arXiv AI

High-Precision APT Malware Attribution with Out-of-Scope Resilience

arXiv:2606. 03523v1 Announce Type: cross Abstract: Early attribution of Advanced Persistent Threat (APT) activity can help defenders prioritise investigation, select countermeasures, and reduce the impact of an intrusion.

arXiv Machine Learning
Sep 24

Enhancing Multiclass Malware Classification in Resource-Constrained Environments

The paper presents a lightweight machine‑learning approach for multi‑class malware detection on resource‑constrained devices. Using a LightGBM classifier with SMOTE oversampling, SOM‑US undersampling, and Genetic‑Algorithm feature selection, the authors achieve 89.1 % accuracy on four malware families and 76 % on 16 individual malware types. A second Random‑Forest model further improves family classification to 91.2 % and individual classification to 78.7 %.

By Abdul Khalek Alve, Alif Rahman, Saadman Zaman, Sazzad Hossen Himel, Muhammad Iqbal Hossain
arXiv Machine Learning
Sep 25

Classifier-Dependent Benefits of Pseudo-Labeling for Semi-Supervised Android Malware Attribution

The study evaluates pseudo‑labeling for semi‑supervised learning on Android malware attribution using six classifiers. Results show that the benefit of SSL varies strongly by classifier: SVM gains the most, LightGBM improves modestly, and Random Forest can be harmed at low label ratios. The approach particularly helps hard‑to‑classify families and achieves near‑optimal performance with about 800 labeled samples.

By Md Rafid Islam, Zahid Hasan, Hafiz Abdur Rahman
arXiv AI
Aug 28

Beyond F1: Evaluating Coverage and Failure Recovery in AI Model Security Scanners

The paper evaluates three AI model security scanners—ModelScan, ModelAudit, and Fickling—using a benchmark of 170 Pickle and PyTorch artifacts from 145 families, 135 of which have binary security labels. It distinguishes coverage metrics such as non‑N/A coverage, analysis completion, and definitive security decisions, finding that ModelAudit achieved 100% definitive decisions, Fickling 81.5%, and ModelScan 49.6%. When a definitive judgment was made, ModelScan reached perfect precision, recall, and F1, while Fickling added no unique true positives beyond those found by the other tools.

By Qianlong Lan, Vinothini Pandurangan, Anuj Kaul, Indranil Sanyal
arXiv Machine Learning
Sep 11

Empirical Evaluation of Data Poisoning Attacks in Supervised Learning

The paper evaluates two training‑time data poisoning attacks—label flipping and backdoor poisoning—on MNIST and Fashion‑MNIST using Logistic Regression, Linear SVM, and Random Forest classifiers. Label flipping degrades performance most for Logistic Regression and Linear SVM, while Random Forest remains relatively stable. Backdoor poisoning achieves near‑perfect attack success rates across all models while largely preserving clean‑test accuracy, highlighting the stealthy nature of targeted backdoors.

By Toshif Khan (Minot State University), Muhammad Abusaqer (Minot State University)
arXiv Machine Learning
Sep 21

Identifying Security Platform Product Abuse with Machine Learning

arXiv:2609.21303v1 Announce Type: cross Abstract: Product abuse is an individually rare, but growing, problem across the SaaS industry. Highly sophisticated threat actors can misuse security platform...

By Shaefer Drew, Michael Brautbar, Paul Knight, Edward Raff, Lana Peric-McDermott, Simran Sarin, Nickolas Machado, Hanna Albright, Vitaly Zaytsev