arrow
Return

One step forward, two steps back: ML-based malware detection under concept drift

delete2025-10-06
delete0
PRE
AI
A
Ahmed Abusnaina
A
Afsah Anwar
M
Muhammad Saad
A
Abdulrahman Alabduljabbar
R
Rhongho Jang
S
Saeed Salem
D
David Mohaisen *
DOI:10.1007/s00607-025-01543-7delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The arms race between malware authors and detection frameworks is marked by continuous malware mutations and corresponding model retraining efforts. With over 1.5 million new samples reported daily (VirusTotal Statistics, 2025 https://www.virustotal.com/en/statistics/ ), retraining has become the de facto response to evolving threats. In this paper, we question the effectiveness of this approach by exposing key limitations: while retraining offers only marginal improvements in detecting malicious samples, it often degrades performance on benign samples. To address these challenges, we evaluate multiple retraining strategies that enable the timely detection of emerging malware families while tracking mutation patterns. Our analysis reveals that retraining can unintentionally aid adversaries by allowing the reuse of old malware samples, which online detectors often discard. Additionally, we uncover labeling inconsistencies−such as family renaming−across online detection engines, which obscure shared malicious capabilities and weaken family-based detection efforts.
Keywords:
Adversarial machine learning
Robust malware detection
Model drift

Journal

C
Computing
IF:
2.8
Papers:
2.3K
Citations:
3.5K

Organization

U
university of new mexico
Scholars:
1.6W
Papers: 1.3W
Citations: 25
W
wayne state university
Scholars:
2.0W
Papers: 1.6W
Citations: 17
U
University of Central Florida
Scholars:
8.5K
Papers: 6.8K
Citations: 1.4W
Q
Qatar University
Scholars:
8.9K
Papers: 9.0K
Citations: 16
researcher View more organizations