From Data and Model Levels: Improve the Performance of Few-Shot Malware Classification

被引:17
作者
Chai, Yuhan [1 ]
Qiu, Jing [1 ]
Yin, Lihua [1 ]
Zhang, Lejun [1 ]
Gupta, Brij B. [2 ,3 ,4 ,5 ,6 ]
Tian, Zhihong [1 ]
机构
[1] Guangzhou Univ, Cyberspace Inst Adv Technol, Guangzhou 510006, Peoples R China
[2] Asia Univ, Int Ctr AI & Cyber Secur Res & Innovat, Taichung 413, Taiwan
[3] Asia Univ, Dept Comp Sci & Informat Engn, Taichung 413, Taiwan
[4] Lebanese Amer Univ, Dept Comp Sci, Beirut 1102, Lebanon
[5] Univ Petr & Energy Studies, Ctr Interdisciplinary Res, Dehra Dun 248007, India
[6] King Abdulaziz Univ, Dept Comp Sci, Jeddah 21589, Saudi Arabia
来源
IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT | 2022年 / 19卷 / 04期
基金
中国国家自然科学基金;
关键词
Malware; Data visualization; Data models; Gray-scale; Analytical models; Adaptation models; Training; Cyber-security; few-shot malware classification; malware visualization; flat minima; NETWORK; FRAMEWORK; ENTROPY; SERVICE;
D O I
10.1109/TNSM.2022.3200866
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Existing malware classification methods cannot handle the open-ended growth of new or unknown malware well because it only focuses on pre-defined malware classes with sufficient training data. Due to the superiority of the visualization method, some researchers use it for solving few-shot malware classification. However, the malware images generated by existing visualization methods contain insufficient semantic information. At the same time, existing few-shot models tend to converge to sharp minima resulting in poor generalization performance. By synthesizing the observations, we think that accurate and effective few-shot malware classification methods are affected by generated malware images and classification models, which can be called data and model levels, respectively. To solve the above problems, we propose a novel method from the Data and Model levels, which is used to classify new or unknown malware well, called DMMal. More specifically, we propose a multi-channel malware image generation method based on multi-view so that malware images can contain more prosperous information at the data level. In addition, we investigated adaptive sharpness-aware minimization in a few-shot scenario from the perspective of model optimization at the model level to minimize the loss value and sharpness simultaneously. This enhances the generalization ability of the model and improves the ability of the model to classify new or unknown classes. Experiments on two few-shot malware classification datasets show that the method proposed can improve the performance of few-shot malware classification from the data and model levels.
引用
收藏
页码:4248 / 4261
页数:14
相关论文
共 50 条
  • [11] Few-Shot Classification Model Compression via School Learning
    Yang, Sai
    Liu, Fan
    Chen, Delong
    Huang, Huaxi
    Zhou, Jun
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2024, 34 (12) : 12244 - 12257
  • [12] Personalized Multiparty Few-Shot Learning for Remote Sensing Scene Classification
    Wang, Shanfeng
    Li, Jianzhao
    Liu, Zaitian
    Gong, Maoguo
    Zhang, Yourun
    Zhao, Yue
    Deng, Boya
    Zhou, Yu
    IEEE TRANSACTIONS ON GEOSCIENCE AND REMOTE SENSING, 2024, 62 : 1 - 15
  • [13] Dynamic Prototype Network Based on Sample Adaptation for Few-Shot Malware Detection
    Chai, Yuhan
    Du, Lei
    Qiu, Jing
    Yin, Lihua
    Tian, Zhihong
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2023, 35 (05) : 4754 - 4766
  • [14] Attention Multisource Fusion-Based Deep Few-Shot Learning for Hyperspectral Image Classification
    Liang, Xuejian
    Zhang, Ye
    Zhang, Junping
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2021, 14 : 8773 - 8788
  • [15] Few-Shot Specific Emitter Identification: A Knowledge, Data, and Model-Driven Fusion Framework
    Sun, Minhong
    Teng, Jiazhong
    Liu, Xinyuan
    Wang, Wei
    Huang, Xingru
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 3247 - 3259
  • [16] Learning Noisy Few-Shot Classification Without Relying on Pseudo-Noise Data
    Wu, Yixin
    Xue, Hui
    An, Yuexuan
    Fang, Pengfei
    IEEE SIGNAL PROCESSING LETTERS, 2025, 32 : 86 - 90
  • [17] Calibration of Few-Shot Classification Tasks: Mitigating Misconfidence From Distribution Mismatch
    Kim, Sungnyun
    Yun, Se-Young
    IEEE ACCESS, 2022, 10 : 53894 - 53908
  • [18] Few-Shot Classification With Feature Reconstruction Bias
    Li, Zhen
    Wang, Lang
    Ding, Shuo
    Yang, Xiaochen
    Li, Xiaoxu
    PROCEEDINGS OF 2022 ASIA-PACIFIC SIGNAL AND INFORMATION PROCESSING ASSOCIATION ANNUAL SUMMIT AND CONFERENCE (APSIPA ASC), 2022, : 526 - 532
  • [19] Few-Shot Learning Meets Transformer: Unified Query-Support Transformers for Few-Shot Classification
    Wang, Xixi
    Wang, Xiao
    Jiang, Bo
    Luo, Bin
    IEEE TRANSACTIONS ON CIRCUITS AND SYSTEMS FOR VIDEO TECHNOLOGY, 2023, 33 (12) : 7789 - 7802
  • [20] Data Augmentation and Few-Shot Change Detection in Forest Remote Sensing
    Zhu, Songyu
    Jing, Weipeng
    Kang, Peilun
    Emam, Mahmoud
    Li, Chao
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2023, 16 : 5919 - 5934