Return
Self-Supervised Vision Transformers for Malware Detection
DOI:10.1109/ACCESS.2022.3206445.png)
Abstract
En 中文
Malware detection plays a crucial role in cyber-security with the increase in malware growth and advancements in cyber-attacks. Previously unseen malware which is not determined by security vendors are often used in these attacks and it is becoming inevitable to find a solution that can self-learn from unlabeled sample data. This paper presents SHERLOCK, a self-supervision based deep learning model to detect malware based on the Vision Transformer (ViT) architecture. SHERLOCK is a novel malware detection method which learns unique features to differentiate malware from benign programs with the use of image-based binary representation. Experimental results using 1.2 million Android applications across a hierarchy of 47 types and 696 families, shows that self-supervised learning can achieve an accuracy of 97% for the binary classification of malware which is higher than existing state-of-the-art techniques. Our proposed model is also able to outperform state-of-the-art techniques for multi-class malware classification of types and family with macro-F1 score of.497 and.491 respectively.
Keywords:
Malware
Feature extraction
Deep learning
Self-supervised learning
Operating systems
Gray-scale
Visualization
Androids
Self-supervised learning
deep learning
malware detection
Android security
Journal
IF:
3.6
Papers:
9.8W
Citations:
29.4W
Organization
Cited Papers
A Combination Method for Android Malware Detection Based on Control Flow Graphs and Machine Learning Algorithms
IEEE ACCESS
IF3.6
Global Profiling of the Antioxidant Constituents in Chebulae Fructus Based on an Integrative Strategy of UHPLC/IM-QTOF-MS, MS/MS Molecular Networking, and Spectrum-Effect Correlation
Antioxidants
IF0

