Skip to content

Author

Isaac Osei Asante

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Robust Few-Shot Malware Detection in IoT via ACL on Heterogeneous Behavior Graphs

The proliferation of Internet of Things (IoT) devices has expanded the attack surface for sophisticated, polymorphic malware. Traditional intrusion detection systems (IDSs) and standard graph neural networks (GNNs) struggle with the heterogeneity of IoT traffic, adversarial structural perturbations, and the scarcity of labeled data for zero-day threats. This article introduces HeG-Defend, a novel framework unifying adversarial heterogeneous graph contrastive learning (AHGCL) with meta-learning. We propose a methodology to construct heterogeneous behavior graphs (HBGs) from raw traffic, preserving rich semantic contexts via meta-path topology. To combat label scarcity and adversarial fragility, we use a min–max contrastive training objective, where a learnable graph augmenter generates “hard” adversarial views to force the encoder to learn robust, invariant representations. Furthermore, a prototypical meta-learning module is integrated to enable rapid N-way K-shot adaptation to unseen malware. Experiments on the IoT-23 benchmark demonstrate that HeG-Defend achieves a 99.7% $F1$ -score on known classes and improves few-shot detection on zero-day variants by 14.5% over baselines. Crucially, under glass box PGD topology attacks, our model maintains 91.4% accuracy, significantly outperforming traditional GNNs.

Isaac Osei Asante, Farouk Abass · 0 citations