{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/119758"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/119758","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Towards robust malware detection","abstract":"A central challenge of malware detection using machine learning methods is the presence of adversarial variants, small changes to detectable malware that allow it to evade a model (i.e. be classified as benign). We take inspiration from adversarial variant generation methods in the continuous-valued image domain to introduce methods for malware in the binary domain. We incorporate these methods in the training of hardened models towards the goal of robustness against adversarial variants. Additionally, we provide visualization tools for analysis of hardened models. Our tools illustrate the difference in loss behavior between models trained with different methods, the effect of adversarial learning on the loss landscape of a model, and the effect of adversarial learning on the decision map of a model. The adversarial learning framework and the visualization tools in combination allow for the creation and understanding of robust models.","abstract_html":"A central challenge of malware detection using machine learning methods is the presence of adversarial variants, small changes to detectable malware that allow it to evade a model (i.e. be classified as benign). We take inspiration from adversarial variant generation methods in the continuous-valued image domain to introduce methods for malware in the binary domain. We incorporate these methods in the training of hardened models towards the goal of robustness against adversarial variants. Additionally, we provide visualization tools for analysis of hardened models. Our tools illustrate the difference in loss behavior between models trained with different methods, the effect of adversarial learning on the loss landscape of a model, and the effect of adversarial learning on the decision map of a model. The adversarial learning framework and the visualization tools in combination allow for the creation and understanding of robust models.","abstract_has_math":false,"creators":["Huang, Alex Yangyang"],"institution":"Massachusetts Institute of Technology","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science.","school":null,"contributors":[],"advisors":["Abdullah Al-Dujaili and Una-May O'Reilly."],"committee_chairs":[],"committee_members":[],"year":2018,"date_issued":"2018","date_published":"2018","updated_at":"2026-07-22T22:21:47Z","subjects":["Electrical Engineering and Computer Science."],"languages":["eng"],"rights":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."],"rights_urls":["http://dspace.mit.edu/handle/1721.1/7582"],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/1721.1/119758","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Abdullah Al-Dujaili and Una-May O'Reilly."]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."]},{"key":"dc:contributor.other","label":"Dc Contributor Other","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."]},{"key":"dc:creator","label":"Author","values":["Huang, Alex Yangyang"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2018-12-18T19:48:47Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2018-12-18T19:48:47Z"]},{"key":"dc:date.issued","label":"Date","values":["2018"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Electrical Engineering and Computer Science."]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://dspace.mit.edu/handle/1721.1/7582"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/1721.1/119758"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Thesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2018.","This electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.","Cataloged from student-submitted PDF version of thesis.","Includes bibliographical references (pages 45-48)."]},{"key":"dc:description.abstract","label":"Abstract","values":["A central challenge of malware detection using machine learning methods is the presence of adversarial variants, small changes to detectable malware that allow it to evade a model (i.e. be classified as benign). We take inspiration from adversarial variant generation methods in the continuous-valued image domain to introduce methods for malware in the binary domain. We incorporate these methods in the training of hardened models towards the goal of robustness against adversarial variants. Additionally, we provide visualization tools for analysis of hardened models. Our tools illustrate the difference in loss behavior between models trained with different methods, the effect of adversarial learning on the loss landscape of a model, and the effect of adversarial learning on the decision map of a model. The adversarial learning framework and the visualization tools in combination allow for the creation and understanding of robust models."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["M. Eng."]},{"key":"dc:title","label":"Title","values":["Towards robust malware detection"]}]}],"canonical_facts":{"dc:contributor.advisor":["Abdullah Al-Dujaili and Una-May O'Reilly."],"dc:contributor.department":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."],"dc:contributor.other":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science."],"dc:creator":["Huang, Alex Yangyang"],"dc:date.accessioned":["2018-12-18T19:48:47Z"],"dc:date.available":["2018-12-18T19:48:47Z"],"dc:date.issued":["2018"],"dc:description":["Thesis: M. Eng., Massachusetts Institute of Technology, Department of Electrical Engineering and Computer Science, 2018.","This electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.","Cataloged from student-submitted PDF version of thesis.","Includes bibliographical references (pages 45-48)."],"dc:description.abstract":["A central challenge of malware detection using machine learning methods is the presence of adversarial variants, small changes to detectable malware that allow it to evade a model (i.e. be classified as benign). We take inspiration from adversarial variant generation methods in the continuous-valued image domain to introduce methods for malware in the binary domain. We incorporate these methods in the training of hardened models towards the goal of robustness against adversarial variants. Additionally, we provide visualization tools for analysis of hardened models. Our tools illustrate the difference in loss behavior between models trained with different methods, the effect of adversarial learning on the loss landscape of a model, and the effect of adversarial learning on the decision map of a model. The adversarial learning framework and the visualization tools in combination allow for the creation and understanding of robust models."],"dc:description.degree":["M. Eng."],"dc:identifier.uri":["http://hdl.handle.net/1721.1/119758"],"dc:language.iso":["eng"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."],"dc:rights.uri":["http://dspace.mit.edu/handle/1721.1/7582"],"dc:subject":["Electrical Engineering and Computer Science."],"dc:title":["Towards robust malware detection"],"dc:type":["Thesis"]},"updated_at":"2026-07-22T22:21:47Z"}