AIセキュリティポータル K Program
Optimized Deep Learning Models for Malware Detection under Concept Drift
Share
Abstract
Despite the promising results of machine learning models in malicious files detection, they face the problem of concept drift due to their constant evolution. This leads to declining performance over time, as the data distribution of the new files differs from the training one, requiring frequent model update. In this work, we propose a model-agnostic protocol to improve a baseline neural network against drift. We show the importance of feature reduction and training with the most recent validation set possible, and propose a loss function named Drift-Resilient Binary Cross-Entropy, an improvement to the classical Binary Cross-Entropy more effective against drift. We train our model on the EMBER dataset, published in2018, and evaluate it on a dataset of recent malicious files, collected between 2020 and 2023. Our improved model shows promising results, detecting 15.2% more malware than a baseline model.
Malware detection issues, challenges, and future directions: A survey
Faitouri A. Aboaoja, Anazida Zainal, Fuad A. Ghaleb, Bander Ali Saleh Al-rimy, Taiseer Abdalla Elfadil Eisa, Asma Abbas Hassan Elnour
Published: 2022
A survey on heuristic malware detection techniques
Zahra Bazrafshan, Hashem Hashemi, Seyed Mehdi Hazrati Fard, Ali Hamzeh
Published: 2013
Lightgbm: A highly efficient gradient boosting decision tree
Guolin Ke, Qi Meng, Thomas Finley, Taifeng Wang, Wei Chen, Weidong Ma, Qiwei Ye, Tie-Yan Liu
Published: 2017
Detection of malware by deep learning as cnn-lstm machine learning techniques in real time
Muhammad Shoaib Akhtar, Tao Feng
Published: 2022
Malware detection using lightgbm with a custom logistic loss function
Yun Gao, Hirokazu Hasegawa, Yukiko Yamaguchi, Hajime Shimada
Published: 2022
LightGBM Algorithm for Malware Detection
Mouhammd Alkasassbeh, Mohammad Abbadi, Ahmed Al-Bustanji
Published: 2020
Sonicwall 2023 cyber threat report
SonicWall
Published: 2023
Learning under concept drift: A review
Jie Lu, Anjin Liu, Fan Dong, Feng Gu, Joao Gama, Guangquan Zhang
Published: 2018
Bodmas: An open dataset for learning based temporal analysis of pe malware
Limin Yang, Arridhana Ciptadi, Ihar Laziuk, Ali Ahmadzadeh, Gang Wang
Published: 2021
EMBER: An Open Dataset for Training Static PE Malware Machine Learning Models
Hyrum S. Anderson, Phil Roth
Published: 2018.4.13
A survey on supervised classification on data streams
Vincent Lemaire, Christophe Salperwyck, Alexis Bondu
Published: 2015
A comparative study on concept drift detectors
Paulo Gonçalves Jr, Silas Santos, Roberto Barros, Davi Vieira
Published: 2014
An overview of unsupervised drift detection methods
Rosana Noronha Gemaque, Albert França Josua Costa, Rafael Giusti, Eulanda Miranda dos Santos
Published: 2020
CADE: detecting and explaining concept drift samples for security applications
L. Yang, W. Guo, Q. Hao, A. Ciptadi, A. Ahmadzadeh, X. Xing, G. Wang
Published: 2021
Investigating labelless drift adaptation for malware detection
Z. Kan, F. Pendlebury, F. Pierazzi, L. Cavallaro
Published: 2021
Enhancing State-of-the-Art Classifiers with API Semantics to Detect Evolved Android Malware
X. Zhang, Y. Zhang, M. Zhong, D. Ding, Y. Cao, Y. Zhang, M. Zhang, M. Yang
Published: 2020
Designing Machine Learning Systems: An Iterative Process for Production-ready Applications
C. Huyen
Published: 2022
Machine learning & concept drift based approach for malicious website detection
Siddharth Singhal, Utkarsh Chawla, Rajeev Shorey
Published: 2020
Transcend: Detecting concept drift in malware classification models
R. Jordaney, K. Sharad, S. K. Dash, Z. Wang, D. Papini, I. Nouretdinov, L. Cavallaro
Published: 2017
Transcending Transcend: Revisiting Malware Classification in the Presence of Concept Drift
Federico Barbero, Feargus Pendlebury, Fabio Pierazzi, Lorenzo Cavallaro
Published: 2020.10.8
The concept drift problem in android malware detection and its solution
Donghui Hu, Zhongjin Ma, Xiaotian Zhang, Peipei Li, Ye Dengpan, Baohong Ling
Published: 2017
Context-aware, Adaptive and Scalable Android Malware Detection through Online Learning (extended version)
Annamalai Narayanan, Mahinthan Chandramohan, Lihui Chen, Yang Liu
Published: 2017.6.3
A new adaptive learning algorithm and its application to online malware detection
Andy Huynh, Wee Keong Ng, Kanishka Ariyapala
Published: 2017
Droidvolver: Self-evolving android malware detection system
K. Xu, Y. Li, R. Deng, K. Chen, J. Xu
Published: 2019
Continuous Learning for Android Malware Detection
Yizheng Chen, Zhoujie Ding, David Wagner
Published: 2023.2.9
Deep networks in online malware detection
Jirí Tumpach, Marek Krcal, Martin Hole na
Published: 2019
Gradient starvation: A learning proclivity in neural networks
Mohammad Pezeshki, Sekou-Oumar Kaba, Yoshua Bengio, Aaron Courville, Doina Precup, Guillaume Lajoie
Published: 2021
Improved multi-label classification under temporal concept drift: Rethinking group-robust algorithms in a label-wise setting
Ilias Chalkidis, Anders Søgaard
Published: 2022
Spectral decoupling for training transferable neural networks in medical imaging
Joona Pohjonen, Carolin Sturenberg, Antti Rannikko, Tuomas Mirtti, Esa Pitkanen
Published: 2022
Malwarebazaar website
MalwareBazaar
Published: 2023
Feature selection: A literature review
Vipin Kumar
Published: 2014
A review of feature selection and its methods
B. Venkatesh, J. Anuradha
Published: 2019
Why are the module timestamps in windows 10 so nonsensical?
Raymond Chen
Published: 2018
Random forests
L Breiman
Published: 2001
All models are wrong, but many are useful: Learning a variable’s importance by studying an entire class of prediction models simultaneously
Aaron Fisher, Cynthia Rudin, Francesca Dominici
Published: 2019
Interpretable Machine Learning
Christoph Molnar
Published: 2022
Decoupled weight decay regularization
Ilya Loshchilov, Frank Hutter
Published: 2018
Combat security alert fatigue with ai-assisted techniques
Tao Ban
Published: 2021
Share