MH-AutoML让安卓恶意软件检测既快又透明,无需牺牲性能。
Interpretable by Design: MH-AutoML for Transparent and Efficient Android Malware Detection without Compromising Performance
- 专为安卓恶意软件设计,自动完成数据处理到模型调优全流程。
- 相比7个主流AutoML工具,召回率更高且过程可解释。
- 适合需要透明决策的网络安全场景,兼顾效率与可追溯性。
安卓系统中的恶意软件检测需结合网络安全知识与机器学习技术。自动化机器学习(AutoML)通过减少对专业知识的依赖,简化了机器学习开发流程。然而,现有AutoML方案多为黑箱系统,缺乏透明度、可解释性及实验可追溯性。为此,本文提出针对安卓恶意软件检测的领域专用框架MH-AutoML,自动化完成数据预处理、特征工程、算法选择与超参数调优。该框架集成可解释性、调试与实验追踪功能,弥补通用解决方案的不足。在与Auto-Sklearn、AutoGluon、TPOT、HyperGBM、Auto-PyTorch、LightAutoML和MLJAR共七种主流AutoML框架的对比中,MH-AutoML在保持计算效率的同时,实现了更高的召回率,并提供了更强的透明度与控制能力,适用于对性能与可解释性并重的网络安全应用。
原文摘要 · Abstract (English)
Malware detection in Android systems requires both cybersecurity expertise and machine learning (ML) techniques. Automated Machine Learning (AutoML) has emerged as an approach to simplify ML development by reducing the need for specialized knowledge. However, current AutoML solutions typically operate as black-box systems with limited transparency, interpretability, and experiment traceability. To address these limitations, we present MH-AutoML, a domain-specific framework for Android malware detection. MH-AutoML automates the entire ML pipeline, including data preprocessing, feature engineering, algorithm selection, and hyperparameter tuning. The framework incorporates capabilities for interpretability, debugging, and experiment tracking that are often missing in general-purpose solutions. In this study, we compare MH-AutoML against seven established AutoML frameworks: Auto-Sklearn, AutoGluon, TPOT, HyperGBM, Auto-PyTorch, LightAutoML, and MLJAR. Results show that MH-AutoML achieves better recall rates while providing more transparency and control. The framework maintains computational efficiency comparable to other solutions, making it suitable for cybersecurity applications where both performance and explainability matter.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。