paper-with-me

Papers

LoRA-based Parameter-Efficient LLMs for Continuous Learning in Edge-based Malware Detection

2026-02-12 · Christian Rondanini, Barbara Carminati, Elena Ferrari, Niccolò Lardo, Ashish Kundu arxiv

The proliferation of edge devices has created an urgent need for security solutions capable of detecting malware in real time while operating under strict computational and memory constraints. Recently, Large Language Models (LLMs) have demonstrated remarkable capabilities in recognizing complex patterns, yet their deployment on edge devices remains impractical due to their resource demands. However, in edge malware detection, static or centrally retrained models degrade under evolving threats and heterogeneous traffic; locally trained models become siloed and fail to transfer across domains. To overcome these limitations, in this paper, we present a continuous learning architecture for edge-based malware detection that combines local adaptation on each device with global knowledge sharing through parameter-efficient LoRA adapters. Lightweight transformer models (DistilBERT, DistilGPT-2, TinyT5) run on edge nodes and are incrementally fine-tuned on device-specific traffic; only the resulting LoRA modules are aggregated by a lightweight coordinator and redistributed, enabling cross-device generalization without exchanging raw data. We evaluate on two public IoT security datasets, Edge-IIoTset and TON-IoT, under multi-round learning to simulate evolving threats. Compared to isolated fine-tuning, the LoRA-based exchange yields up to 20-25% accuracy gains when models encounter previously unseen attacks from another domain, while maintaining stable loss and F1 across rounds. LoRA adds less than 1% to model size (~0.6-1.8 MB), making updates practical for constrained edge hardware.

📄 PDF Abstract BibTeX arXiv:2602.11655

Code (0)

등록된 구현이 없습니다.

Tasks

Malware Detection

Similar Papers 제목 키워드 기반

Accuracy and Efficiency Trade-Offs in LLM-Based Malware Detection and Explanation: A Comparative Study of Parameter Tuning vs. Full Fine-Tuning

2025-11-24 · Stephen C. Gravereaux, Sheikh Rabiul Islam arxiv

This study examines whether Low-Rank Adaptation (LoRA) fine-tuned Large Language Models (LLMs) can approximate the performance of fully fine-tuned models in generating human-interpretable decisions and explanations for m…

Malware ClassificationSemantic SimilarityMalware Detection

Reinforcement Learning for an Efficient and Effective Malware Investigation during Cyber Incident Response

2024-08-04 · Dipo Dunsin, Mohamed Chahine Ghanem, Karim Ouazzane, Vassil Vassilev

This research focused on enhancing post-incident malware forensic investigation using reinforcement learning RL. We proposed an advanced MDP post incident malware forensics investigation model and framework to expedite p…

Decision MakingMalware AnalysisQ-LearningReinforcement Learning (RL)

Malware Detection at the Edge with Lightweight LLMs: A Performance Evaluation

2025-03-06 · Christian Rondanini, Barbara Carminati, Elena Ferrari, Antonio Gaudiano 외

The rapid evolution of malware attacks calls for the development of innovative detection methods, especially in resource-constrained edge computing. Traditional detection techniques struggle to keep up with modern malwar…

Edge-computingMalware Detection

A Language-Guided Bayesian Optimization for Efficient LoRA Hyperparameter Search

2026-01-19 · Baek Seong-Eun, Lee Jung-Mok, Kim Sung-Bin, Tae-Hyun Oh arxiv

Fine-tuning Large Language Models (LLMs) with Low-Rank Adaptation (LoRA) offers a resource-efficient way to personalize or specialize. However, LoRA is highly sensitive to hyperparameter choices, and exhaustive hyperpara…

A Decompilation-Driven Framework for Malware Detection with Large Language Models

2026-01-14 · Aniesh Chawla, Udbhav Prasad arxiv

The parallel evolution of Large Language Models (LLMs) with advanced code-understanding capabilities and the increasing sophistication of malware presents a new frontier for cybersecurity research. This paper evaluates t…

Malware Detection