Pith. sign in

REVIEW 4 cited by

MORPH: Towards Automated Concept Drift Adaptation for Malware Detection

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2401.12790 v1 pith:E5M23VLV submitted 2024-01-23 cs.LG

classification cs.LG
keywords conceptdriftmalwareadaptationdetectionlearningmethodactive
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Concept drift is a significant challenge for malware detection, as the performance of trained machine learning models degrades over time, rendering them impractical. While prior research in malware concept drift adaptation has primarily focused on active learning, which involves selecting representative samples to update the model, self-training has emerged as a promising approach to mitigate concept drift. Self-training involves retraining the model using pseudo labels to adapt to shifting data distributions. In this research, we propose MORPH -- an effective pseudo-label-based concept drift adaptation method specifically designed for neural networks. Through extensive experimental analysis of Android and Windows malware datasets, we demonstrate the efficacy of our approach in mitigating the impact of concept drift. Our method offers the advantage of reducing annotation efforts when combined with active learning. Furthermore, our method significantly improves over existing works in automated concept drift adaptation for malware detection.

Discussion (0). Sign in to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Empirical Evaluation of Concept Drift in ML-Based Android Malware Detection

    cs.CR 2025-07 conditional novelty 5.0 of 10

    Concept drift consistently lowers Android malware detection accuracy across nine machine learning and deep learning algorithms and two large language models, on two datasets.

  2. Understanding Concept Drift with Deprecated Permissions in Android Malware Detection

    cs.CR 2025-07 reject novelty 5.0 of 10

    Removing deprecated and restricted Android permissions barely changes malware detection accuracy, but makes year-to-year model drift easier to detect.

  3. ADAPT: A Pseudo-labeling Approach to Combat Concept Drift in Malware Detection

    cs.LG 2025-07 conditional novelty 5.0 of 10

    A pseudo-labeling method with class-specific adaptive thresholds, label-consistent augmentation, and mixup reduces concept-drift performance loss in malware classifiers across five datasets.

  4. MADCAT: Combating Malware Detection Under Concept Drift with Test-Time Adaptation

    cs.CR 2025-05 reject novelty 5.0 of 10

    MADCAT applies masked-autoencoder test-time training to Android malware detection and reports improved F1 under concept drift, but the main experiments use ground-truth labels for balancing.

Pith tools