DOMR: Toward Deep Open-World Malware Recognition

计算机科学 恶意软件 人工智能 遗忘 机器学习 再培训 Android(操作系统) 推论 深度学习 代表(政治) 计算机安全 哲学 法学 国际贸易 业务 操作系统 政治 语言学 政治学
作者
Tingting Lu,Junfeng Wang
出处
期刊:IEEE Transactions on Information Forensics and Security [Institute of Electrical and Electronics Engineers]
卷期号:19: 1455-1468 被引量:8
标识
DOI:10.1109/tifs.2023.3338469
摘要

Deep learning has been widely used for Android malware family recognition, but current deep learning-based approaches make the closed-world assumption that malware families encountered during testing are available at training phase. Unfortunately, this assumption is often violated in practice due to the constant emergence of novel categories and the huge cost of collecting abundant training classes, causing serious failures to the existing approaches. Accordingly, a new problem setting for Android malware family recognition is introduced, i.e., deep open-world malware recognition that poses two critical tasks: 1) Open recognition, aiming to not only classify malware from known families (present in training) but detect malware from unknown families (absent in training); 2) Incremental update, aiming to learn about the detected unknown/new categories without retraining from scratch and catastrophically forgetting the previously learned known/old classes. This paper formalizes the problem and proposes a novel solution called DOMR to address the above two tasks in a unified framework. The core of DOMR is an episode-based representation learning scheme that mimics the open-world setting through episodic training to learn a generalizable representation. The key insight is that the training process following the open-world setting forces the representation to accumulate experience in open recognition, thereby facilitating both the classification of known family instances and the detection of unknown family instances at inference. Given this representation, multiple one-vs-rest classifiers are subsequently built to make the final recognition decision through an aggregative strategy. Comparative experiments show that DOMR outperforms start-of-the-art methods, with macro-averaged F1-scores obtained on two datasets reaching 80.88% and 56.17% in the open case, and 79.34% and 49.55% in the incremental case, respectively. Ablation studies further analyze the effectiveness of DOMR in achieving the open recognition and incremental update goals.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
不倒翁37发布了新的文献求助10
1秒前
1秒前
火星上惊蛰完成签到,获得积分10
2秒前
FAN完成签到 ,获得积分10
2秒前
朴实的无极完成签到,获得积分10
3秒前
5秒前
5秒前
molihuakai应助大树十字坡采纳,获得10
5秒前
7秒前
隐形曼青应助咖啡酸醋冰采纳,获得10
7秒前
白开水完成签到,获得积分10
7秒前
彭于晏应助sdnumakabazi采纳,获得30
8秒前
华仔应助Just森采纳,获得10
8秒前
李伟发布了新的文献求助10
9秒前
机智的紫丝完成签到,获得积分10
9秒前
云止完成签到 ,获得积分10
9秒前
终极007完成签到 ,获得积分10
10秒前
不倒翁37完成签到,获得积分10
10秒前
噼里啪啦冲冲子完成签到,获得积分10
10秒前
立青发布了新的文献求助10
11秒前
12秒前
隐形曼青应助大方明杰采纳,获得10
12秒前
徐云完成签到,获得积分10
12秒前
天真怀梦发布了新的文献求助10
13秒前
14秒前
咖啡酸醋冰完成签到,获得积分10
15秒前
Camille完成签到 ,获得积分10
15秒前
CCcc3324完成签到,获得积分10
15秒前
16秒前
16秒前
微笑皮皮虾完成签到,获得积分10
17秒前
种棵糖葫芦树完成签到 ,获得积分10
17秒前
loulan完成签到,获得积分10
17秒前
RUI完成签到 ,获得积分10
18秒前
fool完成签到,获得积分10
18秒前
fantastic完成签到,获得积分10
19秒前
zhangyiyang完成签到,获得积分10
19秒前
斯文败类应助YYYBGGHJU采纳,获得10
19秒前
19秒前
顺利萧完成签到,获得积分10
19秒前
高分求助中
(应助此贴封号)【重要!!请各用户(尤其是新用户)详细阅读】【科研通的精品贴汇总】 10000
The Organometallic Chemistry of the Transition Metals 800
Chemistry and Physics of Carbon Volume 18 800
The Organometallic Chemistry of the Transition Metals 800
Leading Academic-Practice Partnerships in Nursing and Healthcare: A Paradigm for Change 800
The formation of Australian attitudes towards China, 1918-1941 640
Signals, Systems, and Signal Processing 610
热门求助领域 (近24小时)
化学 材料科学 医学 生物 纳米技术 工程类 有机化学 化学工程 生物化学 计算机科学 物理 内科学 复合材料 催化作用 物理化学 光电子学 电极 细胞生物学 基因 无机化学
热门帖子
关注 科研通微信公众号,转发送积分 6437617
求助须知:如何正确求助?哪些是违规求助? 8252063
关于积分的说明 17558310
捐赠科研通 5496115
什么是DOI,文献DOI怎么找? 2898680
邀请新用户注册赠送积分活动 1875337
关于科研通互助平台的介绍 1716355