arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

残差社区原型在FCG-MFD中对保留恶意软件家族的拒绝不足

Residual Community Prototypes Under-Reject Held-Out Malware Families in FCG-MFD

Junru Zhu, Yixin Yang, Xiaoqing Ding, Ruoyu Qi

arXiv 2609.24980首次发表:更新:

发表机构

University of Chicago(芝加哥大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究检验残差社区原型在FCG-MFD开放集恶意软件家族识别中的拒绝能力,发现其未能稳定拒绝保留家族,且性能劣于简单分类器不确定性,建议图开放集评估需结合拓扑控制与操作阈值。

AI 中文摘要

开放集恶意软件家族识别必须对已知家族进行分类,同时拒绝训练中未出现的家族。我们测试了Louvain社区摘要是否在图神经网络嵌入和维度匹配的通用拓扑之外增加了拒绝信息。该研究使用了去重、冲突审计的FCG-MFD语料库、五个保留家族和三个优化种子。在最近原型评分之前,使用已知家族训练数据对社区特征针对通用拓扑进行残差化处理。残差社区未产生稳定的保留家族拒绝效果。排名效应在不同家族间反转,在95%未知召回率下的假阳性率对每个保留家族均恶化,验证拟合的阈值仅拒绝4.48%的未知样本。已知接受的宏F1在每个家族中均提升,但五个独立家族单元的精确双侧符号翻转p值为0.0625,这是可达到的最小值。该分数仍与图规模相关,而简单分类器不确定性在排名、高召回拒绝和OSCR上表现更好。在此GIN/FCG-MFD设置中,社区增强原型改变了已知类几何结构,但未产生稳定的未知边界。图开放集评估应将结构特征与匹配的拓扑控制、操作阈值和保留家族分析相结合。

英文摘要

Open-set malware-family recognition must classify known families while rejecting families absent from training. We test whether Louvain-community summaries add rejection information beyond a graph neural network embedding and dimension-matched generic topology. The study uses a deduplicated, conflict-audited FCG-MFD corpus, five held-out families, and three optimization seeds. Community features are residualized against generic topology using known-family training data before nearest-prototype scoring. Residual community does not produce stable held-out-family rejection. Ranking effects reverse across families, the false-positive rate at 95 percent unknown recall worsens for every held-out family, and a validation-fitted threshold rejects only 4.48 percent of unknown samples. Accepted-known macro F1 improves in every family, but with five independent family units the exact two-sided sign-flip p-value is 0.0625, the smallest attainable value. The score remains associated with graph scale, while simple classifier uncertainty performs better on ranking, high-recall rejection, and OSCR. In this GIN/FCG-MFD setting, community-enriched prototypes change known-class geometry without creating a stable unknown margin. Graph open-set evaluations should pair structural features with matched topology controls, operational thresholds, and held-out-family analysis.

Comments6 pages, 1 figure, 4 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