CFGExplainer: Explaining Graph Neural Network-Based Malware Classification from Control Flow Graphs

CFGExplainer: Explaining Graph Neural Network-Based Malware Classification from Control Flow Graphs
复制标题

DOI:
10.1109/dsn53405.2022.00028
复制
发表时间:
2022-06
期刊:
2022 52nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks (DSN)
影响因子:
--
通讯作者:
J. D. Herath;Priti Wakodikar;Pin Yang;Guanhua Yan
J. D. Herath;Priti Wakodikar;Pin Yang;Guanhua Yan
中科院分区:
其他
文献类型:
--
作者:
J. D. Herath;Priti Wakodikar;Pin Yang;Guanhua Yan

文献摘要

被引文献

相似文献

With the ever increasing threat of malware, extensive research effort has been put on applying Deep Learning for malware classification tasks. Graph Neural Networks (GNNs) that process malware as Control Flow Graphs (CFGs) have shown great promise for malware classification. However, these models are viewed as black-boxes, which makes it hard to validate and identify malicious patterns. To that end, we propose CFG-Explainer, a deep learning based model for interpreting GNN-oriented malware classification results. CFGExplainer identifies a subgraph of the malware CFG that contributes most towards classification and provides insight into importance of the nodes (i.e., basic blocks) within it. To the best of our knowledge, CFGExplainer is the first work that explains GNN-based mal-ware classification. We compared CFGExplainer against three explainers, namely GNNExplainer, SubgraphX and PGExplainer, and showed that CFGExplainer is able to identify top equisized subgraphs with higher classification accuracy than the other three models.