FL-SVM: A Federated Learning-Based Support Vector Machine Model for IoT Malware Detection
DOI:
https://doi.org/10.54654/isj.v2i28.1243Keywords:
IoT Malware, federated learning, machine learning, artificial intelligence, malware detectionTóm tắt
The rapid development of IoT devices has significantly contributed to digital transformation across organizations, enterprises, and institutions. The risk of malware infection on IoT devices has become increasingly prevalent and dangerous, with new attack methods and infection techniques. IoT devices, with their numerous, diverse types, configurations and resource usage characteristics, have raised new requirements for more efficient, accurate IoT malware detection methods and solutions that ensure privacy during model training in real-world applications. In this paper, we propose a more efficient IoT malware detection model based on an improved Federated Learning method. Specifically, our key contributions include a dynamic aggregation mechanism designed for clients with heterogeneous feature spaces, allowing resource-constrained IoT devices to adaptively adjust their feature dimensionality according to hardware capacity. The proposed malware detection model has been tested with an IoT dataset on the MIPS architecture platform. Experimental results show that the proposed malware detection model achieves good accuracy while strongly leveraging the advantages of Federated Learning in ensuring data privacy and minimizing computational resource usage during model training.
Downloads
References
“Enabling-IOT.pdf”, Access time:18/12/2025, https://cdn.ihs.com/www/pdf/enabling-IOT.pdf
“TL-WR841N”, Access time: 17/12/2025, https://volatilesystems.org/hardware/tl-wr841n.html.
A. Sivanathan, H. H. Gharakheili, F. Loi, A. Radford, C. Wijenayake, A Vishwanath, V. Sivaraman, “Classifying IoT Devices in Smart Environments Using Network Traffic Characteristics”, IEEE Trans. on Mobile Comput., vol. 18, no. 8, pp. 1745–1759, 2019. DOI: 10.1109/TMC.2018.2866249.
M. Antonakakis, T. April, M. Bailey, M. Bernhard, E. Bursztein, J. Cochran, ... & Y. Zhou, “Understanding the Mirai Botnet”, in Proc. 26th USENIX Security Symp. (USENIX Security 2017), Vancouver, BC, Canada, pp. 1093–1110, Aug. 16–18, 2017.
F. Fischer, K. Böttinger, H. Xiao, C. Stransky, Y. Acar, M. Backes, & S. Fahl, “Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security”, in 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA: IEEE, pp. 121–136, 2017. DOI: 10.1109/SP.2017.31.
C.W. Tien, S.W. Chen, T. Ban, and S.Y. Kuo, “Machine Learning Framework to Analyze IoT Malware Using ELF and Opcode Features”, Digital Threats, vol. 1, no. 1, pp. 5:1-5:19, 2020. DOI: 10.1145/3378448.
N. N. Toan, L. T. Dung, D. Q. Thang, “Static Feature Selection for IoT Malware Detection”, Journal of Science and Technology on Information security, vol. 1, no. 15, pp. 74 - 84, 2022. DOI: 10.54654/isj.v1i15.844.
L. T. Dung, N. N. Toan, T. N. Phu, “CAIMP: Cross-Architecture IoT Malware Detection and Prediction Based On Static Feature”, The Computer Journal, vol. 67, no. 9, pp. 2763 - 2776, 2024. DOI:10.1093/comjnl/bxae042
J. Ramamoorthy, K. Gupta, R. C. Kafle, N. K. Shashidhar, and C. Varol, “A Novel Static Analysis Approach Using System Calls for Linux IoT Malware Detection”, Computer Science and Mathematics, 2024, DOI: 10.20944/preprints202407.0268.v1.
J. Ramamoorthy, K. Gupta, N. K. Shashidhar, and C. Varol, “Linux IoT Malware Variant Classification Using Binary Lifting and Opcode Entropy”, Electronics, vol. 13, no. 12, pp. 2381, 2024. DOI: 10.3390/electronics13122381.
