Skip to main navigation Skip to search Skip to main content

Debugging Malware Classification Models Based on Event Logs with Explainable AI

  • State University of New York Binghamton University
  • IBM
  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

As machine learning models find broader applications in cybersecurity, the importance of model explainability becomes more evident. In the area of malware detection, where the consequence of misclassification can be severe, explainability becomes crucial. AI explainers not only help understand the reasons behind malware classifications but also assist in finetuning models to improve detection accuracy. Additionally, AI explainers can serve as a valuable tool for error detection, ensuring accountability, and mitigating potential biases. In this paper, we demonstrate how AI explainers can play a vital role in identifying issues in data collection and enhancing our comprehension of the model's classification results. Our analysis of explanation results reveals several issues within the data collection process, including event loss and the presence of environment-specific information. Additionally, we have identified mislabelled samples based on the explanation results and shared lessons learned from our data collection efforts.

Original languageEnglish
Title of host publicationProceedings - 23rd IEEE International Conference on Data Mining Workshops, ICDMW 2023
EditorsJihe Wang, Yi He, Thang N. Dinh, Christan Grant, Meikang Qiu, Witold Pedrycz
PublisherIEEE Computer Society
Pages939-948
Number of pages10
ISBN (Electronic)9798350381641
DOIs
StatePublished - 2023
Event23rd IEEE International Conference on Data Mining Workshops, ICDMW 2023 - Hybrid, Shanghai, China
Duration: Dec 1 2023Dec 4 2023

Publication series

NameIEEE International Conference on Data Mining Workshops, ICDMW

Conference

Conference23rd IEEE International Conference on Data Mining Workshops, ICDMW 2023
Country/TerritoryChina
CityHybrid, Shanghai
Period12/1/2312/4/23

Keywords

  • ETW
  • Random Forest
  • SHAP
  • TreeSHAP
  • XAI
  • explainable AI
  • malware detection

Fingerprint

Dive into the research topics of 'Debugging Malware Classification Models Based on Event Logs with Explainable AI'. Together they form a unique fingerprint.

Cite this