Protecting Privacy in Malware-Infected Edge Intelligence and IoT Systems
Published:
Malware infections in Internet of Things (IoT) systems can lead to both device compromise and the leakage of sensitive information. Protecting privacy in these environments is challenging because defenders often have incomplete information about which devices are infected and how the malware is behaving.
This blog post discusses our paper, Privacy Preservation Strategies for Malware-Infected Edge Intelligence Systems: A Bayesian Stochastic Game-Based Approach https://doi.org/10.1109/TMC.2025.3546910, published in IEEE Transactions on Mobile Computing.
What problem did we investigate?
Common privacy-preserving techniques include data masking, anonymisation, and differential privacy. These techniques are valuable, but they do not always model the strategic interactions that occur between malware-infected IoT devices and the edge nodes responsible for protecting the system.
The problem becomes more difficult when a defender cannot directly observe the complete security state of every device. Decisions must then be made under uncertainty while malware infections, privacy leakage, detection outcomes, and false alarms evolve over time.
What did we propose?
We modelled the interactions between IoT endpoints and edge nodes as an incomplete-information stochastic game. Bayesian reasoning was used to represent uncertainty about privacy leakage and malware infection. In particular, posterior probabilities were updated using Bayes’ rule to estimate the likely security state of IoT endpoints.
For practical decision-making, we proposed a reinforcement learning method called Bayesian Advantage Actor-Critic, or BA2C. The method enables edge nodes to learn privacy-preservation strategies while considering uncertain and changing system conditions.
What did we find?
Our simulations examined how decision-making was affected by factors including the successful malware detection rate, successful infection rate, and false alarm rate. We also compared BA2C with alternative learning algorithms.
The results demonstrate that combining Bayesian inference, stochastic game modelling, and actor-critic learning can support adaptive privacy-preservation decisions in malware-infected edge intelligence systems.
Perspective
An important aspect of this work is that privacy protection is represented as a dynamic decision problem rather than a one-time technical control. Edge nodes must continually revise their beliefs and actions as new information becomes available.
This provides a useful foundation for privacy-preserving IoT defence in situations where complete knowledge of malware activity is unavailable.
The paper was co-authored with Yizhou Shen, Carlton Shepherd, Shigen Shen, and Shui Yu.
Reference
https://doi.org/10.1109/TMC.2025.3546910. IEEE Transactions on Mobile Computing 24, 8 (2025), 7121–7135. https://doi.org/10.1109/TMC.2025.3546910