T. A. Tu, D. C. Thanh, T. D. Su, “Amplified Gradient Inversion Attacks on Federated Learning Frameworks”, Journal of Science and Technology on Information Security, vol. 3, no. 23, pp. 15–26, 2024. DOI: 10.54654/isj.v3i23.1066
V. Rey, P. M. Sánchez, A. Huertas Celdrán, and G. Bovet, “Federated learning for malware detection in IoT devices”, Computer Networks, vol. 204, pp. 108693, 2022. DOI: 10.1016/j.comnet.2021.108693.
Z. Çıplak, K. Yıldız, and Ş. Altınkaya, “FEDetect: A Federated Learning-Based Malware Detection and Classification Using Deep Neural Network Algorithms”, Arab J Sci Eng, 2025. DOI: 10.1007/s13369-025-10043-x.
M. Nobakht, R. Javidan, and A. Pourebrahimi, “SIM-FED: Secure IoT malware detection model with federated learning”, Computers and Electrical Engineering, vol. 116, pp. 109-139, 2024. DOI: 10.1016/j.compeleceng.2024.109139.
M. Asiri, M. A. Khemakhem, R. M. Alhebshi, B. S. Alsulami, and F. E. Eassa, “RPFL: A Reliable and Privacy-Preserving Framework for Federated Learning-Based IoT Malware Detection”, Electronics, vol. 14, no. 6, pp. 1089, 2025. DOI: 10.3390/electronics14061089.
C. Jiang, K. Yin, C. Xia, and W. Huang, “FedHGCDroid: An Adaptive Multi-Dimensional Federated Learning for Privacy-Preserving Android Malware Classification”, Entropy, vol. 24, no. 7, pp. 919, 2022. DOI: 10.3390/e24070919.
K. Chen, W. Zhang, Z. Liu, and B. Mi, “Leveraging Federated Learning for Malware Classification: A Heterogeneous Integration Approach”, Electronics, vol. 14, no. 5, pp. 915, 2025. DOI: 10.3390/electronics14050915.
R. H. Hsu, Y. C. Wang, C. I. Fan, B. Sun, T. Ban, T. Takahashi, ... & S. W. Kao, “A Privacy-Preserving Federated Learning System for Android Malware Detection Based on Edge Computing”, in 2020 15th Asia Joint Conference on Information Security (AsiaJCIS), pp. 128-136, 2020. DOI: 10.1109/AsiaJCIS50894.2020.00031.
K. Y. Lin and W. R. Huang, “Using Federated Learning on Malware Classification”, in 2020 22nd International Conference on Advanced Communication Technology (ICACT), pp. 585–589, 2020. DOI: 10.23919/ICACT48636.2020.9061261.
R. Taheri, M. Shojafar, M. Alazab, and R. Tafazolli, “Fed-IIoT: A Robust Federated Malware Detection Architecture in Industrial IoT”, IEEE Transactions on Industrial Informatics, vol. 17, no. 12, pp. 8442–8452, 2021. DOI:10.1109/TII.2020.3043458.
T. N. Phu, H. D. Kien, N. Q. Dung, N. D. Tho, “A Novel Framework to Classify Malware in MIPS Architecture-Based IoT Devices”, Hindawi Security and Communication Networks Volume 2019, Article ID 4073940, 2019.
DOI: 0.1155/2019/4073940
N. H. Trung, “Doctoral thesis Research to propose PSI graph characteristics in detecting Botnet malware on IoT devices”, PhD Thesis, Academy of Science and Technology, Vietnam Academy of Sciences, 2021.
Downloads
Published
How to Cite
Issue
Section
License
Open Access Policy
The Journal of Science and Technology on Information Security provides open access to its published articles to broaden opportunities for high-quality research findings to be available and widely disseminated free of charge, contributing to the greater exchange of knowledge.
Open access statement: CTUJoS permits everyone to read, download, copy, distribute, print, search, or link to the full texts of the published articles without registration, price barriers, or asking for permission from the Journal or the author.
Proposed Policy for Journals That Offer Delayed Open Access
Authors who publish with this journal agree to the following terms:
1. Authors retain copyright and grant the journal right of first publication, with the work [SPECIFY PERIOD OF TIME] after publication simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
2. Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
3. Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work (See The Effect of Open Access).










