Related Experiment Video
Updated: Sep 27, 2025

08:20
Author Spotlight: AI-Driven Trypanosome Species Detection from Microscopic Images
Published on: October 27, 2023
1.8K
Zero-Day Malware Detection and Effective Malware Analysis Using Shapley Ensemble Boosting and Bagging Approach.
Rajesh Kumar1, Geetha Subbiah1
1School of Computer Science and Engineering, Vellore Institute of Technology, Chennai Campus, Chennai 600127, Tamil Nadu, India.
Sensors (Basel, Switzerland)
|April 12, 2022
Summary
This study enhances machine learning (ML) models for malware detection by reducing misclassifications. Shapley values identify key features, enabling the creation of inductive rules to improve cybersecurity and detect zero-day malware.
Area of Science:
- Cybersecurity
- Machine Learning
- Software Vulnerability Analysis
Background:
- Software vulnerabilities are a significant security concern, frequently exploited by malware.
- Machine learning (ML) offers state-of-the-art capabilities for malware detection.
- Improving ML model accuracy by minimizing false negatives and false positives is crucial.
Purpose of the Study:
- To enhance the performance of bagging and boosting ML models in malware detection.
- To utilize Shapley values for feature contribution analysis and misclassification reduction.
- To develop effective inductive rules for improved cybersecurity by analyzing feature trends in misclassified instances.
Main Methods:
- Evaluated bagging and boosting ML models on three distinct malware datasets.
- Employed Shapley values to identify and analyze feature contributions for ML predictions.
- Transformed Shapley values to a probability scale for correlation with ML predictions.
- Generated inductive rules using waterfall plots based on feature probability scales.
Main Results:
- Determined the best-performing ML model (bagging or boosting) based on accuracy and confusion matrix analysis.
- Successfully identified top features contributing to ML model predictions using Shapley values.
- Demonstrated the utility of feature trends from misclassifications in creating inductive rules.
- Enhanced the detection of false-negative zero-day malware.
Conclusions:
- The proposed method effectively reduces misclassifications in ML-based malware detection.
- Shapley value analysis provides insights into feature importance for cybersecurity applications.
- Inductive rules derived from feature trends improve the identification of novel and evasive malware.
- This research contributes to more robust cybersecurity defenses against evolving threats.
Related Concept Videos
MALDI-TOF Mass Spectrometry
5.5K
Mass spectrometry is a powerful characterization technique that can identify and separate a wide variety of compounds ranging from chemical to biological entities, based on their mass-to-charge ratio (m/z). The instruments that allow this detection, known as mass spectrometers, have three components: an ion source, a mass analyzer, and a detector. These spectrometers differ based on the nature of their ion source and analyzers.
Matrix-assisted laser desorption ionization (MALDI) is a commonly...
Matrix-assisted laser desorption ionization (MALDI) is a commonly...
5.5K
Mass Analyzers: Overview
845
The mass analyzer is a crucial component of the mass spectrometer. In the ionization chamber, the vaporized sample is bombarded with a high-energy electron beam to generate a radical cation and further fragment into neutral molecules, radicals, and cations. A series of negatively charged accelerator plates accelerate the cations into the mass analyzer. The mass analyzer separates ions according to their mass-to-charge (m/z) ratios and then directs them to the detector. The common types of mass...
845
