Regression-aware Continual Learning for Android Malware Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ghiani, Daniele, Angioni, Daniele, Piras, Giorgio, Sotgiu, Angelo, Minnei, Luca, Gupta, Srishti, Pintor, Maura, Roli, Fabio, Biggio, Battista
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911074718056448
author Ghiani, Daniele
Angioni, Daniele
Piras, Giorgio
Sotgiu, Angelo
Minnei, Luca
Gupta, Srishti
Pintor, Maura
Roli, Fabio
Biggio, Battista
author_facet Ghiani, Daniele
Angioni, Daniele
Piras, Giorgio
Sotgiu, Angelo
Minnei, Luca
Gupta, Srishti
Pintor, Maura
Roli, Fabio
Biggio, Battista
contents Malware evolves rapidly, forcing machine learning (ML)-based detectors to adapt continuously. With antivirus vendors processing hundreds of thousands of new samples daily, datasets can grow to billions of examples, making full retraining impractical. Continual learning (CL) has emerged as a scalable alternative, enabling incremental updates without full data access while mitigating catastrophic forgetting. In this work, we analyze a critical yet overlooked issue in this context: security regression. Unlike forgetting, which manifests as a general performance drop on previously seen data, security regression captures harmful prediction changes at the sample level, such as a malware sample that was once correctly detected but evades detection after a model update. Although often overlooked, regressions pose serious risks in security-critical applications, as the silent reintroduction of previously detected threats in the system may undermine users' trust in the whole updating process. To address this issue, we formalize and quantify security regression in CL-based malware detectors and propose a regression-aware penalty to mitigate it. Specifically, we adapt Positive Congruent Training (PCT) to the CL setting, preserving prior predictive behavior in a model-agnostic manner. Experiments on the ELSA, Tesseract, and AZ-Class datasets show that our method effectively reduces regression across different CL scenarios while maintaining strong detection performance over time.
format Preprint
id arxiv_https___arxiv_org_abs_2507_18313
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Regression-aware Continual Learning for Android Malware Detection
Ghiani, Daniele
Angioni, Daniele
Piras, Giorgio
Sotgiu, Angelo
Minnei, Luca
Gupta, Srishti
Pintor, Maura
Roli, Fabio
Biggio, Battista
Machine Learning
Cryptography and Security
Malware evolves rapidly, forcing machine learning (ML)-based detectors to adapt continuously. With antivirus vendors processing hundreds of thousands of new samples daily, datasets can grow to billions of examples, making full retraining impractical. Continual learning (CL) has emerged as a scalable alternative, enabling incremental updates without full data access while mitigating catastrophic forgetting. In this work, we analyze a critical yet overlooked issue in this context: security regression. Unlike forgetting, which manifests as a general performance drop on previously seen data, security regression captures harmful prediction changes at the sample level, such as a malware sample that was once correctly detected but evades detection after a model update. Although often overlooked, regressions pose serious risks in security-critical applications, as the silent reintroduction of previously detected threats in the system may undermine users' trust in the whole updating process. To address this issue, we formalize and quantify security regression in CL-based malware detectors and propose a regression-aware penalty to mitigate it. Specifically, we adapt Positive Congruent Training (PCT) to the CL setting, preserving prior predictive behavior in a model-agnostic manner. Experiments on the ELSA, Tesseract, and AZ-Class datasets show that our method effectively reduces regression across different CL scenarios while maintaining strong detection performance over time.
title Regression-aware Continual Learning for Android Malware Detection
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2507.18313