VLDB 2026 Research / reviewers in the wild / expert
Hemant Rathore
dblp:224/4545
· DBLP profile ↗
34ranked-venue papers
13as first author
21since 2021 · last 2025
0000-0001-7298-0210ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 15 · 4 first-author · 10 since 2021Computer networks · 6 · 5 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 1 since 2021Security and privacy · 1Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | G-GQSA: Exploiting Feature-Based Vulnerabilities and Enhancing Adversarial Resilience in Android Malware DetectionabstractAndroid, as the world's dominant mobile operating system, provides a broad ecosystem of applications accessible through official channels like the Google Play Store and various third-party platforms. Despite rigorous security protocols, malicious actors continue to compromise user safety by embedding malware within seemingly innocuous apps. The increasing sophistication of these threats has driven the adoption of advanced machine learning (ML) and deep learning (DL) techniques for malware detection. While these techniques have shown significant promise, particularly in identifying complex and evolving malware, they remain vulnerable to adversarial attacks. In this work, we introduce a targeted evasion attack called Gradient-Guided Q-Learning with Simulated Annealing (G-GQSA), designed for grey-box scenarios, to evaluate the resilience of these detection models. G-GQSA creates adversarial examples by making minimal perturbations to the binary features of Android permissions and intents, thereby evading detection. Our experiments show that G-GQSA achieves an average fooling rate of 100% with only 3.474 perturbations for 13 permission-based models and 1.630 perturbations for 13 intent-based models. We also conduct a comprehensive feature analysis to evaluate how accurately our method identifies significant features. This analysis reveals an impressive overlap of 81.71% in critical features across all 26 classification models, demonstrating our method's effectiveness in identifying key features that impact model predictions. Finally, we implement adversarial retraining techniques to enhance the robustness of detection models, successfully reducing G-GQSA's fooling rate to 16.77% across the same 26 detection models. Our study underscores the critical need to understand the origins and interactions of adversarial samples with different malware families and emphasizes the importance of developing robust defense mechanisms before deploying ML and DL-based detection systems in real-world applications. Advik Raj Basani, Hemant Rathore |
CCNC | 2 |
| 2025 | Linear Decision Trees: A Comparative Study with Insights on ReLU Neural NetworksabstractTraditional decision trees also known as vanilla decision trees, use axis-aligned splits and are interpretable. Alternate implementations known as linear decision trees use oblique splits to form shorter trees that can improve feature utilisation and performance. In this paper, we compare linear decision trees with vanilla decision trees, random forests, and ReLU neural networks. We theoretically demonstrate that any ReLU neural network can be represented as a linear decision tree in a binary classification setting. We evaluate the performance of the four model classes using both generated and real-world datasets and assess the impact of noise, ground truth complexity, and dataset size. Our findings indicate that vanilla decision trees and random forests are well-suited for real-world tabular data, while linear decision trees perform better on datasets with less noise and linear ground truths. In contrast, neural networks excel with both linear and non-linear ground truths in several scenarios. Additionally, we analyse the interpretability of linear decision trees in comparison with vanilla decision trees and also discuss their suitability for interpreting neural networks. Nirmal Govindaraj, Kumarakrishna Valeti, Siddhant Kulkarni, Nandan Surani, Hemant Rathore |
CCNC | 5 |
