发表机构
University of Maryland Baltimore County; CrowdStrike(马里兰大学巴尔的摩县分校; CrowdStrike)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究指出SHAP因依赖冗余特征、流形外联盟等问题,无法作为恶意软件检测的独立解释框架,仅为需明确数据分布和领域验证的有限诊断工具,实验在多数据集和检测器上验证了其缺陷。
AI 中文摘要
机器学习被广泛应用于恶意软件检测,但它的决策必须得到解释。分析人员需要知道模型是学习到了真正的恶意行为,还是仅学习到了数据集特有的模式[gaur2021semantics]。SHapley加性解释(SHAP)是这一领域的标准工具,具备局部准确性、缺失性和一致性等形式属性。我们认为这些保证对于可靠的恶意软件解释而言是不够的。我们提出,SHAP解释的是所选的特征联盟博弈,而非数据中的恶意软件行为;该博弈仅在分析人员选定特征参与者、缺失特征规则、背景分布和简化输入映射后才被确定。在静态可移植执行体(PE)特征空间中,字节直方图、字节熵、字符串、头信息、节、导入和数据目录等组并非独立信号,而是由文件结构、打包、编译器行为和家族约定共同塑造的。我们证明,这种依赖关系会使条件SHAP在m-1个冗余特征间将模型的特征贡献稀释1/m倍,将模型从未使用的特征赋予重要性,甚至在数据分布变化时反转未使用特征贡献的符号;同时,干预型SHAP会查询真实可执行文件不会出现的流形外联盟。在EMBER-2018、EMBER-2024和BODMAS数据集上使用固定的LightGBM和XGBoost检测器开展的实验证实了这些效应。因此,我们认为SHAP是一种有限的诊断工具,需要明确指定数据分布和领域验证,而非作为恶意软件行为的独立说明。
英文摘要
Machine learning is widely used for malware detection, but its decisions must be explained. An analyst needs to know whether a model has learned genuine malicious behavior or only dataset-specific patterns \cite{gaur2021semantics}. SHapley Additive exPlanations (SHAP) is the standard tool for this, backed by formal properties such as local accuracy, missingness, and consistency. We argue that these guarantees are insufficient for reliable malware interpretation. We claim SHAP explains a chosen feature-coalition game, not malware behavior in the data. That game is fixed only after the analyst selects the feature players, the missing feature rule, the background distribution, and the simplified input mapping. In static Portable Executable feature spaces, groups such as byte histograms, byte-entropy, strings, headers, sections, imports, and data-directories are not independent signals but are jointly shaped by file structure, packing, compiler behavior, and family conventions. We prove that this dependence makes conditional SHAP dilute a model's feature credit by a factor of $1/m$ across $m-1$ redundant features, attributes importance to features the model never uses, and even reverses the sign of an unused feature's attribution when the data distribution changes; interventional SHAP, meanwhile, queries off-manifold coalitions that no real executable would exhibit. Experiments on EMBER-2018, EMBER-2024, and BODMAS with fixed LightGBM and XGBoost detectors confirm these effects. We therefore position SHAP as a limited diagnostic that requires an explicitly stated data distribution and domain validation, not a standalone account of malware behavior.