Adaptive ensemble-based malware detection in smart factory IIoT using AERS-WPS algorithm
摘要
In Industrial Internet of Things (IIoT), malware recognition is crucial to protect the accessibility, confidentiality, and integrity of intelligent devices. Traditional detection techniques are vulnerable to concept drift and struggle to adapt to evolving malware patterns, resulting in high false positives and lower detection accuracy. Therefore, the Adaptive Ensemble Random Support Vector-based Waterwheel Plant Search (AERS-WPS) is developed that adopts a three-layer architecture wherein the core detection mechanism is positioned at the edge computing layer to achieve decentralized processing. The Principal Component Analysis (PCA) is deployed to reduce high-dimensional feature spaces, Adaptive Random Forest (ARF) is utilized to handle streaming data by adapting to the evolving patterns of IIoT data, and the Ensemble Support Vector Machine (SVM) is employed to obtain discriminative features within the IIoT data under unbalanced, noisy, and high-dimensional malware data. Another notable contribution is the Water Wheel Plant algorithm (WWPA), along with an initial search strategy to dynamically tune key hyperparameters of both ARF and SVM. The AERS-WPS was evaluated using a malware datasets and compared with baseline models. The result illustrates higher detection accuracy rates of 98.06%, 98.73%, and 97.86% on MaleVis, Malimg, and BIG 2015 datasets, respectively, with high F1-scores, Matthews Correlation Coefficient (MCC), recall, specificity, and precision, with low false positive/negative rates. The approach exhibits higher computational efficiency by obtaining 18.23 M parameters, 112 MB of memory, and 3.2 ms inference time. These results validate its adaptability to changing threats and applicability for real-time malware detection in the IIoT-enabled smart industry.