Membership Inference Attacks (MIAs) pose a significant privacy risk in machine learning by enabling adversaries to infer whether specific data samples were used during training, particularly in sensitive domains such as social media and mental health analytics. To address this challenge, this paper proposes HEbdMIA, a lightweight homomorphic encryption-based defense that operates at the post-inference stage by encrypting model output logits without requiring retraining or architectural modifications. The proposed approach preserves the relative ordering of predictions while obscuring confidence patterns exploited by MIAs. Experimental evaluation on DepInferAttack and BotInferAttack demonstrates that HEbdMIA achieves a reduction in MIA success rates of 31.0% and 27.3%, respectively, with an associated accuracy decrease of 29.3% and 26.4%, reflecting a controlled privacy and utility trade off. Additional analysis using precision, recall, F1-score, and ROC-AUC confirms a substantial decline in adversarial inference capability. These findings indicate that HEbdMIA provides an effective, scalable, and deployment-friendly solution for enhancing privacy in real-world machine learning systems.
- Article type
- Year
- Co-author
Open Access
Article
Issue
Open Access
Article
Issue
Malware remains a persistent and evolving threat to digital security, highlighting the need for advanced and resilient detection frameworks capable of mitigating increasingly sophisticated and evasive cyberattacks. Although deep learning ensembles have been explored, many existing approaches fail to balance computational efficiency with the diverse feature extraction capabilities needed for complex variants. To address this gap, this study proposes a novel stacking ensemble framework, MalDetect-IoT, which specifically eliminates the requirement for manual feature engineering and domain specific preprocessing traditionally required in malware classification. By fine-tuning two pre-trained models MobileNetV3 for its lightweight efficiency and Xception for its depthwise distinct convolutions within a stacked architecture, the ensemble achieves superior reliability and predictive accuracy while remaining suitable for resource limited Internet of Things (IoT) environments. The proposed approach leverages complementary features to identify nuanced structural characteristics in malware binaries transformed into images, achieving domain knowledge independence. The proposed approach was evaluated on two benchmark datasets, achieving accuracies of 98.75% on the Malimg dataset (9335 images) and 98.55% on the MaleVis dataset (14,226 images). Statistical validation via McNemar’s test and a Cohen’s kappa coefficient of 0.983 confirm that the framework consistently surpasses state of the art methodologies in effectively identifying malware instances.
京公网安备11010802044758号