Bài viết
AnLibsXAI: Phân loại phần mềm độc hại trên Android bằng danh sách thư viện và trí tuệ nhân tạo có thể giải thích được bằng SHAP
- Nguyễn Tấn Cầm · University of Information Technology, Ho Chi Minh City, Vietnam. Vietnam National University, Ho Chi Minh City, Vietnam (VN)
Tóm tắt
Trong nghiên cứu này, tác giả sử dụng các loại đặc trưng gồm danh sách thư viện, danh sách quyền hạn, lời gọi hàm hệ thống để xây dựng hệ thống phân loại mã độc Android có tên là AnLibsXAI. Tác giả đã thử sử dụng các mô hình học máy phổ biến như Support Vector Machine, Random Forest, Decision Tree, Logistic Regression, K-Nearest Neighbors và Multilayer Perceptron. Bên cạnh đó, nghiên cứu này cũng áp dụng các nền tảng trí tuệ nhân tạo có thể giải thích được để đánh giá tầm quan trọng cũng như ảnh hưởng của các đặc trưng trong các mô hình phân loại mã độc Android. Kết quả thử nghiệm khi sử dụng bộ dữ liệu thử nghiệm CICMalDroid 2020 cho thấy SVM có độ chính xác cao nhất, đạt 96%. Kết quả nghiên cứu này có ích trong việc sử dụng để hỗ trợ các nghiên cứu liên quan đến phân loại mã độc Android trong tương lai
Lượt tải theo tháng
Di chuột vào cột để xem số lượt tải.
Cách trích dẫn
Nguyễn Tấn Cầm (2024). AnLibsXAI: Phân loại phần mềm độc hại trên Android bằng danh sách thư viện và trí tuệ nhân tạo có thể giải thích được bằng SHAP. Tạp chí Khoa học và Công nghệ trong lĩnh vực An toàn thông tin, 2(22), 5-16. https://doi.org/10.54654/isj.v2i22.1018
Tài liệu tham khảo
- 1.B. Wang, W. Pei, B. Xue, and M. Zhang, "A multi-objective genetic algorithm to evolving local interpretable model-agnostic explanations for deep neural networks in image classification," IEEE Transactions on Evolutionary Computation, 2022.
- 2.S. Lundberg. (2023, October, 10). SHapley Additive exPlanations. Available: https://shap.readthedocs.io/en/latest/
- 3.D. Macha, M. Kozielski, Ł. Wróbel, and M. Sikora, "RuleXAI—A package for rule-based explanations of machine learning model," SoftwareX, vol. 20, p. 101209, 2022.
- 4.Toan, N. N. ., Dung, L. T., & Thang, D. Q. (2022). Static Feature Selection for IoT Malware Detection. Journal of Science and Technology on Information Security, 1(15), 74-84. https://doi.org/10.54654/isj.v1i15.844
- 5.R. Vinayakumar, K. Soman, and P. Poornachandran, "Deep android malware detection and classification," in 2017 International conference on advances in computing, communications and informatics (ICACCI), 2017, pp. 1677-1683: IEEE.
- 6.D. Ö. Şahın, S. Akleylek, and E. Kiliç, "LinRegDroid: Detection of Android malware using multiple linear regression models-based classifiers," IEEE Access, vol. 10, pp. 14246-14259, 2022.
- 7.G. D’Angelo, F. Palmieri, and A. Robustelli, "A federated approach to Android malware classification through Perm-Maps," Cluster Computing, vol. 25, no. 4, pp. 2487-2500, 2022.
- 8.X. Zhang et al., "An early detection of android malware using system calls based machine learning model," in Proceedings of the 17th International Conference on Availability, Reliability and Security, 2022, pp. 1-9.
- 9.K. Vinayaka and C. Jaidhar, "Android malware detection using function call graph with graph convolutional networks," in 2021 2nd International Conference on Secure Cyber Computing and Communications (ICSCCC), 2021, pp. 279-287: IEEE.
- 10.Y. Wu, J. Shi, P. Wang, D. Zeng, and C. Sun, "DeepCatra: Learning flow‐and graph‐based behaviours for Android malware detection," IET Information Security, vol. 17, no. 1, pp. 118-130, 2023.
- 11.J. Kim, Y. Ban, E. Ko, H. Cho, and J. H. Yi, "MAPAS: a practical deep learning-based android malware detection system," International Journal of Information Security, vol. 21, no. 4, pp. 725-738, 2022.
- 12.S. R. T. Mat, M. F. Ab Razak, M. N. M. Kahar, J. M. Arif, and A. Firdaus, "A Bayesian probability model for Android malware detection," ICT Express, vol. 8, no. 3, pp. 424-431, 2022.
- 13.S. Mahdavifar, D. Alhadidi, and A. A. Ghorbani, "Effective and efficient hybrid android malware classification using pseudo-label stacked auto-encoder," Journal of network and systems management, vol. 30, pp. 1-34, 2022.
- 14.Y. Ding, X. Zhang, J. Hu, and W. Xu, "Android malware detection method based on bytecode image," Journal of Ambient Intelligence and Humanized Computing, vol. 14, no. 5, pp. 6401-6410, 2023.
- 15.K. Allix, T. F. Bissyandé, J. Klein, and Y. Le Traon, "Androzoo: Collecting millions of android apps for the research community," in Mining Software Repositories (MSR), 2016 IEEE/ACM 13th Working Conference on, 2016, pp. 468-471: IEEE.
- 16.D. Arp, M. Spreitzenbarth, M. Hübner, H. Gascon, and K. Rieck, "Drebin: Effective and Explainable Detection of Android Malware in Your Pocket," 2014.
- 17.M. Kinkead, S. Millar, N. McLaughlin, and P. O’Kane, "Towards explainable CNNs for Android malware detection," Procedia Computer Science, vol. 184, pp. 959-965, 2021.
- 18.A. Galli, V. La Gatta, V. Moscato, M. Postiglione, and G. Sperlì, "Explainability in AI-based behavioral malware detection systems," Computers & Security, vol. 141, p. 103842, 2024.
- 19.A. Martín, R. Lara-Cabrera, and D. Camacho, "A new tool for static and dynamic Android malware analysis," in Data Science and Knowledge Engineering for Sensing Decision Support: Proceedings of the 13th International FLINS Conference (FLINS 2018), 2018, pp. 509-516: World Scientific.
- 20.D. Boxler and K. R. Walcott, "Static Taint Analysis Tools to Detect Information Flows," in Proceedings of the International Conference on Software Engineering Research and Practice (SERP), 2018, pp. 46-52: The Steering Committee of The World Congress in Computer Science, Computer ….
- 21.C. Molnar, "Interpretable Machine Learning: A Guide for Making Black Box Models Explainable.", 2020, [Online]. Available: https://christophm.github.io/interpretable-ml-book/. [Accessed: Dec. 10, 2023].