| 2025 | DNN-GRAD: Exploiting Membership Inference for Adversarial Attacks on Malware Detection ModelsabstractAndroid is currently the most dominant mobile operating system, with over 70 % of smartphones using it. This widespread adoption makes malware developers target Android devices to exploit security vulnerabilities. Current mal ware de-tection solutions use a combination of traditional signature and heuristics-based methods along with newer machine learning-based methods for protection against evolving malware attacks. While effective, machine learning models are often vulnerable to adversarial attacks. Adversaries can carefully perturb malware samples to evade detection by these models. Furthermore, these models are known to leak information about their training data, which adversaries can exploit to infer private and sensitive information via membership inference attacks. In this study, we propose a novel method to exploit membership information to improve the effectiveness of adversarial attacks. This method effectively selects a subset of available data using membership information leaked from the target model, allowing one to better approximate the target model's training data. Training a local model with the selected data, we demonstrate that an attacker can improve the effectiveness of the attack, achieving a 17 % increase in fooling rate while using 15 % less data compared to using all available data. We then propose DNN-GRAD, a grey-box gradient-based adversarial attack which, by using this leaked membership information, achieves a fooling rate of 56.69 % against various machine learning-based malware detectors. We also demonstrate that a combination of defences like adversarial training and regularization reduces the fooling rate by 46 % reduction in fooling rate across various model architectures. Siddhant Kulkarni, Hemant Rathore |
CCNC | 2 |
| 2025 | ExpanQN: Enhancing Android Malware Detection with Dataset Expansion and Adversarial RobustnessabstractAndroid is the predominant smartphone operating system, with various Android applications being a key attractor. However, certain malicious actors take advantage of security vulnerabilities to exploit users. Traditionally, security systems have relied on signatures, rules and other static methods for detection. However, recently, researchers have explored the efficacy of Machine Learning and Deep Learning models for malware detection. These methods have shown great promise and have outperformed several antivirus solutions but researchers face a major challenge due to a lack of access to extensive malware datasets due to the intensive process of collection and labelling applications. These models also face the threat of adversarial attacks, which can make small targeted perturbations to evade these models. In this study, we propose the ExpanQN algorithm to expand the existing malware family datasets while also improving the robustness of malware detection models. We generate 55.16 adversarial samples per input sample on average using ExpanQN and expand five malware families. ExpanQN generates adversarial variants that have a similarity of over 94% with source samples, allowing for family-specific expansion. These adversarial samples achieve misclassification rates greater than 71% against 10 malware detection models which initially achieved an average accuracy of 93.51%. We analyse the misclassification rates of distinct algorithmic classes and malware families against these variants and implement adversarial retraining, resulting in robust models having an accuracy greater than 95% against the variants. Kumarakrishna Valeti, Siddhant Kulkarni, Hemant Rathore |
IJCNN | 3 |
| 2022 | Android Malware Detection Based on Static Analysis and Data Mining Techniques: A Systematic Literature Review
Hemant Rathore, Soham Chari, Nishant Verma, Sanjay K. Sahay, Mohit Sewak |
BROADNETS | 1 |
| 2022 | MalEfficient10%: A Novel Feature Reduction Approach for Android Malware Detection
Hemant Rathore, Ajay Kharat, Rashmi T, Adithya Manickavasakam, Sanjay K. Sahay, Mohit Sewak |
BROADNETS | 1 |
| 2022 | Deep CounterStrike: Counter Adversarial Deep Reinforcement Learning for Defense Against Metamorphic Ransomware Swarm Attack
Mohit Sewak, Sanjay K. Sahay, Hemant Rathore |
BROADNETS | 3 |
| 2022 | Elections in Twitter Era: Predicting Winning Party in US Elections 2020 Using Deep Learning
Soham Chari, Rashmi T, Hitesh Mohan Kumain, Hemant Rathore |
HIS | 4 |
| 2022 | Defending malware detection models against evasion based adversarial attacks
Hemant Rathore, Animesh Sasan, Sanjay K. Sahay, Mohit Sewak |
Pattern Recognit. Lett. | 1 |
