Towards moving target defense for IoT malware detection

Loading...
Thumbnail Image
Files
Serp4IoT_18_TowardsMTD.pdf(545.28 KB)
Accepted Version
Date
2026-04-12
Authors
Ryan, Ita
Kurlandski, Luke
Mathews, Nate
Journal Title
Journal ISSN
Volume Title
Publisher
Association for Computing Machinery (ACM)
Published Version
Research Projects
Organizational Units
Journal Issue
Abstract
Machine learning (ML) techniques show promise in malware defense for the Internet of Things (IoT), but are vulnerable to tailored adversarial attacks. Moving Target Defense (MTD) is a security strategy that actively raises the cost to the attacker of a potential attack by changing the target’s characteristics, preventing attackers from profiling the target. In this work we explore the potential for using MTD for IoT malware detection. Applying MTD to protect ML malware detection involves continuously changing the malware classification models, defeating attempts to profile the models. We research the state-of-the-art literature that uses an MTD-style strategy to increase ML model security. We identify two techniques: 'Naive MTD', which cycles between static models, and 'Full MTD', which refreshes models at runtime and is therefore more effective. Focusing on the studies in the ML literature that use Full MTD for adversarial robustness, we examine their approach, assessing features such as discard policy, decision-making and model updating schedule. We make a number of recommendations on development of a Full MTD strategy for ML IoT malware detection.
Description
Keywords
Artificial Intelligence and Data Analytics , Moving target defense , Malware , Internet of things , Malware defense , [ComputerScience]
Citation
Link to publisher’s version