Self-Supervised Vision Transformers for Malware Detection

Self-Supervised Vision Transformers for Malware Detection
复制标题

DOI:
10.1109/access.2022.3206445
复制
发表时间:
2022-08
期刊:
影响因子:
3.9
通讯作者:
Sachith Seneviratne;Ridwan Shariffdeen;Sanka Rasnayaka;Nuran Kasthuriarachchi
Sachith Seneviratne;Ridwan Shariffdeen;Sanka Rasnayaka;Nuran Kasthuriarachchi
中科院分区:
计算机科学3区
文献类型:
--
作者:
Sachith Seneviratne;Ridwan Shariffdeen;Sanka Rasnayaka;Nuran Kasthuriarachchi

文献摘要

被引文献

相似文献

随着恶意软件的增长和网络攻击的发展,恶意软件检测在网络安全中起着至关重要的作用。这些攻击中经常使用以前未见过的恶意软件,这些恶意软件不是由安全供应商确定的,因此找到一种可以从未标记的样本数据中自我学习的解决方案变得不可避免。提出了基于视觉变换(Vision Transformer, ViT)架构的基于自监督的深度学习模型SHERLOCK。SHERLOCK是一种新的恶意软件检测方法,它利用基于图像的二进制表示学习独特的特征来区分恶意软件和良性程序。实验结果表明,在47种类型和696个家族的120万个Android应用程序中,自监督学习可以实现97%的恶意软件二进制分类准确率,高于现有的最先进技术。我们提出的模型也能够优于最先进的多类恶意软件类型和家族分类技术,其宏观f1分数为。497年,。分别为491。
Malware detection plays a crucial role in cyber-security with the increase in malware growth and advancements in cyber-attacks. Previously unseen malware which is not determined by security vendors are often used in these attacks and it is becoming inevitable to find a solution that can self-learn from unlabeled sample data. This paper presents SHERLOCK, a self-supervision based deep learning model to detect malware based on the Vision Transformer (ViT) architecture. SHERLOCK is a novel malware detection method which learns unique features to differentiate malware from benign programs with the use of image-based binary representation. Experimental results using 1.2 million Android applications across a hierarchy of 47 types and 696 families, shows that self-supervised learning can achieve an accuracy of 97% for the binary classification of malware which is higher than existing state-of-the-art techniques. Our proposed model is also able to outperform state-of-the-art techniques for multi-class malware classification of types and family with macro-F1 score of.497 and.491 respectively.