| 2021 | Duplicates in the Drebin Dataset and Reduction in the Accuracy of the Malware Detection ModelsabstractThe Android operating system has constantly remained in the limelight, hence attracts the attention of cyber-criminals. Understanding the rising challenges, many researchers have bagged achievements by applying machine/deep learning techniques for the construction of malware detection models based on popular Drebin malware datasets. However, a cursory look at a table of the frequency of Dalvik opcodes leads us to believe that this dataset may have a massive number of duplicate malicious files. Hence, we used a technique called fitting factor to find the duplicate malicious files in the Drebin datasets on the basis of opcodes occurrence. We found that 51.57% malicious samples in the datasets have one or more duplicates. Hence, accordingly, we studied the performance of the popular detection models with and without duplicates with all the features, top 26 features engineered by Information Gain (IG) and Auto-Encoder (AE). The experimental results show that one of the most popular classical classifiers, the Random Forest classifier, shows a decline in accuracy by 4.2%, 5.3% and 8.8% with all features, top 26 features obtained by IG and AE respectively. To establish the observed facts we further extensively experimented with Decision Tree, Bagging, Gradient Boost, XG Boost, and Deep Neural Network. The most significant decline (12.2%) in accuracy was observed in the Deep Neural Network classifier with the features obtained by IG, i.e., the earlier reported performance of the malware detection models based on Drebin data is exaggerated, and consequently it may lead to a wrong direction in this field of research. Jyotiprakash Mishra, Sanjay K. Sahay, Hemant Rathore, Lokesh Kumar |
APCC | 3 |
| 2021 | Credit Card Fraud Detection Using K-Means Combined with Supervised Learning
Shreyans Jain, Nishant Verma, Aman Tayal, Hemant Rathore |
HIS | 5 |
| 2021 | Sentiment Analysis of IMDb Movie Reviews: A Comparative Analysis of Feature Selection and Feature Extraction Techniques
Gahina Karak, Shubham Mishra, Arkadyuti Bandyopadhyay, Pavirala Ranga Sai Rohith, Hemant Rathore |
HIS | 5 |
| 2021 | Intrusion Detection System Based on Machine and Deep Learning Models: A Comparative and Exhaustive Study
Hemlatha Pandey, Tejal Lalitkumar Karnavat, Mandadapu Naga Sai Sandilya, Shashwat Katiyar, Hemant Rathore |
HIS | 5 |
| 2021 | Identification of Adversarial Android Intents using Reinforcement LearningabstractAndroid malware has grown manifold in the last decade and has become a threat to the ecosystem. Recently published literature suggests that the data mining based models have shown promising results in android malware detection. However, adversaries can identify vulnerabilities in these detection models using adversarial learning. Adversaries can further exploit these vulnerabilities by performing adversarial attacks on these detection models and reduce their performance. Therefore in this work, we first put ourselves in the adversary's shoes and propose an evasion attack to find vulnerabilities in various malware detection models using reinforcement learning. The attack aims to add perturbation(s) in malware samples to generate adversarial samples such that they are forcefully misclassified as benign samples by the malware detection models. The attack is designed for a limited knowledge scenario where an adversary does not know the learning algorithm used to build detection models, which is similar to a real-world scenario. We validated the proposed adversarial attack against ten malware detection models constructed using different learning algorithms. Our proposed attack with limited knowledge and capabilities accomplish more than 58% forced misclassification rate against all ten detection models. We also identified ten vulnerable intents that an adversary could exploit to decrease the performance of malware detection models. Lastly, we propose a defense against evasion attacks to increase the adversarial robustness of all malware detection models. Hemant Rathore, Piyush Nikam, Sanjay K. Sahay, Mohit Sewak |
IJCNN | 1 |
| 2021 | LSTM Hyper-Parameter Selection for Malware Detection: Interaction Effects and Hierarchical Selection ApproachabstractLong-Short-Term-Memory (LSTM) networks have shown great promise in artificial intelligence (AI) based language modeling. Recently, LSTM networks have also become popular for designing an AI-based Intrusion Detection Systems (IDS). However, its applicability in IDS is studied largely in the default settings as used in language models. Whereas security applications offer distinct conditions and hence warrant careful consideration while applying such recurrent networks. Therefore, we conducted one of the most exhaustive work on LSTM hyperparameters for IDS and experimented with 150 LSTM configurations to determine its hyper-parameters' relative-importance, interaction-effects, and optimal selection-approach for designing an IDS. We conducted multiple analysis of the results of these experiments and empirically controlled for the interaction effects of different hyper-parameters covariate level. We found that for security