arrow
返回

Generating sparse explanations for malicious Android opcode sequences using hierarchical LIME

delete2024-02-01
delete1
delete
OA
AI
J
Jeff Mitchell *
N
Niall McLaughlin
J
Jesús Martínez del Rincón
DOI:10.1016/j.cose.2023.103637delete
delete原文链接
delete分享
delete收藏
查看原文
摘要

摘要

En 中文
In malware analysis, understanding the reasons behind a decision is important for building trust on the system. In the case of opcode-sequence-based classifiers, when standard explanation methods, such as LIME, are applied, the resulting explanation may not provide much insight into the salient parts of the input sequence. This is because LIME treats each opcode as an independent feature, and perturbing this feature will not cause a significant change in the output, meaning the resulting explanation tends to look like random noise. In this paper, we introduce a novel method Hierarchical-LIME (H-LIME) to address this issue. We take into consideration the hierarchical structure of the program, composed of classes and methods. We show that when H-LIME is applied at the level of classes and methods the resulting explanation is sparser, vastly helping improve its interpretability. We conduct extensive experiments by evaluating our proposed method against criteria for accuracy, completeness, sparsity, stability and efficiency. We show that our method significantly improves on all the evaluation criteria compared to other explainability methods.
Keyword:
XAI
Malware detection
Android
Deep learning
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

Q
Queen's University Belfast
学者数:
1.6W
论文数: 1.7W
被引数: 2.5W
引用论文

引用论文

err分享
err收藏
err分享
err收藏
Zirconium‐Assisted Activation of Palladium To Boost Syngas Production by Methane Dry Reforming锆辅助钯活化甲烷干重整促进合成气生产
err2018-09-17
err0
errOAAI
errNorbert Köpfle; Thomas Götsch; Matthias Grünbacher; Emilia A. Carbonio; Michael Hävecker; Axel Knop‐Gericke; Lukas Schlicker; Andrew Doran; Delf Kober; Aleksander Gurlo; Simon Penner; Bernhard Klötzer
err分享
err收藏
Why an Android App Is Classified as Malware: Toward Malware Classification Interpretation
err2021-03-10
err50
errOAAI
errWu, Bozhi; Chen, Sen; Gao, Cuiyun; Fan, Lingling; Liu, Yang; Wen, Weiping; Lyu, Michael R.
err分享
err收藏
err分享
err收藏
学者 查看更多内容