Sergio López
phd student
Edificio de Investigación Ada Byron
C/ Arquitecto Francisco Peñalosa, nº 18
Ampliación Campus de Teatinos. Universidad de Málaga
29071 Málaga (Spain)
Phone: +34 951 952 966
E-mail: sergiolf@uma.es
Current research
- …
- …
Ph.D. research
…
Education
- …
- …
Thesis
- …
- …
Publications
Sergio Lopez-Flores, Antonio Muñoz
Resource-aware electromagnetic malware classification on edge platforms: a controlled cross-platform comparison using Raspberry Pi 5 EM traces
In: Journal of Computer Virology and Hacking Techniques, vol. 22, no. 84, 2026, ISSN: 2263-8733.
@article{sergiolf2026,
title = {Resource-aware electromagnetic malware classification on edge platforms: a controlled cross-platform comparison using Raspberry Pi 5 EM traces},
author = {Sergio Lopez-Flores and Antonio Mu\~{n}oz},
url = {/wp-content/papers/sergiolf2026.pdf},
doi = {10.1007/s11416-026-00661-w},
issn = {2263-8733},
year = {2026},
date = {2026-08-28},
urldate = {2026-08-28},
journal = {Journal of Computer Virology and Hacking Techniques},
volume = {22},
number = {84},
abstract = {Electromagnetic side-channel analysis provides a non-intrusive approach to malware characterization in settings where host-based instrumentation is unavailable, undesirable, or too costly to deploy. In practice, however, the usefulness of this approach depends not only on predictive performance but also on whether the selected models remain practically deployable under constrained hardware resources. This paper presents a controlled cross-platform evaluation of electromagnetic malware classification under resource-limited deployment conditions. A single corpus of electromagnetic traces acquired from a Raspberry Pi 5 using the EM-Sense acquisition workflow is reused unchanged throughout the study. This fixed dataset is used to train and evaluate four classical machine-learning pipelines (LDA+NB, LDA+SVM, LDA+RF, and LDA+XGBoost) and four neural architectures (MLP, CNN, RNN, and GRU) across four labeling granularities: Packer, Virtualized, Type, and Family. The same experimental protocol is executed on a virtual machine and three representative edge platforms (Raspberry Pi 5, Jetson Nano, and Jetson Orin Nano), allowing the influence of computational resources to be isolated from the acquisition process. The results show a clear task-dependent trade-off. In the coarse-grained classification tasks, the classical pipelines provide the most favourable accuracy\textendashcost balance while remaining computationally inexpensive across all evaluated platforms. In the finer-grained tasks, the neural architectures achieve higher predictive performance, although at a substantially greater computational cost. The experiments also identify a practical deployment boundary on Jetson Nano, where the more demanding neural configurations no longer retain a practically useful GPU-accelerated operating mode. Under the evaluation conditions considered in this study, these findings support a resource-aware approach to model selection for electromagnetic malware classification on edge platforms.},
keywords = {},
pubstate = {published},
tppubtype = {article}
}
Electromagnetic side-channel analysis provides a non-intrusive approach to malware characterization in settings where host-based instrumentation is unavailable, undesirable, or too costly to deploy. In practice, however, the usefulness of this approach depends not only on predictive performance but also on whether the selected models remain practically deployable under constrained hardware resources. This paper presents a controlled cross-platform evaluation of electromagnetic malware classification under resource-limited deployment conditions. A single corpus of electromagnetic traces acquired from a Raspberry Pi 5 using the EM-Sense acquisition workflow is reused unchanged throughout the study. This fixed dataset is used to train and evaluate four classical machine-learning pipelines (LDA+NB, LDA+SVM, LDA+RF, and LDA+XGBoost) and four neural architectures (MLP, CNN, RNN, and GRU) across four labeling granularities: Packer, Virtualized, Type, and Family. The same experimental protocol is executed on a virtual machine and three representative edge platforms (Raspberry Pi 5, Jetson Nano, and Jetson Orin Nano), allowing the influence of computational resources to be isolated from the acquisition process. The results show a clear task-dependent trade-off. In the coarse-grained classification tasks, the classical pipelines provide the most favourable accuracy–cost balance while remaining computationally inexpensive across all evaluated platforms. In the finer-grained tasks, the neural architectures achieve higher predictive performance, although at a substantially greater computational cost. The experiments also identify a practical deployment boundary on Jetson Nano, where the more demanding neural configurations no longer retain a practically useful GPU-accelerated operating mode. Under the evaluation conditions considered in this study, these findings support a resource-aware approach to model selection for electromagnetic malware classification on edge platforms.


