研究发现安卓恶意软件检测模型受概念漂移影响严重,需改进应对策略。
Empirical Evaluation of Concept Drift in ML-Based Android Malware Detection
- 对比九种算法与多类特征,评估概念漂移影响。
- 静态、动态等特征类型显著影响模型性能下降程度。
- 大语言模型虽有潜力,仍无法完全解决漂移问题。
尽管机器学习在安卓恶意软件检测中表现优异,但快速演化的恶意软件特性导致概念漂移,削弱模型有效性。本研究评估了两种数据集和九种机器学习及深度学习算法,以及大语言模型(LLMs)在概念漂移下的表现。考虑了静态、动态、混合、语义和图像等多种特征类型。结果表明,概念漂移普遍存在且严重影响模型性能,其影响因素包括特征类型、数据环境和检测方法。平衡算法缓解了类别不平衡,但未能有效应对概念漂移,主要源于恶意软件生态的动态性。算法类型与漂移无强关联,影响相对较小,因未微调超参数,仅使用默认配置。虽然使用少样本学习的大语言模型表现出良好检测能力,但未能完全缓解概念漂移,凸显进一步研究必要性。
原文摘要 · Abstract (English)
Despite outstanding results, machine learning-based Android malware detection models struggle with concept drift, where rapidly evolving malware characteristics degrade model effectiveness. This study examines the impact of concept drift on Android malware detection, evaluating two datasets and nine machine learning and deep learning algorithms, as well as Large Language Models (LLMs). Various feature types--static, dynamic, hybrid, semantic, and image-based--were considered. The results showed that concept drift is widespread and significantly affects model performance. Factors influencing the drift include feature types, data environments, and detection methods. Balancing algorithms helped with class imbalance but did not fully address concept drift, which primarily stems from the dynamic nature of the malware landscape. No strong link was found between the type of algorithm used and concept drift, the impact was relatively minor compared to other variables since hyperparameters were not fine-tuned, and the default algorithm configurations were used. While LLMs using few-shot learning demonstrated promising detection performance, they did not fully mitigate concept drift, highlighting the need for further investigation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。