Empirical Quantification of Spurious Correlations in Malware Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Perasso, Bianca, Lozza, Ludovico, Ponte, Andrea, Demetrio, Luca, Oneto, Luca, Roli, Fabio
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908404457406464
author Perasso, Bianca
Lozza, Ludovico
Ponte, Andrea
Demetrio, Luca
Oneto, Luca
Roli, Fabio
author_facet Perasso, Bianca
Lozza, Ludovico
Ponte, Andrea
Demetrio, Luca
Oneto, Luca
Roli, Fabio
contents End-to-end deep learning exhibits unmatched performance for detecting malware, but such an achievement is reached by exploiting spurious correlations -- features with high relevance at inference time, but known to be useless through domain knowledge. While previous work highlighted that deep networks mainly focus on metadata, none investigated the phenomenon further, without quantifying their impact on the decision. In this work, we deepen our understanding of how spurious correlation affects deep learning for malware detection by highlighting how much models rely on empty spaces left by the compiler, which diminishes the relevance of the compiled code. Through our seminal analysis on a small-scale balanced dataset, we introduce a ranking of two end-to-end models to better understand which is more suitable to be put in production.
format Preprint
id arxiv_https___arxiv_org_abs_2506_09662
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Empirical Quantification of Spurious Correlations in Malware Detection
Perasso, Bianca
Lozza, Ludovico
Ponte, Andrea
Demetrio, Luca
Oneto, Luca
Roli, Fabio
Cryptography and Security
Artificial Intelligence
End-to-end deep learning exhibits unmatched performance for detecting malware, but such an achievement is reached by exploiting spurious correlations -- features with high relevance at inference time, but known to be useless through domain knowledge. While previous work highlighted that deep networks mainly focus on metadata, none investigated the phenomenon further, without quantifying their impact on the decision. In this work, we deepen our understanding of how spurious correlation affects deep learning for malware detection by highlighting how much models rely on empty spaces left by the compiler, which diminishes the relevance of the compiled code. Through our seminal analysis on a small-scale balanced dataset, we introduce a ranking of two end-to-end models to better understand which is more suitable to be put in production.
title Empirical Quantification of Spurious Correlations in Malware Detection
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2506.09662