A Malware Detection and Extraction Method for the Related Information Using the ViT Attention Mechanism on Android Operating System

被引:11
作者
Jo, Jeonggeun [1 ]
Cho, Jaeik [2 ]
Moon, Jongsub [1 ]
机构
[1] Korea Univ, Dept Informat Secur, Seoul 02841, South Korea
[2] Lewis Univ, Dept Comp Sci, Romeoville, IL 60446 USA
来源
APPLIED SCIENCES-BASEL | 2023年 / 13卷 / 11期
关键词
explainable artificial intelligence (XAI); deep learning; cybersecurity; mobile malware; malware detection; visualization;
D O I
10.3390/app13116839
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Artificial intelligence (AI) is increasingly being utilized in cybersecurity, particularly for detecting malicious applications. However, the black-box nature of AI models presents a significant challenge. This lack of transparency makes it difficult to understand and trust the results. In order to address this, it is necessary to incorporate explainability into the detection model. There is insufficient research to provide reasons why applications are detected as malicious or explain their behavior. In this paper, we propose a method of a Vision Transformer(ViT)-based malware detection model and malicious behavior extraction using an attention map to achieve high detection accuracy and high interpretability. Malware detection uses a ViT-based model, which takes an image as input. ViT offers a significant advantage for image detection tasks by leveraging attention mechanisms, enabling robust interpretation and understanding of the intricate patterns within the images. The image is converted from an application. An attention map is generated with attention values generated during the detection process. The attention map is used to identify factors that the model deems important. Class and method names are extracted and provided based on the identified factors. The performance of the detection was validated using real-world datasets. The malware detection accuracy was 80.27%, which is a high level of accuracy compared to other models used for image-based malware detection. The interpretability was measured in the same way as the F1-score, resulting in an interpretability score of 0.70. This score is superior to existing interpretable machine learning (ML)-based methods, such as Drebin, LIME, and XMal. By analyzing malicious applications, we also confirmed that the extracted classes and methods are related to malicious behavior. With the proposed method, security experts can understand the reason behind the model's detection and the behavior of malicious applications. Given the growing importance of explainable artificial intelligence in cybersecurity, this method is expected to make a significant contribution to this field.
引用
收藏
页数:22
相关论文
共 45 条
[1]  
Abnar S, 2020, 58TH ANNUAL MEETING OF THE ASSOCIATION FOR COMPUTATIONAL LINGUISTICS (ACL 2020), P4190
[2]  
Allix K, 2016, 13TH WORKING CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR 2016), P468, DOI [10.1109/MSR.2016.056, 10.1145/2901739.2903508]
[3]   An Automated Vision-Based Deep Learning Model for Efficient Detection of Android Malware Attacks [J].
Almomani, Iman ;
Alkhayer, Aala ;
El-Shafai, Walid .
IEEE ACCESS, 2022, 10 :2700-2720
[4]   A Review on Android Ransomware Detection Using Deep Learning Techniques [J].
Alzahrani, Nisreen ;
Alghazzawi, Daniyal .
11TH INTERNATIONAL CONFERENCE ON MANAGEMENT OF DIGITAL ECOSYSTEMS (MEDES), 2019, :330-335
[5]  
Apktool, About us
[6]   Drebin: Effective and Explainable Detection of Android Malware in Your Pocket [J].
Arp, Daniel ;
Spreitzenbarth, Michael ;
Huebner, Malte ;
Gascon, Hugo ;
Rieck, Konrad .
21ST ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2014), 2014,
[7]  
Arras L, 2021, Arxiv, DOI arXiv:2003.07258
[8]  
Ba JL, 2016, arXiv
[9]   Transformer Interpretability Beyond Attention Visualization [J].
Chefer, Hila ;
Gur, Shir ;
Wolf, Lior .
2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, :782-791
[10]   DEXRAY: A Simple, yet Effective Deep Learning Approach to Android Malware Detection Based on Image Representation of Bytecode [J].
Daoudi, Nadia ;
Samhi, Jordan ;
Kabore, Abdoul Kader ;
Allix, Kevin ;
Bissyande, Tegawende F. ;
Klein, Jacques .
DEPLOYABLE MACHINE LEARNING FOR SECURITY DEFENSE, MLHAT 2021, 2021, 1482 :81-106