arXiv:2507.04275cs.CRcs.AI2025-07被引 1

用图神经网络识别未知安卓恶意软件,无需事先样本

VOLTRON: Detecting Unknown Malware Using Graph-Based Zero-Shot Learning

  • 构建应用图结构,结合变分图自编码与孪生网络
  • 未知恶意软件检测准确率96.24%,召回率95.20%
  • 适合应对新型、无标注的零日恶意软件威胁

安卓恶意软件持续威胁全球数百万用户的安全。尽管已有诸多基于机器学习的检测方法,但其对大规模标注数据的依赖使其在面对新兴、此前未见的恶意软件家族时效果受限,因缺乏相关标注数据。为此,我们提出一种新型零样本学习框架,融合变分图自编码器(VGAE)与孪生神经网络(SNN),无需特定恶意软件家族的先验样本即可识别恶意软件。该方法利用安卓应用的图结构表示,能够捕捉良性与恶意软件之间的细微结构差异,即使在无新威胁标注数据的情况下亦可有效检测。实验结果表明,该方法在零日恶意软件检测上优于现有最优的MaMaDroid。模型对未知恶意软件家族的准确率达96.24%,召回率为95.20%,展现出对不断演化的安卓威胁的强大鲁棒性。

原文摘要 · Abstract (English)

The persistent threat of Android malware presents a serious challenge to the security of millions of users globally. While many machine learning-based methods have been developed to detect these threats, their reliance on large labeled datasets limits their effectiveness against emerging, previously unseen malware families, for which labeled data is scarce or nonexistent. To address this challenge, we introduce a novel zero-shot learning framework that combines Variational Graph Auto-Encoders (VGAE) with Siamese Neural Networks (SNN) to identify malware without needing prior examples of specific malware families. Our approach leverages graph-based representations of Android applications, enabling the model to detect subtle structural differences between benign and malicious software, even in the absence of labeled data for new threats. Experimental results show that our method outperforms the state-of-the-art MaMaDroid, especially in zero-day malware detection. Our model achieves 96.24% accuracy and 95.20% recall for unknown malware families, highlighting its robustness against evolving Android threats.

恶意软件检测零样本学习图神经网络安卓安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。