返回
Impact of benign sample size on binary classification accuracy
DOI:10.1016/j.eswa.2022.118630.png)
摘要
En 中文
Recently, there has been a significant increase in malware attacks and malicious traffic. Consequently, several machine learning-based detection models have been developed to detect them. However, the detection accuracy of these models is currently evaluated using different methodologies and datasets, with some studies overstating high detection rates. The lack of a common testing approach coupled with the limited datasets used for the experiments make it challenging to compare the performances of these models to identify those that provide superior detection accuracy. A few studies have focused on benign samples and their effects on detection accuracy. The datasets used in the experiments generally consist of benign and malicious samples; hence, binary classification is used in the machine learning models. In the binary classification task, the size of a benign sample affects the classification accuracy of malicious samples, that is, it can either improve or degrade detection accuracy. In this study, we propose a novel metric for evaluating accuracy degradation by increasing benign sample size. We mainly used the FFRI dataset, which consists of 11,243 malware samples and 250,000 benign samples, and evaluated the classification accuracy with extracted strings from the malware. In addition, we obtained other malware samples that we used as supplementary to the main dataset. We increased the number of benign samples for testing by tenfold, while maintaining the malicious sample and benign training sample sizes, which resulted in a decrease of 0.293 in the F1 score. Furthermore, we confirmed that using a sufficiently sized benign training sample set mitigates accuracy degradation. Our metric can be beneficial for evaluating the benign sample size needed in binary classification and comparing accuracy.
Keyword:
Malware
Machine learning
Binary classification
Benign sample
Random forest
Support vector machine
XGBoost
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
7.5
论文数:
3.0W
被引数:
10.2W
机构
引用论文
Machine Learning for Misuse-Based Network Intrusion Detection: Overview, Unified Evaluation and Feature Choice Comparison Framework基于误用的网络入侵检测的机器学习: 概述,统一评估和特征选择比较框架
IEEE ACCESS
IF3.6
Addressing the class imbalance problem in Twitter spam detection using ensemble learning
COMPUTERS & SECURITY
IF5.4
Expression of IDO1 and PD-L2 in Patients with Benign Lymphadenopathies and Association with Autoimmune Diseases
Biomolecules
IF0
Allosteric Regulation in Phosphofructokinase from the Extreme Thermophile Thermus thermophilus
Biochemistry
IF0