applications, especially for designing an IDS, neither similar relative importance as applicable to language models is valid, nor is the standard linear method for hyper-parameter selection ideal. We ascertained that interaction effect plays a crucial role in determining the relative importance of hyperparameters. We also discovered that after controlling for the interaction-effect, the correct relative importance for LSTMs for an IDS are batch-size, followed-by dropout ratio and padding. The findings are significant because when LSTM were first used for language models, the focus had mostly been on increasing the number of layers to enhance performance. Mohit Sewak, Sanjay K. Sahay, Hemant Rathore |
IJCNN | 3 |
| 2021 | ADVERSARIALuscator: An Adversarial-DRL based Obfuscator and Metamorphic Malware Swarm GeneratorabstractAdvanced metamorphic malware and ransomware, by using obfuscation, could alter their internal structure with every attack. If such malware could intrude even into any of the IoT network, then even if the original malware instance get detected, by that time it can still infect the entire network. The IoT era also required Industry 4.0 grade AI based defense against such advanced malware. But AI algorithm need a lot of training data, and it is challenging to obtain training data for such evasive malware. Therefore, in this paper, we present ADVERSARIALuscator, a novel system that uses specialized (adversarial) deep reinforcement learning to obfuscate malware at the opcode level and create multiple metamorphic instances of the same. To the best of our knowledge, is the first-ever system that adopts the Markov Decision Process based approach to convert and find a solution to the problem of creating individual obfuscations at the opcode level. This is important as the machine language level is the least at which functionality could be preserved so as to mimic an actual attack effectively. is also the first-ever system to use efficient continuous action control capable deep reinforcement learning agents like the Proximal Policy Optimization in the area of cyber security. Experimental results indicate that could raise the metamorphic probability of a corpus of malware by ≥ 0.45. Additionally, more than 33% of metamorphic instances generated by were able to evade even the most potent IDS and penetrate the target system, even when the defending IDS could detect the original malware instance. Hence could be used to generate data representative of a swarm of very potent and coordinated AI based metamorphic malware attack. The so generated data and simulations could be used to bolster the defenses of an IDS against an actual AI based metamorphic attack from advanced malware and ransomware. Mohit Sewak, Sanjay K. Sahay, Hemant Rathore |
IJCNN | 3 |
| 2021 | Designing Adversarial Robust and Explainable Malware Detection System for Android based Smartphones: PhD Forum AbstractabstractAndroid smartphones and malware have grown exponentially in the last decade. Literature suggests that the current malware detection systems cannot cope with the present security challenges. Thus researchers are developing next-generation malware detection systems/models using the machine and deep learning. However, the proposed systems/models have poor explainability and are vulnerable against adversarial attacks, which will jeopardize their adoption in the future security ecosystem. Thus, we aim to construct adversarial robust malware detection models by first acting as an adversary to find vulnerabilities in models and then proposing preventive countermeasures. We also aim to improve models' explain-ability to win security community confidence before real-world implementation. Hemant Rathore |
IPSN | 1 |
| 2021 | Are Android Malware Detection Models Adversarially Robust?: Poster AbstractabstractThe popularity of android mobile phones has increased manifolds in the last few years, which has attracted many malware developers. Researchers have proposed several new-age malware detection models using machine and deep learning algorithms to strengthen the current detection engines. However, we found that these models are adversarially vulnerable, which will jeopardize their adoption in the security ecosystem. We proposed a framework where we first stepped into the attacker's shoes to design a correlation-based evasion attack and tested it against four different malware detection models. The attack exploited vulnerabilities and drastically reduced the performance of all four detection models. Later we proposed adversarial retraining as the defense strategy to counter the attacks and improve the adversarial robustness of android malware detection models. Hemant Rathore, Sanjay K. Sahay, Mohit Sewak |
