 22

轻量级大模型在边缘设备上实现高效恶意软件检测

Malware Detection at the Edge with Lightweight LLMs: A Performance Evaluation

  • 用轻量级大模型替代传统方法,适配边缘计算资源受限场景
  • 在多个边缘节点上测试,验证了模型在不同算力下的检测效果
  • 为物联网设备提供低功耗、高准确率的恶意软件防护方案

恶意软件攻击的快速演进要求开发创新的检测方法,尤其是在资源受限的边缘计算环境中。传统检测技术难以应对现代恶意软件的复杂性和适应性,促使研究转向利用大型语言模型(LLMs)等先进方法提升检测能力。然而,直接在边缘设备部署LLMs面临准确性保障和能源、计算资源限制等挑战。为此,本文提出一种架构,充分发挥轻量级LLMs的优势,同时解决精度下降与计算能力不足的问题。为评估该轻量级LLM方法在边缘计算中的有效性,我们在多个先进的轻量级LLMs上进行了广泛实验,使用多个专为边缘与物联网场景设计的公开数据集,并在具有不同计算能力与特性的多种边缘节点上进行测试。

原文摘要 · Abstract (English)

The rapid evolution of malware attacks calls for the development of innovative detection methods, especially in resource-constrained edge computing. Traditional detection techniques struggle to keep up with modern malware's sophistication and adaptability, prompting a shift towards advanced methodologies like those leveraging Large Language Models (LLMs) for enhanced malware detection. However, deploying LLMs for malware detection directly at edge devices raises several challenges, including ensuring accuracy in constrained environments and addressing edge devices' energy and computational limits. To tackle these challenges, this paper proposes an architecture leveraging lightweight LLMs' strengths while addressing limitations like reduced accuracy and insufficient computational power. To evaluate the effectiveness of the proposed lightweight LLM-based approach for edge computing, we perform an extensive experimental evaluation using several state-of-the-art lightweight LLMs. We test them with several publicly available datasets specifically designed for edge and IoT scenarios and different edge nodes with varying computational power and characteristics.

边缘计算恶意软件检测轻量模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。