节点文献

基于随机平滑的恶意软件识别深度学习模型鲁棒性认证方法

Certified Robustness of Malware Deep Learning Identification Model Based on Random Smoothing

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 罗森林鲁帅张毅飞潘丽敏

【Author】 LUO Senlin;LU Shuai;ZHANG Yifei;PAN Limin;School of Information and Electronics, Beijing Institute of Technology;

【通讯作者】 潘丽敏;

【机构】 北京理工大学信息与电子学院

【摘要】 面向恶意软件识别的任务中,使用随机平滑算法向所有特征中添加噪声得到的噪声样本可能会失去恶意功能.现有的认证算法按照噪声空间分布的似然比从大到小的顺序构建认证区域,使认证的鲁棒区域小、认证准确率低.本文提出一种基于随机平滑的恶意软件识别深度学习模型的鲁棒性认证方法,方法只向与恶意功能非必需的特征中添加离散伯努利噪声构建可认证的平滑模型,选取似然比更小的区域构建认证区域,实现更准确的鲁棒性认证.实验表明,提出的方法在3个数据集上平均认证半径是对比方法的4.37倍、2.67倍和2.72倍。该方法可以提供与实际鲁棒边界更紧密的认证半径,在模型鲁棒性评估方面具有较强的实用价值.

【Abstract】 Robustness,the ability to resist uncertain disturbances, is an important index of machine learning model. The certified method based on random smoothing can certify the robustness of large and complex models. In the task of malware identification, the noise samples obtained by adding noise to all features using random smoothing algorithm may lose the malicious function. The existing certification algorithms construct the certified region according to the likelihood ratio of noise spatial distribution from large to small, causing the certified robust region small and the certified accuracy not good. So, a robust certification method was proposed based on random smoothing for malware recognition deep learning model. The method was arranged to add discrete Bernoulli noise only to the unnecessary features of malicious functions to construct a certifiable smoothing model, and to select the region with smaller likelihood ratio to construct a certified region to achieve more accurate certified robustness. Experiment results show that the average certified radius of the proposed method on three data sets is 4.37 times, 2.67 times and 2.72 times that of the comparison method. This method can provide the certified radius closer to the actual robust boundary, possessing a strong practical value in the evaluation of model robustness.

【关键词】 鲁棒性认证随机平滑恶意软件
【Key words】 certified robustnessrandom smoothingmalware
【基金】 工信部2020年信息安全软件项目(CEIEC-2020-ZM02-0134)
  • 【文献出处】 北京理工大学学报 ,Transactions of Beijing Institute of Technology , 编辑部邮箱 ,2023年02期
  • 【分类号】TP311.5;TP309
  • 【下载频次】28
节点文献中: 

本文链接的文献网络图示:

本文的引文网络