Files

Evaluation_of_Behavior_Graph_Reduction_Strategies_for_ML_Based_Malware_Detection-2.pdf
  • Open Access
  • Adobe PDF
  • 2.38 MB

Details

Authors
Abstract
Graph-based representations of program behavior are a powerful foundation for machine learning-based malware detection. However, the large size and complexity of these behavior graphs pose scalability challenges. This paper presents a systematic evaluation of five graph reduction strategies—covering both coarsening and sparsification—designed to simplify graphs while preserving meaningful behavioral features. Using dynamic analysis data from Windows PE32 binaries, we analyze the impact of these reductions on computational efficiency, detection performance, and model robustness against adversarial mimicry attacks. Our results show that several strategies substantially reduce graph size and extraction time without significant accuracy loss. We also find that coarsening based on API calls’ action maintains stronger robustness to adversarial manipulation.
Affiliations

Citations

Bettaieb, S., Lucca, S., Bertrand Van Ouytsel, C.-H., & Riviere, E. (2025). Evaluating Behavior Graph Reduction Strategies for Machine Learning-Based Malware Detection. Proceedings of the 24th IEEE International Conference on Trust, Security and Privacy in Computing and Communications. Published. The 24th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Guiyang, China. https://hdl.handle.net/2078.5/271857