Can Spiking Neural Networks Help IoT Systems Decide How to Patch Malware?
Published:
Malware can spread rapidly across Internet of Things (IoT) environments. Responding to this threat is challenging because IoT devices are numerous, heterogeneous, and often constrained in their processing power, memory, and energy.
This blog post presents our paper, [Malware Patching Strategies in Edge Intelligence IoT Systems: A Differential Dependable and Secure Computing*.
Why is IoT malware patching difficult?
Traditional patching decisions are often based on fixed rules or centrally managed schedules. Such approaches may be unsuitable when malware behaviour changes over time or when defenders must make rapid decisions across a large and dynamic collection of devices.
A defender must decide where and when to allocate limited patching resources. At the same time, malware continues to infect devices and alter the security state of the network. Patching can therefore be viewed as a dynamic strategic problem between malware propagation and defensive intervention.
What did we propose?
We modelled the interaction between infected IoT devices and edge nodes as a differential game. Differential games provide a mathematical framework for representing competing decisions whose effects evolve continuously over time.
The model describes the changing security states of IoT devices through differential equations and incorporates both attack and defence intentions. This theoretical formulation allows optimal malware patching strategies to be investigated using optimal control principles.
For practical patching decisions, we developed a Differential Games-Based Deep Spiking Q-Network, called DGDSQ. The method combines the strategic model with deep reinforcement learning and spiking neural networks.
What did we find?
Our simulation results show that edge nodes supported by DGDSQ can make effective patching decisions against IoT malware propagation. In the evaluated scenarios, the proposed approach performed better than Double Deep Q-Network and Dueling Double Deep Q-Network alternatives.
These results demonstrate the potential of combining differential game theory with learning methods that are inspired by the event-driven behaviour of biological neurons.
Perspective
The interesting aspect of this work is the connection between a mathematical attack-defence model and a learning-based decision mechanism. Differential games help us represent the strategic interaction, while the spiking reinforcement learning model supports practical and adaptive patching decisions.
This combination could inform future defensive mechanisms for large IoT deployments in which static patching policies cannot respond adequately to a changing threat environment.
The paper was co-authored with Yizhou Shen, Carlton Shepherd, Shigen Shen, and Shui Yu.
