Skip to main navigation Skip to search Skip to main content

FewFine: Few-shot Malware Traffic Classification Via Transfer Learning based on Fine-tuning Strategy

  • Xingtong Liu*
  • , Meng Shen*
  • , Laizhong Cui
  • , Ke Ye
  • , Jizhe Jia*
  • , Guangchun Yue*
  • *Corresponding author for this work
  • Beijing Institute of Technology
  • Shenzhen University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Malware traffic is constantly evolving and remains destructive. The detection and classification of malware traffic is crucial for maintaining cyberspace security. Only by swiftly and accurately detecting and classifying malware traffic can user privacy and cyberspace security be effectively protected.In this paper, we propose FewFine, an approach for few-shot malware traffic classification based on transfer learning. We initially pre-train a detection model and two classification models with substantial quantity of malware and application traffic samples. For classifying new types of malware traffic accurately and promptly, we utilize transfer learning based on fine-tuning strategy and freeze several blocks in the pre-trained model. Utilizing prior knowledge from the pre-trained models, we leverage few samples of novel classes to perform accurate malware detection and classification. We execute extensive experiments on publicly available datasets to evaluate the effectiveness of FewFine. In model pre-training, with considerable number of samples, the accuracy of malware detection and classification can reach 0.99. The pre-trained models are saved for fine-tuning. When detecting and classifying novel malware traffic, FewFine can achieve the accuracy of 0.95 leveraging only 10 samples per class through fine-tuning the pre-trained model. It outperforms methods under comparison in terms of accuracy and efficiency.

Original languageEnglish
Title of host publicationProceedings - 2022 IEEE SmartWorld, Ubiquitous Intelligence and Computing, Autonomous and Trusted Vehicles, Scalable Computing and Communications, Digital Twin, Privacy Computing, Metaverse, SmartWorld/UIC/ATC/ScalCom/DigitalTwin/PriComp/Metaverse 2022
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages425-432
Number of pages8
ISBN (Electronic)9798350346558
DOIs
Publication statusPublished - 2022
Event2022 IEEE SmartWorld, 19th IEEE International Conference on Ubiquitous Intelligence and Computing, 2022 IEEE International Conference on Autonomous and Trusted Vehicles Conference, 22nd IEEE International Conference on Scalable Computing and Communications, 2022 IEEE International Conference on Digital Twin, 8th IEEE International Conference on Privacy Computing and 2022 IEEE International Conference on Metaverse, SmartWorld/UIC/ATC/ScalCom/DigitalTwin/PriComp/Metaverse 2022 - Haikou, China
Duration: 15 Dec 202218 Dec 2022

Publication series

NameProceedings - 2022 IEEE SmartWorld, Ubiquitous Intelligence and Computing, Autonomous and Trusted Vehicles, Scalable Computing and Communications, Digital Twin, Privacy Computing, Metaverse, SmartWorld/UIC/ATC/ScalCom/DigitalTwin/PriComp/Metaverse 2022

Conference

Conference2022 IEEE SmartWorld, 19th IEEE International Conference on Ubiquitous Intelligence and Computing, 2022 IEEE International Conference on Autonomous and Trusted Vehicles Conference, 22nd IEEE International Conference on Scalable Computing and Communications, 2022 IEEE International Conference on Digital Twin, 8th IEEE International Conference on Privacy Computing and 2022 IEEE International Conference on Metaverse, SmartWorld/UIC/ATC/ScalCom/DigitalTwin/PriComp/Metaverse 2022
Country/TerritoryChina
CityHaikou
Period15/12/2218/12/22

Keywords

  • application traffic classification
  • few-shot
  • fine-tune
  • malware traffic classification
  • transfer learning

Fingerprint

Dive into the research topics of 'FewFine: Few-shot Malware Traffic Classification Via Transfer Learning based on Fine-tuning Strategy'. Together they form a unique fingerprint.

Cite this