返回
Generating sparse explanations for malicious Android opcode sequences using hierarchical LIME
DOI:10.1016/j.cose.2023.103637.png)
摘要
En 中文
In malware analysis, understanding the reasons behind a decision is important for building trust on the system. In the case of opcode-sequence-based classifiers, when standard explanation methods, such as LIME, are applied, the resulting explanation may not provide much insight into the salient parts of the input sequence. This is because LIME treats each opcode as an independent feature, and perturbing this feature will not cause a significant change in the output, meaning the resulting explanation tends to look like random noise. In this paper, we introduce a novel method Hierarchical-LIME (H-LIME) to address this issue. We take into consideration the hierarchical structure of the program, composed of classes and methods. We show that when H-LIME is applied at the level of classes and methods the resulting explanation is sparser, vastly helping improve its interpretability. We conduct extensive experiments by evaluating our proposed method against criteria for accuracy, completeness, sparsity, stability and efficiency. We show that our method significantly improves on all the evaluation criteria compared to other explainability methods.
Keyword:
XAI
Malware detection
Android
Deep learning
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
GDroid: Android malware detection and classification with graph convolutional networkGDroid: 使用图卷积网络进行Android恶意软件检测和分类
COMPUTERS & SECURITY
IF5.4
A Survey of Adversarial Attack and Defense Methods for Malware Classification in Cyber Security网络安全中恶意软件分类的对抗攻防方法综述
Peeking Inside the Black-Box: A Survey on Explainable Artificial Intelligence (XAI)窥视黑匣子: 关于可解释人工智能 (XAI) 的调查
IEEE ACCESS
IF3.6
Zirconium‐Assisted Activation of Palladium To Boost Syngas Production by Methane Dry Reforming锆辅助钯活化甲烷干重整促进合成气生产

