Malware Detection at the Edge with Lightweight LLMs: A Performance Evaluation

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Rondanini, Christian, Carminati, Barbara, Ferrari, Elena, Gaudiano, Antonio, Kundu, Ashish
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912262347816960
author Rondanini, Christian
Carminati, Barbara
Ferrari, Elena
Gaudiano, Antonio
Kundu, Ashish
author_facet Rondanini, Christian
Carminati, Barbara
Ferrari, Elena
Gaudiano, Antonio
Kundu, Ashish
contents The rapid evolution of malware attacks calls for the development of innovative detection methods, especially in resource-constrained edge computing. Traditional detection techniques struggle to keep up with modern malware's sophistication and adaptability, prompting a shift towards advanced methodologies like those leveraging Large Language Models (LLMs) for enhanced malware detection. However, deploying LLMs for malware detection directly at edge devices raises several challenges, including ensuring accuracy in constrained environments and addressing edge devices' energy and computational limits. To tackle these challenges, this paper proposes an architecture leveraging lightweight LLMs' strengths while addressing limitations like reduced accuracy and insufficient computational power. To evaluate the effectiveness of the proposed lightweight LLM-based approach for edge computing, we perform an extensive experimental evaluation using several state-of-the-art lightweight LLMs. We test them with several publicly available datasets specifically designed for edge and IoT scenarios and different edge nodes with varying computational power and characteristics.
format Preprint
id arxiv_https___arxiv_org_abs_2503_04302
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Malware Detection at the Edge with Lightweight LLMs: A Performance Evaluation
Rondanini, Christian
Carminati, Barbara
Ferrari, Elena
Gaudiano, Antonio
Kundu, Ashish
Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
The rapid evolution of malware attacks calls for the development of innovative detection methods, especially in resource-constrained edge computing. Traditional detection techniques struggle to keep up with modern malware's sophistication and adaptability, prompting a shift towards advanced methodologies like those leveraging Large Language Models (LLMs) for enhanced malware detection. However, deploying LLMs for malware detection directly at edge devices raises several challenges, including ensuring accuracy in constrained environments and addressing edge devices' energy and computational limits. To tackle these challenges, this paper proposes an architecture leveraging lightweight LLMs' strengths while addressing limitations like reduced accuracy and insufficient computational power. To evaluate the effectiveness of the proposed lightweight LLM-based approach for edge computing, we perform an extensive experimental evaluation using several state-of-the-art lightweight LLMs. We test them with several publicly available datasets specifically designed for edge and IoT scenarios and different edge nodes with varying computational power and characteristics.
title Malware Detection at the Edge with Lightweight LLMs: A Performance Evaluation
topic Cryptography and Security
Artificial Intelligence
Distributed, Parallel, and Cluster Computing
url https://arxiv.org/abs/2503.04302