arXiv ScienceSearch

arXiv subjects

Peter Anthony

Publications and source records attributed to Peter Anthony.

3 recordsLinked to original sources

Explainable Malware Detection with Tailored Logic Explained Networks

Malware detection is a constant challenge in cybersecurity due to the rapid development of new attack techniques. Traditional signature-based approaches struggle to keep pace with the sheer volume of malware samples. Machine learning offers a promising solution, but faces issues of generalization to unseen samples and a lack of explanation for the instances identified as malware. However, human-understandable explanations are especially important in security-critical fields, where understanding model decisions is crucial for trust and legal compliance. While deep learning models excel at malware detection, their black-box nature hinders explainability. Conversely, interpretable models often fall short in performance. To bridge this gap in this application domain, we propose the use of Logic Explained Networks (LENs), which are a recently proposed class of interpretable neural networks providing explanations in the form of First-Order Logic (FOL) rules. This paper extends the application of LENs to the complex domain of malware detection, specifically using the large-scale EMBER dataset. In the experimental results we show that LENs achieve robustness that exceeds traditional interpretable methods and that are rivaling black-box models. Moreover, we introduce a tailored version of LENs that is shown to generate logic explanations with higher fidelity with respect to the model's predictions.

cs.CR

Semantic Data Representation for Explainable Windows Malware Detection Models

Ontologies are a standard tool for creating semantic schemata in many knowledge intensive domains of human interest. They are becoming increasingly important also in the areas that have been until very recently dominated by subsymbolic knowledge representation and machine-learning (ML) based data processing. One such area is information security, and specifically, malware detection. We thus propose PE Malware Ontology that offers a reusable semantic schema for Portable Executable (PE - the Windows binary format) malware files. This ontology is inspired by the structure of the EMBER dataset, which focuses on the static malware analysis of PE files. With this proposal, we hope to provide a unified semantic representation for the existing and future PE-malware datasets and facilitate the application of symbolic, neuro-symbolic, or otherwise explainable approaches in the PE-malware-detection domain, which may produce interpretable results described by the terms defined in our ontology. In addition, we also publish semantically treated EMBER data, including fractional datasets, to support the reproducibility of experiments on EMBER. We supplement our work with a preliminary case study, conducted using concept learning, to show the general feasibility of our approach. While we were not able to match the precision of the state-of-the-art ML tools, the learned malware discriminators were interesting and highly interpretable.

cs.CR

Infinite-energy solutions for the Navier-Stokes equations in a strip revisited

The paper deals with the Navier-Stokes equations in a strip in the class of spatially non-decaing (infinite-energy) solutions belonging to the properly chosen uniformly local Sobolev spaces. The global well-posedness and dissipativity of the Navier-Stokes equations in a strip in such spaces has been first established in [S. Zelik, "Spatially nondecaying solutions of the 2D Navier-Stokes equation in a strip". Glasg. Math. J., 49 (2007), no. 3, 525--588]. However, the proof given there contains rather essential error and the aim of the present paper is to correct this error and to show that the main results of that paper remain true.

math.AP