Related Experiment Videos
Advanced behavioral malware detection: a comprehensive MLOps framework with federated learning and real-time drift
Mohammed El-Hajj1, Mohammad Al Jawad Zeineddine2
1Faculty of Computer Studies (FCS), Arab Open University (AOU), Beirut, Lebanon.
Abstract:
This paper presents a comprehensive MLOps framework for behavioral malware detection that addresses critical challenges in generalization, collaboration, and operational resilience. We introduce three methodological contributions: (1) a formalized Leave-One-Experiment-Out (LOEO) validation protocol that provides conservative assessment of generalization to novel attack methodologies, revealing a 12.3% accuracy drop compared to conventional evaluation; (2) a domain-optimized feature engineering pipeline that transforms raw process telemetry into hierarchical behavioral signatures while maintaining 99.2% accuracy with 50% reduced inference latency; and (3) a hybrid federated learning architecture enabling privacy-preserving collaboration with 75.1% accuracy while maintaining (ϵ, δ)-differential privacy guarantees (ϵ = 3.2, δ = 10-5). A real-time drift detection engine with sub-500 ms latency identifies concept drift using ensemble detection and triggers automated retraining with total recovery time < 5 min (mean 4.2 min). Comprehensive evaluation across 2.74 million behavioral samples from 104 distinct malware experiments validates our approach using up to 104 federated clients, achieving 10,000+ events/s throughput in simulated environments. Architectural projections based on hierarchical aggregation suggest potential scalability to 5,000+ clients, though this remains unvalidated future work. This work bridges the gap between academic research and operational cybersecurity requirements through a production-oriented MLOps implementation.