Umm-E-Hani Tayyab, Faiza Babar Khan, Asifullah Khan, Muhammad Hanif Durad, Farrukh Aslam Khan, Aftab Ali
{"title":"ISAnWin:基于深度CNN的归纳广义零射击学习,用于跨windows和android平台的恶意软件检测。","authors":"Umm-E-Hani Tayyab, Faiza Babar Khan, Asifullah Khan, Muhammad Hanif Durad, Farrukh Aslam Khan, Aftab Ali","doi":"10.7717/peerj-cs.2604","DOIUrl":null,"url":null,"abstract":"<p><p>Effective malware detection is critical to safeguarding digital ecosystems from evolving cyber threats. However, the scarcity of labeled training data, particularly for cross-family malware detection, poses a significant challenge. This research proposes a novel architecture ConvNet-6 to be used in Siamese Neural Networks for applying Zero-shot learning to address the issue of data scarcity. The proposed model for malware detection uses the ConvNet-6 architecture even with limited training samples. The proposed model is trained with just one labeled sample per sub-family. We conduct extensive experiments on a diverse dataset featuring Android and Portable Executables' malware families. The model achieves high performance in terms of 82% accuracy on the test dataset, demonstrating its ability to generalize and effectively detect previously unseen malware variants. Furthermore, we examine the model's transferability by testing it on a portable executable malware dataset, despite being trained solely on the Android dataset. Encouragingly, the performance remains consistent. The results of our research showcase the potential of deep convolutional neural network (CNN) in Siamese neural networks for the application of zero-shot learning to detect cross-family malware, even when dealing with minimal labeled training data.</p>","PeriodicalId":54224,"journal":{"name":"PeerJ Computer Science","volume":"10 ","pages":"e2604"},"PeriodicalIF":2.5000,"publicationDate":"2024-12-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC11784898/pdf/","citationCount":"0","resultStr":"{\"title\":\"ISAnWin: inductive generalized zero-shot learning using deep CNN for malware detection across windows and android platforms.\",\"authors\":\"Umm-E-Hani Tayyab, Faiza Babar Khan, Asifullah Khan, Muhammad Hanif Durad, Farrukh Aslam Khan, Aftab Ali\",\"doi\":\"10.7717/peerj-cs.2604\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<p><p>Effective malware detection is critical to safeguarding digital ecosystems from evolving cyber threats. However, the scarcity of labeled training data, particularly for cross-family malware detection, poses a significant challenge. This research proposes a novel architecture ConvNet-6 to be used in Siamese Neural Networks for applying Zero-shot learning to address the issue of data scarcity. The proposed model for malware detection uses the ConvNet-6 architecture even with limited training samples. The proposed model is trained with just one labeled sample per sub-family. We conduct extensive experiments on a diverse dataset featuring Android and Portable Executables' malware families. The model achieves high performance in terms of 82% accuracy on the test dataset, demonstrating its ability to generalize and effectively detect previously unseen malware variants. Furthermore, we examine the model's transferability by testing it on a portable executable malware dataset, despite being trained solely on the Android dataset. Encouragingly, the performance remains consistent. The results of our research showcase the potential of deep convolutional neural network (CNN) in Siamese neural networks for the application of zero-shot learning to detect cross-family malware, even when dealing with minimal labeled training data.</p>\",\"PeriodicalId\":54224,\"journal\":{\"name\":\"PeerJ Computer Science\",\"volume\":\"10 \",\"pages\":\"e2604\"},\"PeriodicalIF\":2.5000,\"publicationDate\":\"2024-12-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://www.ncbi.nlm.nih.gov/pmc/articles/PMC11784898/pdf/\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"PeerJ Computer Science\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://doi.org/10.7717/peerj-cs.2604\",\"RegionNum\":4,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"2024/1/1 0:00:00\",\"PubModel\":\"eCollection\",\"JCR\":\"Q2\",\"JCRName\":\"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"PeerJ Computer Science","FirstCategoryId":"94","ListUrlMain":"https://doi.org/10.7717/peerj-cs.2604","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"2024/1/1 0:00:00","PubModel":"eCollection","JCR":"Q2","JCRName":"COMPUTER SCIENCE, ARTIFICIAL INTELLIGENCE","Score":null,"Total":0}
ISAnWin: inductive generalized zero-shot learning using deep CNN for malware detection across windows and android platforms.
Effective malware detection is critical to safeguarding digital ecosystems from evolving cyber threats. However, the scarcity of labeled training data, particularly for cross-family malware detection, poses a significant challenge. This research proposes a novel architecture ConvNet-6 to be used in Siamese Neural Networks for applying Zero-shot learning to address the issue of data scarcity. The proposed model for malware detection uses the ConvNet-6 architecture even with limited training samples. The proposed model is trained with just one labeled sample per sub-family. We conduct extensive experiments on a diverse dataset featuring Android and Portable Executables' malware families. The model achieves high performance in terms of 82% accuracy on the test dataset, demonstrating its ability to generalize and effectively detect previously unseen malware variants. Furthermore, we examine the model's transferability by testing it on a portable executable malware dataset, despite being trained solely on the Android dataset. Encouragingly, the performance remains consistent. The results of our research showcase the potential of deep convolutional neural network (CNN) in Siamese neural networks for the application of zero-shot learning to detect cross-family malware, even when dealing with minimal labeled training data.
期刊介绍:
PeerJ Computer Science is the new open access journal covering all subject areas in computer science, with the backing of a prestigious advisory board and more than 300 academic editors.