Interpreting Machine Learning Malware Detectors Which Leverage N-gram Analysis

In cyberattack detection and prevention systems, cybersecurity analysts\nalways prefer solutions that are as interpretable and understandable as\nrule-based or signature-based detection. This is because of the need to tune\nand optimize these solutions to mitigate and control the effect of false\npositives and false negatives. Interpreting machine learning models is a new\nand open challenge. However, it is expected that an interpretable machine\nlearning solution will be domain-specific. For instance, interpretable\nsolutions for machine learning models in healthcare are different than\nsolutions in malware detection. This is because the models are complex, and\nmost of them work as a black-box. Recently, the increased ability for malware\nauthors to bypass antimalware systems has forced security specialists to look\nto machine learning for creating robust detection systems. If these systems are\nto be relied on in the industry, then, among other challenges, they must also\nexplain their predictions. The objective of this paper is to evaluate the\ncurrent state-of-the-art ML models interpretability techniques when applied to\nML-based malware detectors. We demonstrate interpretability techniques in\npractice and evaluate the effectiveness of existing interpretability techniques\nin the malware analysis domain.\n

Paper

References (21)

Scroll for more · 9 remaining

Similar papers

© 2026 NYSGPT2525 LLC