{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:T5CVWRWTJCOV4S7RTG35BRGXRU","short_pith_number":"pith:T5CVWRWT","schema_version":"1.0","canonical_sha256":"9f455b46d3489d5e4bf199b7d0c4d78d1d56aa054cfd343928fb346f30144489","source":{"kind":"arxiv","id":"2407.13918","version":2},"attestation_state":"computed","paper":{"title":"Revisiting Concept Drift in Windows Malware Detection: Adaptation to Real Drifted Malware with Minimal Samples","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Adrian Shuai Li, Arun Iyengar, Ashish Kundu, Elisa Bertino","submitted_at":"2024-07-18T22:06:20Z","abstract_excerpt":"In applying deep learning for malware classification, it is crucial to account for the prevalence of malware evolution, which can cause trained classifiers to fail on drifted malware. Existing solutions to address concept drift use active learning. They select new samples for analysts to label and then retrain the classifier with the new labels. Our key finding is that the current retraining techniques do not achieve optimal results. These techniques overlook that updating the model with scarce drifted samples requires learning features that remain consistent across pre-drift and post-drift da"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2407.13918","kind":"arxiv","version":2},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2024-07-18T22:06:20Z","cross_cats_sorted":[],"title_canon_sha256":"81a2af7b02fe42fd7567921537732044ee61b150e30fb24d1457297fa7f73134","abstract_canon_sha256":"14296e3e8386df33c211c0b7dec082cdf9f7392f3c498dd7151380163beb4c3b"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:52:13.842327Z","signature_b64":"i6Mr5TKEA1uCRrNRCKylUbrGSVlfnBg/S+CS+RNDYOtfWWD4MJL9G4VlP3rjlWDXmw8hodrkKr5957WQxlXJBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9f455b46d3489d5e4bf199b7d0c4d78d1d56aa054cfd343928fb346f30144489","last_reissued_at":"2026-07-05T09:52:13.841830Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:52:13.841830Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Revisiting Concept Drift in Windows Malware Detection: Adaptation to Real Drifted Malware with Minimal Samples","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Adrian Shuai Li, Arun Iyengar, Ashish Kundu, Elisa Bertino","submitted_at":"2024-07-18T22:06:20Z","abstract_excerpt":"In applying deep learning for malware classification, it is crucial to account for the prevalence of malware evolution, which can cause trained classifiers to fail on drifted malware. Existing solutions to address concept drift use active learning. They select new samples for analysts to label and then retrain the classifier with the new labels. Our key finding is that the current retraining techniques do not achieve optimal results. These techniques overlook that updating the model with scarce drifted samples requires learning features that remain consistent across pre-drift and post-drift da"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2407.13918","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2407.13918/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2407.13918","created_at":"2026-07-05T09:52:13.841888+00:00"},{"alias_kind":"arxiv_version","alias_value":"2407.13918v2","created_at":"2026-07-05T09:52:13.841888+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2407.13918","created_at":"2026-07-05T09:52:13.841888+00:00"},{"alias_kind":"pith_short_12","alias_value":"T5CVWRWTJCOV","created_at":"2026-07-05T09:52:13.841888+00:00"},{"alias_kind":"pith_short_16","alias_value":"T5CVWRWTJCOV4S7R","created_at":"2026-07-05T09:52:13.841888+00:00"},{"alias_kind":"pith_short_8","alias_value":"T5CVWRWT","created_at":"2026-07-05T09:52:13.841888+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":2,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.10264","citing_title":"RECON: An LLM-Enhanced Backward Constraint Analysis Framework","ref_index":39,"is_internal_anchor":false},{"citing_arxiv_id":"2604.21310","citing_title":"Adversarial Evasion in Non-Stationary Malware Detection: Minimizing Drift Signals through Similarity-Constrained Perturbations","ref_index":14,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU","json":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU.json","graph_json":"https://pith.science/api/pith-number/T5CVWRWTJCOV4S7RTG35BRGXRU/graph.json","events_json":"https://pith.science/api/pith-number/T5CVWRWTJCOV4S7RTG35BRGXRU/events.json","paper":"https://pith.science/paper/T5CVWRWT"},"agent_actions":{"view_html":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU","download_json":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU.json","view_paper":"https://pith.science/paper/T5CVWRWT","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2407.13918&json=true","fetch_graph":"https://pith.science/api/pith-number/T5CVWRWTJCOV4S7RTG35BRGXRU/graph.json","fetch_events":"https://pith.science/api/pith-number/T5CVWRWTJCOV4S7RTG35BRGXRU/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU/action/timestamp_anchor","attest_storage":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU/action/storage_attestation","attest_author":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU/action/author_attestation","sign_citation":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU/action/citation_signature","submit_replication":"https://pith.science/pith/T5CVWRWTJCOV4S7RTG35BRGXRU/action/replication_record"}},"created_at":"2026-07-05T09:52:13.841888+00:00","updated_at":"2026-07-05T09:52:13.841888+00:00"}