IPSN | 1 |
| 2021 | Image-based Android Malware Detection Models using Static and Dynamic Features
Hemant Rathore, B. Raja Narasimhan, Sanjay K. Sahay, Mohit Sewak |
ISDA | 1 |
| 2021 | DRo: A data-scarce mechanism to revolutionize the performance of DL-based Security SystemsabstractSupervised Deep Learning requires plenty of labeled data to converge, and hence perform optimally for task-specific learning. Therefore, we propose a novel mechanism named DRo (for Deep Routing) for data-scarce domains like security. The DRo approach builds upon some of the recent developments in Deep-Clustering. In particular, it exploits the self-augmented training mechanism using synthetically generated local perturbations. DRo not only allays the challenges with sparse-labeled data but also offers many unique advantages. We also developed a system named DRoID that uses the DRo mechanism for enhancing the performance of an existing Malware Detection System that uses (low information features like the) Android implicit Intent(s) as the only features. We conduct experiments on DRoID using a popular and standardized Android malware dataset and found that the DRo mechanism could successfully reduce the false-alarms generated by the downstream classifier by 67.9%, and also simultaneously boosts its accuracy by 11.3%. This is significant not only because the gains achieved are unparalleled but also because the features used were never considered rich-enough to train a classifier on; and hence no decent performance could ever be reported by any malware classification system till-date using these features in isolation. Owing to the results achieved, the DRo mechanism claims a dominant position amongst all known systems that aims to enhance the classification performance of deep learning models with sparse-labeled data. Mohit Sewak, Sanjay K. Sahay, Hemant Rathore |
LCN | 3 |
| 2021 | Are CNN based Malware Detection Models Robust?: Developing Superior Models using Adversarial Attack and DefenseabstractThe tremendous increase of malicious applications in the android ecosystem has prompted researchers to explore deep learning based malware detection models. However, research in other domains suggests that deep learning models are adversarially vulnerable, and thus we aim to investigate the robustness of deep learning based malware detection models. We first developed two image-based E-CNN malware detection models based on android permission and intent. We then acted as an adversary and designed the ECO-FGSM evasion attack against the above models, which achieved more than 50% fooling rate with limited perturbations. The evasion attack converts maximum malware samples into adversarial samples while minimizing the perturbations and maintaining the sample's syntactical, functional, and behavioral integrity. Later, we used adversarial retraining to counter the evasion attack and develop adversarially superior malware detection models, which should be an essential step before any real-world deployment. Hemant Rathore, Taeeb Bandwala, Sanjay K. Sahay, Mohit Sewak |
SenSys | 1 |
| 2020 | Identification of Significant Permissions for Efficient Android Malware Detection
Hemant Rathore, Sanjay K. Sahay, Ritvik Rajvanshi, Mohit Sewak |
BROADNETS | 1 |
| 2020 | Detection of Malicious Android Applications: Classical Machine Learning vs. Deep Neural Network Integrated with Clustering
Hemant Rathore, Sanjay K. Sahay, Shivin Thukral, Mohit Sewak |
BROADNETS | 1 |
| 2020 | Detection of Fake News Based on Domain Analysis and Social Network Psychology
Dipayan Deb, Ratti Sai Pavan, Azad Nautiyal, Ameya Phadnis, Hemant Rathore |
HIS | 5 |
| 2020 | Emotion Recognition Using Multimodalities
Ajay Kharat, Ashish Patel, Dhruv Bhatt, Nand Parikh, Hemant Rathore |
HIS | 5 |
| 2020 | Movie Recommendation System Addressing Changes in User Preferences with Time
Dhairya Parikh, Dilpreet Kaur, Kajal Parikh, Prakhar Yadav, Hemant Rathore |
HIS | 5 |
