The proliferation of sophisticated malware capable of attacking personal devices or permeating the environments in which users live requires autonomous detection systems that are both effective and privacy-preserving. Graph Neural Networks are promising in capturing complex application behaviors and may be suitable for detecting malicious software. However, their adoption and deployment in smart computing environments is hindered by the hardware heterogeneity of edge devices and the sensitive nature of user data. This paper introduces a resource-aware Federated Learning framework for malware detection that leverages Heterogeneous Graph Transformers (HGTs). To address the diverse hardware capabilities found in mobile ecosystems, this work proposes an adaptive training strategy: while high-performance clients utilize more computationally intensive analysis methods for comprehensive feature extraction, resource-constrained nodes participate in the global model aggregation using only lightweight feature subsets. Furthermore, the intrinsic mechanistic interpretability of HGTs is exploited by analyzing attention maps to identify the specific features that the model pays most attention to during classification, relating them to known attack techniques. The experimental evaluation shows that this approach maintains high detection accuracy across a heterogeneous client base while providing useful insights into malware behavior and preserving user privacy through local-only data processing.
Augello, A., De Paola, A., Lo Re, G. (2026). Resource-Aware Federated Learning for Malware Detection on Smart Devices. In 2026 IEEE International Conference on Smart Computing (SmartComp) (pp. 48-55). IEEE [10.1109/smartcomp69968.2026.00019].
Resource-Aware Federated Learning for Malware Detection on Smart Devices
Augello, Andrea
;De Paola, Alessandra;Lo Re, Giuseppe
2026-06-01
Abstract
The proliferation of sophisticated malware capable of attacking personal devices or permeating the environments in which users live requires autonomous detection systems that are both effective and privacy-preserving. Graph Neural Networks are promising in capturing complex application behaviors and may be suitable for detecting malicious software. However, their adoption and deployment in smart computing environments is hindered by the hardware heterogeneity of edge devices and the sensitive nature of user data. This paper introduces a resource-aware Federated Learning framework for malware detection that leverages Heterogeneous Graph Transformers (HGTs). To address the diverse hardware capabilities found in mobile ecosystems, this work proposes an adaptive training strategy: while high-performance clients utilize more computationally intensive analysis methods for comprehensive feature extraction, resource-constrained nodes participate in the global model aggregation using only lightweight feature subsets. Furthermore, the intrinsic mechanistic interpretability of HGTs is exploited by analyzing attention maps to identify the specific features that the model pays most attention to during classification, relating them to known attack techniques. The experimental evaluation shows that this approach maintains high detection accuracy across a heterogeneous client base while providing useful insights into malware behavior and preserving user privacy through local-only data processing.| File | Dimensione | Formato | |
|---|---|---|---|
|
Resource-Aware_Federated_Learning_for_Malware_Detection_on_Smart_Devices.pdf
Solo gestori archvio
Tipologia:
Versione Editoriale
Dimensione
3.65 MB
Formato
Adobe PDF
|
3.65 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


