为物联网设备设计节能的恶意软件检测方法
Are Trees Really Green? A Detection Approach of IoT Malware Attacks
- 用树模型优化能耗与检测性能
- 功耗降低的同时保持高准确率
- 适合资源受限的物联网场景
如今,物联网(IoT)被广泛应用于医疗和工业领域,推动远程监控、预测性维护和数据驱动决策。然而,由于资源受限且难以更新安全补丁,物联网设备仍易受攻击,尤其是拒绝服务攻击频发。现有检测多依赖机器学习,但较少关注算法对计算资源的影响。本文提出一种绿色检测方法,基于流隐私保护的统计特征,优化决策树、随机森林和极端梯度提升树三类树模型的超参数,在能量消耗(瓦时,Wh)和测试时性能(马修斯相关系数,MCC)之间取得平衡。实验表明,模型在维持高检测准确率的同时,显著降低功耗,证明本地部署的机器学习入侵检测系统适用于物联网等资源受限设备。
原文摘要 · Abstract (English)
Nowadays, the Internet of Things (IoT) is widely employed, and its usage is growing exponentially because it facilitates remote monitoring, predictive maintenance, and data-driven decision making, especially in the healthcare and industrial sectors. However, IoT devices remain vulnerable due to their resource constraints and difficulty in applying security patches. Consequently, various cybersecurity attacks are reported daily, such as Denial of Service, particularly in IoT-driven solutions. Most attack detection methodologies are based on Machine Learning (ML) techniques, which can detect attack patterns. However, the focus is more on identification rather than considering the impact of ML algorithms on computational resources. This paper proposes a green methodology to identify IoT malware networking attacks based on flow privacy-preserving statistical features. In particular, the hyperparameters of three tree-based models -- Decision Trees, Random Forest and Extra-Trees -- are optimized based on energy consumption and test-time performance in terms of Matthew's Correlation Coefficient. Our results show that models maintain high performance and detection accuracy while consistently reducing power usage in terms of watt-hours (Wh). This suggests that on-premise ML-based Intrusion Detection Systems are suitable for IoT and other resource-constrained devices.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。