Empirical Quantification of Spurious Correlations in Malware Detection
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866908404457406464 |
|---|---|
| author | Perasso, Bianca Lozza, Ludovico Ponte, Andrea Demetrio, Luca Oneto, Luca Roli, Fabio |
| author_facet | Perasso, Bianca Lozza, Ludovico Ponte, Andrea Demetrio, Luca Oneto, Luca Roli, Fabio |
| contents | End-to-end deep learning exhibits unmatched performance for detecting malware, but such an achievement is reached by exploiting spurious correlations -- features with high relevance at inference time, but known to be useless through domain knowledge. While previous work highlighted that deep networks mainly focus on metadata, none investigated the phenomenon further, without quantifying their impact on the decision. In this work, we deepen our understanding of how spurious correlation affects deep learning for malware detection by highlighting how much models rely on empty spaces left by the compiler, which diminishes the relevance of the compiled code. Through our seminal analysis on a small-scale balanced dataset, we introduce a ranking of two end-to-end models to better understand which is more suitable to be put in production. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2506_09662 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Empirical Quantification of Spurious Correlations in Malware Detection Perasso, Bianca Lozza, Ludovico Ponte, Andrea Demetrio, Luca Oneto, Luca Roli, Fabio Cryptography and Security Artificial Intelligence End-to-end deep learning exhibits unmatched performance for detecting malware, but such an achievement is reached by exploiting spurious correlations -- features with high relevance at inference time, but known to be useless through domain knowledge. While previous work highlighted that deep networks mainly focus on metadata, none investigated the phenomenon further, without quantifying their impact on the decision. In this work, we deepen our understanding of how spurious correlation affects deep learning for malware detection by highlighting how much models rely on empty spaces left by the compiler, which diminishes the relevance of the compiled code. Through our seminal analysis on a small-scale balanced dataset, we introduce a ranking of two end-to-end models to better understand which is more suitable to be put in production. |
| title | Empirical Quantification of Spurious Correlations in Malware Detection |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2506.09662 |