arXiv:2409.13723cs.CRcs.AI2024-09综述被引 38

让黑箱杀毒模型说清判断依据,提升安全可信度

Explainable Artificial Intelligence (XAI) for Malware Analysis: A Survey of Techniques, Applications, and Open Challenges

  • 用可解释AI技术解析机器学习模型的决策过程
  • 在保持高检测准确率的同时提升结果透明度
  • 适合安全研究人员和需要可信分析的实战场景

近年来,机器学习(ML)在金融、医疗和网络安全等领域快速发展。在恶意软件检测中,基于机器学习的方法已展现出高准确性;然而其缺乏透明性成为关键挑战。传统黑箱模型难以提供可解释的判定理由,限制了其在需理解推理过程的安全关键环境中的应用。可解释人工智能(XAI)通过增强模型可解释性,同时维持强检测能力,弥补了这一空白。本综述系统梳理了当前最先进的机器学习在恶意软件分析中的技术,重点关注可解释性方法。我们分析现有XAI框架及其在恶意软件分类与检测中的应用,并探讨提升恶意软件检测模型可解释性的挑战。此外,还介绍了最新进展,并指出该领域仍存在的开放性研究问题。通过结构化呈现基于XAI的恶意软件检测方法,本综述为寻求提升机器学习性能与可解释性之间平衡的研究人员和从业者提供了重要参考。

原文摘要 · Abstract (English)

Machine learning (ML) has rapidly advanced in recent years, revolutionizing fields such as finance, medicine, and cybersecurity. In malware detection, ML-based approaches have demonstrated high accuracy; however, their lack of transparency poses a significant challenge. Traditional black-box models often fail to provide interpretable justifications for their predictions, limiting their adoption in security-critical environments where understanding the reasoning behind a detection is essential for threat mitigation and response. Explainable AI (XAI) addresses this gap by enhancing model interpretability while maintaining strong detection capabilities. This survey presents a comprehensive review of state-of-the-art ML techniques for malware analysis, with a specific focus on explainability methods. We examine existing XAI frameworks, their application in malware classification and detection, and the challenges associated with making malware detection models more interpretable. Additionally, we explore recent advancements and highlight open research challenges in the field of explainable malware analysis. By providing a structured overview of XAI-driven malware detection approaches, this survey serves as a valuable resource for researchers and practitioners seeking to bridge the gap between ML performance and explainability in cybersecurity.

可解释AI恶意软件分析安全可信

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。