arXiv論文メモ
新着一覧
cs.CR · 査読状況未確認

Androidマルウェア分類でグラフ分割の効果を対照比較

Partition-Matched Evaluation of Community Features under Distribution Shift in Android Malware Function-Call Graphs

Junru Zhu, Yixin Yang, Xiaoqing Ding, Ruoyu Qi

この論文をやさしく読む

ひとことで言うと

関数呼び出しグラフのコミュニティ特徴が、Androidマルウェアの種類が変わっても安定して役立つかを検証した。

何に役立つ?

考えられる用途は、マルウェア分類器の特徴量を評価する際の対照実験の設計である。

この研究の面白いところ

単純なランダム分割とサイズを合わせて比べると、コミュニティの分布変化への優位性は再現しなかった。

どこまで分かった?

15,000グラフと指定した記述子・分割方法での結果である。別の特徴や分布変化全般を否定するものではない。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

グラフを用いたAndroidマルウェア分類器は、マルウェアの種類やファミリーの分布が変わると精度を失うことがある。本研究は、関数呼び出しグラフの中規模なまとまりが、局所次数プロファイル(LDP)、全体統計、軽量なメタデータ、同じ大きさに合わせたランダムな分割よりも、分布変化に安定な情報を持つかを調べる。 MalNet-Tiny、Common、Distinctの計15,000グラフを用い、評価前に指定したLeiden法の六つの記述子と最適化器の五つのシードで検証した。コミュニティ情報を加えると、TinyでのマクロF1は78.7%から81.3%に上がる一方、学習元だけを用いたCommonへの移行では29.4ポイント低下した。同じ大きさに合わせたランダム分割の一つでは27.8ポイント低下し、五つのランダム分割の平均低下幅は27.9ポイントだった。ランダム分割の低下幅からコミュニティ分割の低下幅を引いた差について、二段階ブートストラップによる95%区間は−4.2~1.2ポイントだった。メタデータを加えた場合の対応する差は−0.2ポイント、区間は−1.1~0.6ポイントだった。モジュラリティを取り除くと、構造だけを使ったCommonでのマクロF1は51.9%から53.6%に上がった。検証した特徴は同一分布での情報を増やすが、分布変化への安定性で再現可能な優位性は示さなかった。この結果は、中規模のグラフ構造について主張するには、分割サイズを合わせた対照群と複数のランダム抽出が必要であることを示す。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-21(UTC)
最新改訂
2026-09-21 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Graph-based Android malware classifiers can lose accuracy under malware-type or family shifts. We test whether mesoscopic organization in function-call graphs provides shift-stable information beyond local degree profiles (LDP), global statistics, lightweight metadata, and size-matched random partitions. Using 15,000 MalNet-Tiny, Common, and Distinct graphs, six Leiden descriptors specified before evaluation, and five optimizer seeds, communities raise Tiny macro F1 from 78.7% to 81.3% but yield 29.4-point source-only Common degradation. One size-matched random partition yields 27.8-point degradation. Across five random partitions, mean degradation is 27.9 points; the 95% two-level bootstrap interval for random minus community degradation is [-4.2, 1.2] points. With metadata, the corresponding difference is -0.2 points with interval [-1.1, 0.6]. Removing modularity raises structure-only Common macro F1 from 51.9% to 53.6%. The tested signature adds IID signal but shows no repeatable shift-stability advantage, demonstrating why mesoscopic graph claims need partition-matched controls and repeated null draws.

著者のコメント

6 pages, 1 figure, 3 tables

arXiv ID: 2609.25256 / 要約の誤りについて