Skip to content
Open access

A Blockchain and Federated Learning Framework for Image-Based IoT Malware Detection and Prevention

Jul 2026 · IoT · Vol 7, pp. 56 · 0 citations · 39 references

TL;DR

Mal-Fedchain is presented, a secure and privacy-preserving framework for image-based IoT malware detection and prevention that couples federated learning with blockchain and honeypot-assisted behavioral monitoring, targeting Linux-capable IoT gateway devices.

Abstract

Internet of Things (IoT) devices are increasingly targeted by rapidly evolving malware, yet collaborative detection remains challenged by privacy leakage, noisy and imbalanced training data, and weak integrity guarantees when sharing model updates. This paper presents Mal-Fedchain, a secure and privacy-preserving framework for image-based IoT malware detection and prevention that couples federated learning with blockchain and honeypot-assisted behavioral monitoring, targeting Linux-capable IoT gateway devices. Portable Executable (PE) binaries are transformed into grayscale images using a corrected fixed-width byte-mapping pipeline stabilized by an information-maximizing GAN (IMGAN). A bi-level preprocessing pipeline applies two-sided weighted sparse representation (T-WSR) denoising—designed to selectively suppress zero-padding artifacts, high-entropy packed regions, and sparse opcode noise while preserving discriminative section-boundary texture—followed by geometric augmentation to mitigate class imbalance. Malware detection and family attribution are performed using a residual capsule-based network (RBCN) that fuses discriminative visual representations with PE-header features via concatenation, improving robustness against polymorphism and obfuscation. A formal threat model governs three adversary classes: a semi-honest aggregation server, a bounded fraction of malicious clients (up to 30%), and a passive eavesdropper. To enable collaboration without exposing raw data, clients train locally and share only MemCbar-encrypted updates; a permissioned Hyperledger Fabric blockchain ledger records hashed updates and security events to provide integrity, traceability, and tamper resistance. A file-system-integrated honeypot captures evasive behaviors and logs auditable evidence to strengthen prevention. Experiments on the Malimg dataset across five ablation configurations demonstrate that the corrected RBCN pipeline achieves 93.52% accuracy, 92.40% precision, 93.52% recall, 92.52% F-measure, MCC of 0.9245, and AUC of 0.9976 in its centralized configuration, and 65.62% accuracy with AUC of 0.9840 in the full federated configuration with five clients and eight communication rounds, substantially outperforming all baselines across all reported metrics.

Read PDF

Similar papers

Open access Aug 2026

A Blockchain-Enabled Security Framework for Cloud-Based Sensor Systems with Deep Learning-Driven Attack Classification

A Weighted Symmetric Hashed Blockchain framework that integrates mutual-information-based feature weighting, deep-learning-based attack classification, AES-256-GCM authenticated encryption, cryptographic hashing, and permissioned-ledger logging, demonstrating the potential of WSHB as a reproducible framework for attack classification and secure event logging in cloud-integrated sensor environments.

Naveed Ahmad, Yue Cao, William Liu · 0 citations
Aug 2026

A Secure Federated Learning and Blockchain Framework for E-Health Threat Detection

The proposed framework effectively integrates encryption, federated intrusion detection, explainable artificial intelligence, and blockchain security to enhance privacy, transparency, and reliability in IoMT healthcare networks.

P. Banupriya, K. Vanitha · 0 citations
Aug 2026

Blockchain-Enhanced Secure Data Sharing in Financial Institutions: A Federated Learning Framework for Privacy-Preserving Analytics

The proposed framework for financial system fraud detection that is safe and protects privacy while resolving issues with data sharing, legal restrictions, and cybersecurity threats is appropriate for practical financial applications since it successfully improves fraud detection while guaranteeing Privacy Preservation, security, and openness.

Jie Gao · 0 citations
Conference Jul 2026

SecShield: A Privacy-Preserved Federated Learning Model to Detect Zero-Day Malware Attack

The proliferation of Internet of Things (IoT) devices has amplified the attack surface for large-scale cyber threats, with rapidly evolving malware families such as Mirai posing significant detection challenges. Existing side-channel and host-based approaches are limited by poor generalization to unseen variants and the absence of robust privacy protections during training. In this paper, we propose SecShield, a federated deep learning framework for privacy-preserving malware detection in resource-constrained IoT environments. SecShield employs a three-party secure computation model, where clients locally train a shared deep neural network on power side-channel traces and transmit only noisy parameter updates to a central server via an aggregator, preventing raw data exposure. Differential privacy is incorporated by injecting calibrated noise into gradients, mitigating inference risks such as data reconstruction and poisoning attacks. This decentralized architecture enables continuous adaptation to zero-day malware, reduces communication overhead, and ensures robustness against adversarial manipulation. Experimental evaluations on IoT power trace datasets demonstrate that SecShield achieves high detection accuracy over 98% while preserving client data confidentiality and maintaining computational efficiency.

Damodar Dhital, Sabir Ahmed Khan, Almustapha A. Wakili et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.