| 2020 | DeepIntent: ImplicitIntent based Android IDS with E2E Deep Learning architectureabstractThe Intent in Android plays an important role in inter-process and intra-process communications. The implicit Intent that an application could accept are declared in its manifest and are amongst the easiest feature to extract from an apk. Implicit Intents could even be extracted online and in real-time. So far neither the feasibility of developing an Intrusion Detection System solely on implicit Intent has been explored, nor are any benchmarks available of a malware classifier that is based on implicit Intent alone. We demonstrate that despite Intent is implicit and well declared, it can provide very intuitive insights to distinguish malicious from non-malicious applications. We conducted exhaustive experiments with over 40 different end-to-end Deep Learning configurations of Auto-Encoders and Multi-Layer-Perceptron to create a benchmark for a malware classifier that works exclusively on implicit Intent. Using the results from the experiments we create an intrusion detection system using only the implicit Intents and end-to-end Deep Learning architecture. We obtained an area-under-curve statistic of 0.81, and accuracy of 77.2% along with false-positive-rate of 0.11 on Drebin dataset. Mohit Sewak, Sanjay K. Sahay, Hemant Rathore |
PIMRC | 3 |
| 2020 | Adversarial attacks on malware detection models for smartphones using reinforcement learning: PhD forum abstractabstractMalware analysis and detection is a rat race between malware designer and anti-malware community. Most of the current Smartphone antivirus(s) are based on the signature, heuristic and behaviour based mechanisms which are unable to detect advanced polymorphic and metamorphic malware. Recently, researchers have developed state-of-the-art Android malware detection systems based on machine learning and deep learning. However, these models are prone to adversarial attacks which threaten the anti-malware ecosystem. Therefore in this work, we are investigating the robustness of Android malware detection models against adversarial attacks. We crafted adversarial attacks using reinforcement learning against detection models built using a variety of machine learning (classical, bagging, boosting) and deep learning algorithms. We are designing two adversarial attack strategies, namely single-policy and multi-policy attack for white-box and grey-box scenarios which are based on adversary's knowledge about the system. We designed the attack using Q-learning where a malicious application(s) is modified to generate variants which will force the detection models to misclassify them. The goal of the attack policy is to convert maximum Android applications (such that they are misclassified) with minimum modifications while maintaining the functional and behavioural integrity of applications. Preliminary results show an average fooling rate of around 40% across twelve distinct detection models based on different classification algorithms. We are also designing defence against these adversarial attack using model retraining and distillation. Hemant Rathore |
SenSys | 1 |
| 2020 | How robust are malware detection models for Android smartphones against adversarial attacks?: poster abstractabstractAndroid-based smartphones and IoT devices have grown at an exponential rate in the last decade. Meanwhile, malicious applications have also increased dramatically, which threaten the Android ecosystem. The anti-malware community has proposed data mining based malware detection models which have shown encouraging results. However, these detection models are vulnerable to adversarial attacks. In this work, we first acted as an adversary and performed adversarial attacks on eight different malware detection models. We found all the eight detection models vulnerable to adversarial attacks and fooling rate of more than 90% was achieved against each of them. We also propose defence against these attacks by adversarial retraining and accomplish encouraging results to improve the overall robustness of malware detection models. Hemant Rathore, Sanjay K. Sahay, Mohit Sewak |
SenSys | 1 |
| 2020 | Assessment of the Relative Importance of different hyper-parameters of LSTM for an IDSabstractRecurrent deep learning language models like the LSTM are often used to provide advanced cyber-defense for high-value assets. The underlying assumption for using LSTM networks for malware-detection is that the op-code sequence of a malware could be treated as a (spoken) language representation. There are differences between any spoken-language (sequence of words/sentences) and the machine-language (sequence of op-codes). In this paper we demonstrate that due to these inherent differences, an LSTM model with its default configuration as tuned for a spoken-language, may not work well to detect malware (using its op-code sequence) unless the network’s essential hyper-parameters are tuned appropriately. In the process, we also determine the relative importance of all the different hyper-parameters of an LSTM network as applied to malware detection using their op-code sequence representations. We experimented with different