MADCAT: Combating Malware Detection Under Concept Drift with Test-Time Adaptation

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Roh, Eunjin, Kaya, Yigitcan, Kruegel, Christopher, Vigna, Giovanni, Hong, Sanghyun
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908378741080064
author Roh, Eunjin
Kaya, Yigitcan
Kruegel, Christopher
Vigna, Giovanni
Hong, Sanghyun
author_facet Roh, Eunjin
Kaya, Yigitcan
Kruegel, Christopher
Vigna, Giovanni
Hong, Sanghyun
contents We present MADCAT, a self-supervised approach designed to address the concept drift problem in malware detection. MADCAT employs an encoder-decoder architecture and works by test-time training of the encoder on a small, balanced subset of the test-time data using a self-supervised objective. During test-time training, the model learns features that are useful for detecting both previously seen (old) data and newly arriving samples. We demonstrate the effectiveness of MADCAT in continuous Android malware detection settings. MADCAT consistently outperforms baseline methods in detection performance at test time. We also show the synergy between MADCAT and prior approaches in addressing concept drift in malware detection
format Preprint
id arxiv_https___arxiv_org_abs_2505_18734
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle MADCAT: Combating Malware Detection Under Concept Drift with Test-Time Adaptation
Roh, Eunjin
Kaya, Yigitcan
Kruegel, Christopher
Vigna, Giovanni
Hong, Sanghyun
Cryptography and Security
Machine Learning
We present MADCAT, a self-supervised approach designed to address the concept drift problem in malware detection. MADCAT employs an encoder-decoder architecture and works by test-time training of the encoder on a small, balanced subset of the test-time data using a self-supervised objective. During test-time training, the model learns features that are useful for detecting both previously seen (old) data and newly arriving samples. We demonstrate the effectiveness of MADCAT in continuous Android malware detection settings. MADCAT consistently outperforms baseline methods in detection performance at test time. We also show the synergy between MADCAT and prior approaches in addressing concept drift in malware detection
title MADCAT: Combating Malware Detection Under Concept Drift with Test-Time Adaptation
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2505.18734