Dylan Zapzalka

dblp:396/8624 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2025
—ORCID · unresolved

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
1 paper
Trustworthy machine learning · 100%
Network and information security
1 paper
Security and privacy of machine learning · 62% Malware analysis · 38%
Interdisciplinary, comprehensive, and emerging computing
1 paper
Computational social science and digital humanities · 100%

Topics — the 8 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › fairness
causal fairness
0.912025
Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025
Machine learning › Trustworthy machine learning
fairness
0.912025
Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025
Machine learning › Trustworthy machine learning
strategic behavior
0.912025
Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025
Machine learning › Trustworthy machine learning › performative prediction
strategic classification
0.912025
Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025
Computational social science and digital humanities
algorithmic decision-making
0.912025
Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025
Security and privacy of machine learning
adversarial example
0.912025
Semantics-Preserving Node Injection Attacks Against GNN-Based ACFG Malware Classifiers · IEEE Trans. Dependable Secur. Comput. 2025
Malware analysis › graph-based malware analysis
control flow graph analysis
0.312025
Semantics-Preserving Node Injection Attacks Against GNN-Based ACFG Malware Classifiers · IEEE Trans. Dependable Secur. Comput. 2025
Malware analysis
malware detection
0.312025
Semantics-Preserving Node Injection Attacks Against GNN-Based ACFG Malware Classifiers · IEEE Trans. Dependable Secur. Comput. 2025

Methods — techniques the papers use, named apart from their topics

identifiability analysis · 1.7causal inference · 1.7node injection · 0.9attributed control flow graph · 0.9
YearPublicationVenuePosition
2025 Disentangling misreporting from genuine adaptation in strategic settings: a causal approach
abstract
In settings where ML models are used to inform the allocation of resources, agents affected by the allocation decisions might have an incentive to strategically change their features to secure better outcomes. While prior work has studied strategic responses broadly, disentangling misreporting from genuine adaptation remains a fundamental challenge. In this paper, we propose a causally-motivated approach to identify and quantify how much an agent misreports on average by distinguishing deceptive changes in their features from genuine adaptation. Our key insight is that, unlike genuine adaptation, misreported features do not causally affect downstream variables (i.e., causal descendants). We exploit this asymmetry by comparing the causal effect of misreported features on their causal descendants as derived from manipulated datasets against those from unmanipulated datasets. We formally prove identifiability of the misreporting rate and characterize the variance of our estimator. We empirically validate our theoretical results using a semi-synthetic and real Medicare dataset with misreported data, demonstrating that our approach can be employed to identify misreporting in real-world scenarios.
Dylan Zapzalka, Trenton Chang, Lindsay A. Warrenburg, Sae-Hwan Park, Daniel K. Shenfeld, Ravi B. Parikh, Jenna Wiens, Maggie Makar
NeurIPS1
2025 Semantics-Preserving Node Injection Attacks Against GNN-Based ACFG Malware Classifiers
abstract
To increase security for devices connected to the internet, research has gone into using Graph Neural Networks (GNNs) to inhibit the spread of malware through detection. GNN classifiers that use Attributed Control Flow Graphs (ACFGs) have demonstrated favorable results in classifying software binaries as malicious or benign. In this work, we show that such classifiers are vulnerable to Adversarial Examples (AEs) by proposing several grey-box adversarial attacks that perform node injection and preserve the semantics of a program. We demonstrate that adversaries can take advantage of the aggregation properties of GNNs to apply effective perturbation outside of the original ACFG nodes of a software binary through node injection. We conducted experiments on our methods and compared them against two similar semantics-preserving adversarial attacks. Our results have shown that our methods of applying perturbation through node injection can result in higher evasion rates while decreasing the amount of perturbation needed to fool detectors. Namely, we deliver an evasion rate of up to 94.83% with only 2.49% of total perturbation, in comparison with a maximum evasion of 79.50% at 2.78% perturbation by a state-of-the-art approach and only 27.44% at 2.95% perturbation by the baseline attack. Our results highlight the need for creating more robust GNN malware detectors.
Dylan Zapzalka, Saeed Salem, David Mohaisen
IEEE Trans. Dependable Secur. Comput.1