返回
I-MAD : Interpretable malware detector using Galaxy Transformer
DOI:10.1016/j.cose.2021.102371.png)
摘要
En 中文
Malware currently presents a number of serious threats to computer users. Signature-based malware detection methods are limited in detecting new malware samples that are significantly different from known ones. Therefore, machine learning-based methods have been proposed, but there are two challenges these methods face. The first is to model the full semantics behind the assembly code of malware. The second challenge is to provide interpretable results while keeping excellent detection performance. In this paper, we propose an Interpretable MAlware Detector ( I-MAD ) that outperforms state-of-the-art static malware detection models regarding accuracy with excellent interpretability. To improve the detection performance, I-MAD incorporates a novel network component called the Galaxy Transformer network that can understand assembly code at the basic block, function, and executable levels. It also incorporates our proposed interpretable feed-forward neural network to provide interpretations for its detection results by quantifying the impact of each feature with respect to the prediction. Experiment results show that our model significantly outperforms existing state-of-the-art static malware detection models and presents meaningful interpretations. (c) 2021 Elsevier Ltd. All rights reserved.
Keyword:
Cybersecurity
Malware detection
Deep learning
Transformers
Interpretability
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Image-Based malware classification using ensemble of CNN architectures (IMCEC)
COMPUTERS & SECURITY
IF5.4
Deep EHR: A Survey of Recent Advances in Deep Learning Techniques for Electronic Health Record (EHR) Analysis深度EHR: 用于电子健康记录 (EHR) 分析的深度学习技术的最新进展综述
MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral Models (Extended Version)MaMaDroid: 通过构建行为模型的马尔可夫链来检测Android恶意软件 (扩展版本)

