Counteracting Concept Drift by Learning with Future Malware Predictions

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Bosansky, Branislav, Hospodkova, Lada, Najman, Michal, Rigaki, Maria, Babayeva, Elnaz, Lisy, Viliam
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866913314859122688
author Bosansky, Branislav
Hospodkova, Lada
Najman, Michal
Rigaki, Maria
Babayeva, Elnaz
Lisy, Viliam
author_facet Bosansky, Branislav
Hospodkova, Lada
Najman, Michal
Rigaki, Maria
Babayeva, Elnaz
Lisy, Viliam
contents The accuracy of deployed malware-detection classifiers degrades over time due to changes in data distributions and increasing discrepancies between training and testing data. This phenomenon is known as the concept drift. While the concept drift can be caused by various reasons in general, new malicious files are created by malware authors with a clear intention of avoiding detection. The existence of the intention opens a possibility for predicting such future samples. Including predicted samples in training data should consequently increase the accuracy of the classifiers on new testing data. We compare two methods for predicting future samples: (1) adversarial training and (2) generative adversarial networks (GANs). The first method explicitly seeks for adversarial examples against the classifier that are then used as a part of training data. Similarly, GANs also generate synthetic training data. We use GANs to learn changes in data distributions within different time periods of training data and then apply these changes to generate samples that could be in testing data. We compare these prediction methods on two different datasets: (1) Ember public dataset and (2) the internal dataset of files incoming to Avast. We show that while adversarial training yields more robust classifiers, this method is not a good predictor of future malware in general. This is in contrast with previously reported positive results in different domains (including natural language processing and spam detection). On the other hand, we show that GANs can be successfully used as predictors of future malware. We specifically examine malware families that exhibit significant changes in their data distributions over time and the experimental results confirm that GAN-based predictions can significantly improve the accuracy of the classifier on new, previously unseen data.
format Preprint
id arxiv_https___arxiv_org_abs_2404_09352
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Counteracting Concept Drift by Learning with Future Malware Predictions
Bosansky, Branislav
Hospodkova, Lada
Najman, Michal
Rigaki, Maria
Babayeva, Elnaz
Lisy, Viliam
Cryptography and Security
Artificial Intelligence
The accuracy of deployed malware-detection classifiers degrades over time due to changes in data distributions and increasing discrepancies between training and testing data. This phenomenon is known as the concept drift. While the concept drift can be caused by various reasons in general, new malicious files are created by malware authors with a clear intention of avoiding detection. The existence of the intention opens a possibility for predicting such future samples. Including predicted samples in training data should consequently increase the accuracy of the classifiers on new testing data. We compare two methods for predicting future samples: (1) adversarial training and (2) generative adversarial networks (GANs). The first method explicitly seeks for adversarial examples against the classifier that are then used as a part of training data. Similarly, GANs also generate synthetic training data. We use GANs to learn changes in data distributions within different time periods of training data and then apply these changes to generate samples that could be in testing data. We compare these prediction methods on two different datasets: (1) Ember public dataset and (2) the internal dataset of files incoming to Avast. We show that while adversarial training yields more robust classifiers, this method is not a good predictor of future malware in general. This is in contrast with previously reported positive results in different domains (including natural language processing and spam detection). On the other hand, we show that GANs can be successfully used as predictors of future malware. We specifically examine malware families that exhibit significant changes in their data distributions over time and the experimental results confirm that GAN-based predictions can significantly improve the accuracy of the classifier on new, previously unseen data.
title Counteracting Concept Drift by Learning with Future Malware Predictions
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2404.09352