Despite the promising results of machine learning models in malicious files
detection, they face the problem of concept drift due to their constant
evolution. This leads to declining performance over time, as the data
distribution of the new files differs from the training one, requiring frequent
model update. In this work, we propose a model-agnostic protocol to improve a
baseline neural network against drift. We show the importance of feature
reduction and training with the most recent validation set possible, and
propose a loss function named Drift-Resilient Binary Cross-Entropy, an
improvement to the classical Binary Cross-Entropy more effective against drift.
We train our model on the EMBER dataset, published in2018, and evaluate it on a
dataset of recent malicious files, collected between 2020 and 2023. Our
improved model shows promising results, detecting 15.2% more malware than a
baseline model.
外部データセット
EMBER
BODMAS
MalwareBazaar
参考文献
Malware detection issues, challenges, and future directions: A survey
Faitouri A. Aboaoja, Anazida Zainal, Fuad A. Ghaleb, Bander Ali Saleh Al-rimy, Taiseer Abdalla Elfadil Eisa, Asma Abbas Hassan Elnour
Published: 2022
The 5th Conference on Information and Knowledge Technology
A survey on heuristic malware detection techniques
Zahra Bazrafshan, Hashem Hashemi, Seyed Mehdi Hazrati Fard, Ali Hamzeh
Published: 2013
Advances in neural information processing systems
Lightgbm: A highly efficient gradient boosting decision tree
Guolin Ke, Qi Meng, Thomas Finley, Taifeng Wang, Wei Chen, Weidong Ma, Qiwei Ye, Tie-Yan Liu
Published: 2017
Detection of malware by deep learning as cnn-lstm machine learning techniques in real time
Muhammad Shoaib Akhtar, Tao Feng
Published: 2022
Malware detection using lightgbm with a custom logistic loss function