Selecting Representative Samples from Malware Datasets
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F68407700%3A21240%2F25%3A00385461" target="_blank" >RIV/68407700:21240/25:00385461 - isvavai.cz</a>
Výsledek na webu
<a href="https://doi.org/10.1007/978-3-031-83157-7_5" target="_blank" >https://doi.org/10.1007/978-3-031-83157-7_5</a>
DOI - Digital Object Identifier
<a href="http://dx.doi.org/10.1007/978-3-031-83157-7_5" target="_blank" >10.1007/978-3-031-83157-7_5</a>
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
Selecting Representative Samples from Malware Datasets
Popis výsledku v původním jazyce
This work focuses on the selection of representative instances for the training set in malware detection. Opposed to random instance selection, the goal of instance selection algorithms is to remove noise and redundancy while preserving relevant data for solving the task. Experiments were conducted on two publicly available datasets containing metadata of Windows PE files, namely the EMBER and SOREL-20M datasets. The theoretical part describes data preprocessing methods, instance selection algorithms, and classification algorithms used in the practical part of this work. The practical part outlines the process of preprocessing datasets and main experiments related to the comparison of state-of-the-art instance selection algorithms. As part of the work, modifications to the parallel instance selection algorithm PIF were proposed and implemented, and these were also experimentally evaluated and compared with the results of state-of-the-art instance selection algorithms. Some of the modified versions ranked among the best in terms of reduction level as well as the ratio between accuracy and the size of the reduced sets. The best among the modified versions was the RPIF-AllKNN algorithm, which reduced the entire training set of the SOREL-20M dataset to 6.24% of its original size with an accuracy loss of 2.1%. The ratio between accuracy and the size of the reduced set was 14.43 and in terms of this metric, RPIF-AllKNN was the best among the compared algorithms.
Název v anglickém jazyce
Selecting Representative Samples from Malware Datasets
Popis výsledku anglicky
This work focuses on the selection of representative instances for the training set in malware detection. Opposed to random instance selection, the goal of instance selection algorithms is to remove noise and redundancy while preserving relevant data for solving the task. Experiments were conducted on two publicly available datasets containing metadata of Windows PE files, namely the EMBER and SOREL-20M datasets. The theoretical part describes data preprocessing methods, instance selection algorithms, and classification algorithms used in the practical part of this work. The practical part outlines the process of preprocessing datasets and main experiments related to the comparison of state-of-the-art instance selection algorithms. As part of the work, modifications to the parallel instance selection algorithm PIF were proposed and implemented, and these were also experimentally evaluated and compared with the results of state-of-the-art instance selection algorithms. Some of the modified versions ranked among the best in terms of reduction level as well as the ratio between accuracy and the size of the reduced sets. The best among the modified versions was the RPIF-AllKNN algorithm, which reduced the entire training set of the SOREL-20M dataset to 6.24% of its original size with an accuracy loss of 2.1%. The ratio between accuracy and the size of the reduced set was 14.43 and in terms of this metric, RPIF-AllKNN was the best among the compared algorithms.
Klasifikace
Druh
C - Kapitola v odborné knize
CEP obor
—
OECD FORD obor
10201 - Computer sciences, information science, bioinformathics (hardware development to be 2.2, social aspect to be 5.8)
Návaznosti výsledku
Projekt
—
Návaznosti
S - Specificky vyzkum na vysokych skolach
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Název knihy nebo sborníku
Machine Learning, Deep Learning and AI for Cybersecurity
ISBN
978-3-031-83156-0
Počet stran výsledku
30
Strana od-do
113-142
Počet stran knihy
642
Název nakladatele
Springer Nature Switzerland AG
Místo vydání
Basel
Kód UT WoS kapitoly
—