arXiv:2502.10556cs.CRcs.LG2025-02被引 21

用图神经网络分析恶意软件行为,提升检测效果与可解释性。

Recent Advances in Malware Detection: Graph Learning and Explainability

  • 基于图神经网络建模恶意软件的复杂行为关系
  • 融合特征工程与图嵌入,实现高效可扩展检测
  • 增强结果可解释性,适合安全研究人员和开发团队

恶意软件的快速演化推动了超越传统签名检测方法的新型检测技术发展。图学习技术因其在建模恶意软件行为内在复杂关系方面的优势而成为关键工具,得益于图神经网络(GNNs)及相关方法的进步。本综述全面探讨了恶意软件检测领域的最新进展,聚焦图学习与可解释性的协同作用。首先回顾了恶意软件分析技术与数据集,强调其在理解恶意行为及支持检测策略中的基础作用。接着讨论了特征工程、图简化与图嵌入方法,突出其将原始数据转化为可操作洞察的重要性,同时保障系统的可扩展性与效率。此外,本综述重点分析了可解释性技术及其在恶意软件检测中的应用,确保系统透明可信。通过整合上述要素,展示了图学习与可解释性如何共同构建鲁棒、可解释且可扩展的恶意软件检测系统。最后指出了未来研究方向,以应对现有挑战并开拓该关键网络安全领域的新机遇。

原文摘要 · Abstract (English)

The rapid evolution of malware has necessitated the development of sophisticated detection methods that go beyond traditional signature-based approaches. Graph learning techniques have emerged as powerful tools for modeling and analyzing the complex relationships inherent in malware behavior, leveraging advancements in Graph Neural Networks (GNNs) and related methods. This survey provides a comprehensive exploration of recent advances in malware detection, focusing on the interplay between graph learning and explainability. It begins by reviewing malware analysis techniques and datasets, emphasizing their foundational role in understanding malware behavior and supporting detection strategies. The survey then discusses feature engineering, graph reduction, and graph embedding methods, highlighting their significance in transforming raw data into actionable insights, while ensuring scalability and efficiency. Furthermore, this survey focuses on explainability techniques and their applications in malware detection, ensuring transparency and trustworthiness. By integrating these components, this survey demonstrates how graph learning and explainability contribute to building robust, interpretable, and scalable malware detection systems. Future research directions are outlined to address existing challenges and unlock new opportunities in this critical area of cybersecurity.

恶意软件检测图神经网络可解释性网络安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。