Mal-Fedchain is presented, a secure and privacy-preserving framework for image-based IoT malware detection and prevention that couples federated learning with blockchain and honeypot-assisted behavioral monitoring, targeting Linux-capable IoT gateway devices.
Abstract
Internet of Things (IoT) devices are increasingly targeted by rapidly evolving malware, yet collaborative detection remains challenged by privacy leakage, noisy and imbalanced training data, and weak integrity guarantees when sharing model updates. This paper presents Mal-Fedchain, a secure and privacy-preserving framework for image-based IoT malware detection and prevention that couples federated learning with blockchain and honeypot-assisted behavioral monitoring, targeting Linux-capable IoT gateway devices. Portable Executable (PE) binaries are transformed into grayscale images using a corrected fixed-width byte-mapping pipeline stabilized by an information-maximizing GAN (IMGAN). A bi-level preprocessing pipeline applies two-sided weighted sparse representation (T-WSR) denoising—designed to selectively suppress zero-padding artifacts, high-entropy packed regions, and sparse opcode noise while preserving discriminative section-boundary texture—followed by geometric augmentation to mitigate class imbalance. Malware detection and family attribution are performed using a residual capsule-based network (RBCN) that fuses discriminative visual representations with PE-header features via concatenation, improving robustness against polymorphism and obfuscation. A formal threat model governs three adversary classes: a semi-honest aggregation server, a bounded fraction of malicious clients (up to 30%), and a passive eavesdropper. To enable collaboration without exposing raw data, clients train locally and share only MemCbar-encrypted updates; a permissioned Hyperledger Fabric blockchain ledger records hashed updates and security events to provide integrity, traceability, and tamper resistance. A file-system-integrated honeypot captures evasive behaviors and logs auditable evidence to strengthen prevention. Experiments on the Malimg dataset across five ablation configurations demonstrate that the corrected RBCN pipeline achieves 93.52% accuracy, 92.40% precision, 93.52% recall, 92.52% F-measure, MCC of 0.9245, and AUC of 0.9976 in its centralized configuration, and 65.62% accuracy with AUC of 0.9840 in the full federated configuration with five clients and eight communication rounds, substantially outperforming all baselines across all reported metrics.
A Weighted Symmetric Hashed Blockchain framework that integrates mutual-information-based feature weighting, deep-learning-based attack classification, AES-256-GCM authenticated encryption, cryptographic hashing, and permissioned-ledger logging, demonstrating the potential of WSHB as a reproducible framework for attack...
Naveed Ahmad, Yue Cao, William Liu· Italian National Conference...· 0 citations
The proposed framework effectively integrates encryption, federated intrusion detection, explainable artificial intelligence, and blockchain security to enhance privacy, transparency, and reliability in IoMT healthcare networks.
P. Banupriya, K. Vanitha· Journal of Vibration Enginee...· 0 citations
A decentralised federated learning (FL)-based IoT malware detection framework, evaluated using the recent IoT-23 dataset and systematically assessed in terms of robustness and scalability, highlighting the feasibility of robust and scalable FL-based security systems in real-world IoT deployments.
Saba Nayab, Sana Qadir, Madiha Khalid et al.· Journal of Computer Virology...· 0 citations
The proposed framework for financial system fraud detection that is safe and protects privacy while resolving issues with data sharing, legal restrictions, and cybersecurity threats is appropriate for practical financial applications since it successfully improves fraud detection while guaranteeing Privacy Preservation...
The proposed hybrid approach outperforms ML-only and blockchain-only baselines, offering a scalable, secure, and real-time IDS for IIoT infrastructures.
The proliferation of Internet of Things (IoT) devices has amplified the attack surface for large-scale cyber threats, with rapidly evolving malware families such as Mirai posing significant detection challenges. Existing side-channel and host-based approaches are limited by poor generalization to unseen variants and th...
Damodar Dhital, Sabir Ahmed Khan, Almustapha A. Wakili et al.· International Conference on...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.