EMBER2024 -- A Benchmark Dataset for Holistic Evaluation of Malware Classifiers

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Joyce, Robert J., Miller, Gideon, Roth, Phil, Zak, Richard, Zaresky-Williams, Elliott, Anderson, Hyrum, Raff, Edward, Holt, James
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915328206831616
author Joyce, Robert J.
Miller, Gideon
Roth, Phil
Zak, Richard
Zaresky-Williams, Elliott
Anderson, Hyrum
Raff, Edward
Holt, James
author_facet Joyce, Robert J.
Miller, Gideon
Roth, Phil
Zak, Richard
Zaresky-Williams, Elliott
Anderson, Hyrum
Raff, Edward
Holt, James
contents A lack of accessible data has historically restricted malware analysis research, and practitioners have relied heavily on datasets provided by industry sources to advance. Existing public datasets are limited by narrow scope - most include files targeting a single platform, have labels supporting just one type of malware classification task, and make no effort to capture the evasive files that make malware detection difficult in practice. We present EMBER2024, a new dataset that enables holistic evaluation of malware classifiers. Created in collaboration with the authors of EMBER2017 and EMBER2018, the EMBER2024 dataset includes hashes, metadata, feature vectors, and labels for more than 3.2 million files from six file formats. Our dataset supports the training and evaluation of machine learning models on seven malware classification tasks, including malware detection, malware family classification, and malware behavior identification. EMBER2024 is the first to include a collection of malicious files that initially went undetected by a set of antivirus products, creating a "challenge" set to assess classifier performance against evasive malware. This work also introduces EMBER feature version 3, with added support for several new feature types. We are releasing the EMBER2024 dataset to promote reproducibility and empower researchers in the pursuit of new malware research topics.
format Preprint
id arxiv_https___arxiv_org_abs_2506_05074
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle EMBER2024 -- A Benchmark Dataset for Holistic Evaluation of Malware Classifiers
Joyce, Robert J.
Miller, Gideon
Roth, Phil
Zak, Richard
Zaresky-Williams, Elliott
Anderson, Hyrum
Raff, Edward
Holt, James
Cryptography and Security
Machine Learning
A lack of accessible data has historically restricted malware analysis research, and practitioners have relied heavily on datasets provided by industry sources to advance. Existing public datasets are limited by narrow scope - most include files targeting a single platform, have labels supporting just one type of malware classification task, and make no effort to capture the evasive files that make malware detection difficult in practice. We present EMBER2024, a new dataset that enables holistic evaluation of malware classifiers. Created in collaboration with the authors of EMBER2017 and EMBER2018, the EMBER2024 dataset includes hashes, metadata, feature vectors, and labels for more than 3.2 million files from six file formats. Our dataset supports the training and evaluation of machine learning models on seven malware classification tasks, including malware detection, malware family classification, and malware behavior identification. EMBER2024 is the first to include a collection of malicious files that initially went undetected by a set of antivirus products, creating a "challenge" set to assess classifier performance against evasive malware. This work also introduces EMBER feature version 3, with added support for several new feature types. We are releasing the EMBER2024 dataset to promote reproducibility and empower researchers in the pursuit of new malware research topics.
title EMBER2024 -- A Benchmark Dataset for Holistic Evaluation of Malware Classifiers
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2506.05074