Can We Trust Your Explanations? Sanity Checks for Interpreters in Android Malware Analysis

Can We Trust Your Explanations? Sanity Checks for Interpreters in Android Malware Analysis
复制标题

我们可以相信你的解释吗?

DOI:
10.1109/tifs.2020.3021924
复制
发表时间:
2020
影响因子:
6.8
通讯作者:
Ting Liu
Ting Liu
中科院分区:
计算机科学1区
文献类型:
--
作者:
Ming Fan;Wenying Wei;Xiaofei Xie;Yang Liu;Xiaohong Guan;Ting Liu

文献摘要

相似文献

随着Android恶意软件的快速增长,许多基于机器学习的恶意软件分析方法被提出来缓解这一严重现象。然而,这样的分类器是不透明的,非直观的,很难理解的内部决策原因的分析。出于这个原因,提出了各种解释方法来解释预测提供重要的功能。不幸的是,在恶意软件分析领域中获得的解释结果通常不能达成共识,这使得分析人员对于他们是否可以信任这样的结果感到困惑。在这项工作中,我们提出了原则性的指导方针,通过设计三个关键的定量指标来衡量其稳定性,鲁棒性和有效性,以评估五种解释方法的质量。此外,我们收集了五个广泛使用的恶意软件数据集,并将解释方法应用于两个任务,包括恶意软件检测和家族识别。基于生成的解释结果,我们进行了合理性检查的解释方法的三个指标。结果表明,我们的指标可以评估的解释方法,并帮助我们获得最典型的恶意软件分析的恶意行为的知识。
With the rapid growth of Android malware, many machine learning-based malware analysis approaches are proposed to mitigate the severe phenomenon. However, such classifiers are opaque, non-intuitive, and difficult for analysts to understand the inner decision reason. For this reason, a variety of explanation approaches are proposed to interpret predictions by providing important features. Unfortunately, the explanation results obtained in the malware analysis domain cannot achieve a consensus in general, which makes the analysts confused about whether they can trust such results. In this work, we propose principled guidelines to assess the quality of five explanation approaches by designing three critical quantitative metrics to measure their stability, robustness, and effectiveness. Furthermore, we collect five widely-used malware datasets and apply the explanation approaches on them in two tasks, including malware detection and familial identification. Based on the generated explanation results, we conduct a sanity check of such explanation approaches in terms of the three metrics. The results demonstrate that our metrics can assess the explanation approaches and help us obtain the knowledge of most typical malicious behaviors for malware analysis.