Selecting Representative Samples from Malware Datasets
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F68407700%3A21240%2F25%3A00385461" target="_blank" >RIV/68407700:21240/25:00385461 - isvavai.cz</a>
Result on the web
<a href="https://doi.org/10.1007/978-3-031-83157-7_5" target="_blank" >https://doi.org/10.1007/978-3-031-83157-7_5</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1007/978-3-031-83157-7_5" target="_blank" >10.1007/978-3-031-83157-7_5</a>
Alternative languages
Result language
angličtina
Original language name
Selecting Representative Samples from Malware Datasets
Original language description
This work focuses on the selection of representative instances for the training set in malware detection. Opposed to random instance selection, the goal of instance selection algorithms is to remove noise and redundancy while preserving relevant data for solving the task. Experiments were conducted on two publicly available datasets containing metadata of Windows PE files, namely the EMBER and SOREL-20M datasets. The theoretical part describes data preprocessing methods, instance selection algorithms, and classification algorithms used in the practical part of this work. The practical part outlines the process of preprocessing datasets and main experiments related to the comparison of state-of-the-art instance selection algorithms. As part of the work, modifications to the parallel instance selection algorithm PIF were proposed and implemented, and these were also experimentally evaluated and compared with the results of state-of-the-art instance selection algorithms. Some of the modified versions ranked among the best in terms of reduction level as well as the ratio between accuracy and the size of the reduced sets. The best among the modified versions was the RPIF-AllKNN algorithm, which reduced the entire training set of the SOREL-20M dataset to 6.24% of its original size with an accuracy loss of 2.1%. The ratio between accuracy and the size of the reduced set was 14.43 and in terms of this metric, RPIF-AllKNN was the best among the compared algorithms.
Czech name
—
Czech description
—
Classification
Type
C - Chapter in a specialist book
CEP classification
—
OECD FORD branch
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Result continuities
Project
—
Continuities
S - Specificky vyzkum na vysokych skolach
Others
Publication year
2025
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Book/collection name
Machine Learning, Deep Learning and AI for Cybersecurity
ISBN
978-3-031-83156-0
Number of pages of the result
30
Pages from-to
113-142
Number of pages of the book
642
Publisher name
Springer Nature Switzerland AG
Place of publication
Basel
UT code for WoS chapter
—