configurations of LSTM networks, and altered hyper-parameters like the embedding-size, number of hidden-layers, number of LSTM-units in a hidden layers, pruning/padding-length of the input-vector, activation-function, and batch-size. We discovered that owing to the enhanced complexity of the malware/machine-language, the performance of an LSTM network configured for an Intrusion Detection System, is very sensitive towards the number-of-hidden-layers, input sequence-length and the choice of the activation-function. Also, for (spoken) language-modeling, the recurrent architectures by-far outperforms their non-recurrent counterparts. Therefore, we also assess how sequential DL architectures like the LSTM compares against their non-sequential counterparts like the MLP-DNN for the purpose of malware-detection. Mohit Sewak, Sanjay K. Sahay, Hemant Rathore |
TENCON | 3 |
| 2020 | Socio-Cellular Network: A Novel Social Assisted Cellular Communication ParadigmabstractTo handle unprecedented mobile data demands in the next-generation 5G networks, dense deployments of base stations is the most promising solution. However, dense deployments not only leads to co-channel interference but also the underutilization of wireless resources in most scenarios. One way to maximize the gains of such deployments is to allow inter-operator collaborations where multiple operators can share their base stations and licensed spectrum with each other users. In addition to outdoor base stations, ultra-dense deployment of small cells such as femtocells inside homes/offices/public areas can further improve frequency reuse and system throughput. Femtocells are usually owned by end-users who are often reluctant to share them with other users due to trust and performance concerns. Hence, apart from operator collaboration, it is necessary to have collaborations among end-users to share femtocells. In this direction, we propose a unique cellular communication paradigm called Socio-Cellular Network along with an efficient cell selection scheme to facilitate operator and user collaborations to share base stations. Our simulation results show that collaborations among operators and end-users via social networks help to improve the performance of cellular networks in terms of throughput and energy efficiency. Swati Agarwal 0001, Rahul Thakur, Utkarsh Yadav, Hemant Rathore |
VTC Spring | 4 |
| 2018 | An investigation of a deep learning based malware detection systemabstractWe investigate a Deep Learning based system for malware detection. In the investigation, we experiment with different combination of Deep Learning architectures including Auto-Encoders, and Deep Neural Networks with varying layers over Malicia malware dataset on which earlier studies have obtained an accuracy of (98%) with an acceptable False Positive Rates (1.07%). But these results were done using extensive man-made custom domain features and investing corresponding feature engineering and design efforts. In our proposed approach, besides improving the previous best results (99.21% accuracy and an False Positive Rate of 0.19%) indicates that Deep Learning based systems could deliver an effective defense against malware. Since it is good in automatically extracting higher conceptual features from the data, Deep Learning based systems could provide an effective, general and scalable mechanism for detection of existing and unknown malware. Mohit Sewak, Sanjay K. Sahay, Hemant Rathore |
ARES | 3 |
| 2018 | Android Malicious Application Classification Using Clustering
Hemant Rathore, Sanjay K. Sahay, Palash Chaturvedi, Mohit Sewak |
ISDA (2) | 1 |
| 2018 | Comparison of Deep Learning and the Classical Machine Learning Algorithm for the Malware DetectionabstractRecently, Deep Learning has been showing promising results in various Artificial Intelligence applications like image recognition, natural language processing, language modeling, neural machine translation, etc. Although, in general, it is computationally more expensive as compared to classical machine learning techniques, their results are found to be more effective in some cases. Therefore, in this paper, we investigated and compared one of the Deep Learning Architecture called Deep Neural Network (DNN) with the classical Random Forest (RF) machine learning algorithm for the malware classification. We studied the performance of the classical RF and DNN with 2, 4 & 7 layers architectures with the four different feature sets, and found that irrespective of the features inputs, the classical RF accuracy outperforms the DNN. Mohit Sewak, Sanjay K. Sahay, Hemant Rathore |
SNPD | 3 |