arXiv:2506.05074cs.CRcs.LG2025-06KDD被引 46

构建首个覆盖多平台的恶意软件评估数据集,支持七类任务并包含逃逸样本挑战集。

EMBER2024 -- A Benchmark Dataset for Holistic Evaluation of Malware Classifiers

  • 整合320万+文件,支持六种格式与七类分类任务的统一评估
  • 首次引入未被主流杀毒软件检测出的逃逸样本,形成挑战集
  • 新增特征类型,兼容旧版特征版本,助力模型可复现研究

长期以来,恶意软件分析研究受限于可用数据的匮乏,实践者主要依赖行业提供的数据集推进工作。现有公开数据集存在范围狭窄的问题:多数仅针对单一平台,标签仅支持一类分类任务,且未涵盖实际检测中具有规避能力的恶意文件。本文提出 EMBER2024,一个支持恶意软件分类器全貌评估的新数据集。该数据集由 EMBER2017、EMBER2018 原作者团队共同构建,包含超过 320 万个文件的哈希值、元数据、特征向量和标签,覆盖六种文件格式。其支持七类机器学习模型训练与评估任务,包括恶意软件检测、家族分类及行为识别。尤为关键的是,该数据集首次纳入一组初始未被多个主流杀毒产品检测到的恶意文件,构成“挑战集”以评估分类器对逃避性恶意软件的表现。同时,本文推出 EMBER 特征版本 3,新增多种特征类型。我们将 EMBER2024 数据集公开发布,以促进研究可复现性,并推动新型恶意软件研究议题的发展。

原文摘要 · Abstract (English)

A lack of accessible data has historically restricted malware analysis research, and practitioners have relied heavily on datasets provided by industry sources to advance. Existing public datasets are limited by narrow scope - most include files targeting a single platform, have labels supporting just one type of malware classification task, and make no effort to capture the evasive files that make malware detection difficult in practice. We present EMBER2024, a new dataset that enables holistic evaluation of malware classifiers. Created in collaboration with the authors of EMBER2017 and EMBER2018, the EMBER2024 dataset includes hashes, metadata, feature vectors, and labels for more than 3.2 million files from six file formats. Our dataset supports the training and evaluation of machine learning models on seven malware classification tasks, including malware detection, malware family classification, and malware behavior identification. EMBER2024 is the first to include a collection of malicious files that initially went undetected by a set of antivirus products, creating a "challenge" set to assess classifier performance against evasive malware. This work also introduces EMBER feature version 3, with added support for several new feature types. We are releasing the EMBER2024 dataset to promote reproducibility and empower researchers in the pursuit of new malware research topics.

恶意软件数据集机器学习安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。