发表机构
University of Chicago(芝加哥大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究通过分区匹配对照实验,评估社区特征在Android恶意软件函数调用图分布偏移下的稳定性,发现其无显著优势,强调需严格对照验证介观图主张。
AI 中文摘要
基于图的Android恶意软件分类器在恶意软件类型或家族偏移下可能损失准确性。我们测试函数调用图中的介观组织是否在局部度分布(LDP)、全局统计、轻量级元数据以及大小匹配的随机分区之外,提供偏移稳定的信息。使用15,000个MalNet-Tiny、Common和Distinct图,六个在评估前指定的Leiden描述符,以及五个优化器种子,社区将Tiny的宏F1从78.7%提升至81.3%,但在Common上导致29.4个百分点的仅源域性能下降。一个大小匹配的随机分区导致27.8个百分点的下降。在五个随机分区中,平均下降为27.9个百分点;随机分区与社区下降之差的95%两层自助法区间为[-4.2, 1.2]个百分点。加入元数据后,相应差异为-0.2个百分点,区间为[-1.1, 0.6]。移除模块度将仅结构信息的Common宏F1从51.9%提升至53.6%。所测试的特征增加了独立同分布(IID)信号,但未显示出可重复的偏移稳定性优势,这证明了为何介观图主张需要分区匹配的对照和重复的零假设抽样。
英文摘要
Graph-based Android malware classifiers can lose accuracy under malware-type or family shifts. We test whether mesoscopic organization in function-call graphs provides shift-stable information beyond local degree profiles (LDP), global statistics, lightweight metadata, and size-matched random partitions. Using 15,000 MalNet-Tiny, Common, and Distinct graphs, six Leiden descriptors specified before evaluation, and five optimizer seeds, communities raise Tiny macro F1 from 78.7% to 81.3% but yield 29.4-point source-only Common degradation. One size-matched random partition yields 27.8-point degradation. Across five random partitions, mean degradation is 27.9 points; the 95% two-level bootstrap interval for random minus community degradation is [-4.2, 1.2] points. With metadata, the corresponding difference is -0.2 points with interval [-1.1, 0.6]. Removing modularity raises structure-only Common macro F1 from 51.9% to 53.6%. The tested signature adds IID signal but shows no repeatable shift-stability advantage, demonstrating why mesoscopic graph claims need partition-matched controls and repeated null draws.
Comments6 pages, 1 figure, 3 tables