Device-Specific ML Model Configuration for Malware Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing malware detection systems deploy uniform machine learning (ML) models across computing devices with varying capabilities, leading to inconsistent and often incorrect classifications, which can expose devices to malware due to a lack of tailored configurations based on their unique computing parameters.
Innovation Solution
The system determines unique ML model configurations for each computing device by considering parameters such as available memory and CPU capacity, selecting and configuring ML models to match the device's capabilities, and deploying them to ensure accurate malware classification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If uniform ML models are deployed across all computing devices, then deployment simplicity is maintained, but malware detection accuracy deteriorates due to inconsistent classifications on devices with varying capabilities
Solution Approach 1:
The patent implements local quality by configuring ML models with device-specific parameters tailored to individual computing device capabilities. The system determines computing parameters for each device and adjusts ML model configurations accordingly, ensuring that each device receives optimized model parameters matching its specific hardware characteristics rather than using uniform deployment across all devices.
Solution Approach 2:
The patent applies parameter changes by dynamically adjusting ML model parameters based on detected computing device characteristics. The system modifies model parameters such as complexity, resource allocation, and processing depth according to each device's computing power, memory, and processing capabilities, thereby optimizing detection accuracy for diverse hardware environments.
2Measurement precision
If ML model configurations are tailored to individual device capabilities, then malware detection accuracy is improved, but system complexity increases due to multiple device assessments and model configurations
Solution Approach 1:
The patent implements self-service by enabling computing devices to autonomously assess their own computing parameters and automatically receive appropriately configured ML models without manual intervention. The system performs self-diagnosis of hardware capabilities and self-configures the optimal ML model parameters, eliminating the need for complex manual deployment processes.
Solution Approach 2:
The patent applies preliminary action by pre-assessing computing device parameters before deploying ML models. The system performs upfront characterization of device capabilities and pre-configures appropriate model parameters in advance, avoiding the need for complex real-time adjustments and simplifying the overall deployment process.
3Adaptability or versatility
If computing parameters are assessed for each device, then customized ML configurations can be provided, but time consumption increases due to additional assessment steps
Solution Approach 1:
The patent applies preliminary action by performing computing parameter assessment and ML model configuration in advance before actual malware detection operations begin. The system characterizes device capabilities upfront and pre-configures optimal model parameters, so that when deployment occurs, the process is already optimized and ready to execute without time-consuming adjustments during operation.
Data Source
AI summary
Methods and apparatus to determine machine learning (ML) configurations for classifying malware are disclosed. An example server comprises interface circuitry, machine readable instructions, and programmable circuitry to at least one of instantiate or execute the machine readable instructions to determine a computing parameter associated with a computing device, the computing device communicatively coupled to the server, select a ML model to deploy on the computing device based on the computing parameter, determine a configuration of the ML model based on the computing parameter, deploy the ML model to the computing device, and cause the deployed ML model to classify a sample as clean or malicious, the sample received at the computing device.


