EDBT 2026 Demo / reviewers in the wild / expert
Annamalai Narayanan
dblp:147/2783
· DBLP profile ↗
8ranked-venue papers
4as first author
0since 2021 · last 2019
0000-0001-8452-3703ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 3 first-authorSoftware engineering, systems software and programming languages · 3 · 1 first-authorSecurity and privacy · 1Databases, data management, data science and information retrieval · 1 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Malware analysis · 100% | |
| Databases, data mining, and information retrieval
1 paper |
Recommender systems · 56% Data mining · 44% |
Topics — the 7 heaviest of 7, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Recommender systems
multi-view representation learning |
0.3 | 1 | 2018 | Apk2vec: Semi-Supervised Multi-view Representation Learning for Profiling Android Applications · ICDM 2018 |
Data mining
representation learning |
0.3 | 1 | 2018 | Apk2vec: Semi-Supervised Multi-view Representation Learning for Profiling Android Applications · ICDM 2018 |
Malware analysis › android malware
android malware analysis |
0.2 | 1 | 2016 | Semantic modelling of Android malware for effective malware comprehension, detection, and classification · ISSTA 2016 |
Malware analysis
malware classification |
0.2 | 1 | 2016 | Semantic modelling of Android malware for effective malware comprehension, detection, and classification · ISSTA 2016 |
Malware analysis
malware detection |
0.2 | 1 | 2016 | Semantic modelling of Android malware for effective malware comprehension, detection, and classification · ISSTA 2016 |
Recommender systems › domain-specific recommendation
mobile app recommendation |
0.1 | 1 | 2018 | Apk2vec: Semi-Supervised Multi-view Representation Learning for Profiling Android Applications · ICDM 2018 |
Malware analysis › mobile malware detection
android malware detection |
0.1 | 1 | 2018 | Apk2vec: Semi-Supervised Multi-view Representation Learning for Profiling Android Applications · ICDM 2018 |
Methods — techniques the papers use, named apart from their topics
semi-supervised learning · 0.7online learning · 0.7feature hashing · 0.7semantic clone detection · 0.2deterministic symbolic automaton · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | Employee profiling via aspect-based sentiment and network for insider threats detectionabstractHistorically, the harm caused by insiders has proven to be one of the greatest concerns for any organization. As such, it has received considerable attention from both the industrial and research communities. Existing works mainly focused on modeling the employees’ normal biometric behavior (e.g., human to device interaction pattern) to detect anomalous behavior which corresponds to the insider activity. However, it is unattainable to stop the insider at the final moment when the malicious act is being carried out. In this paper, we propose a novel framework which performs employee profiling based on aspect-based sentiments and social network information and examine its applicability for early detection of potential insider threats. On the contrary to the traditional sentiment analysis , aspect-based sentiment analysis provides more fine-grained information on the employee. Our framework employs a combination of deep learning techniques such as Gated Recurrent Unit (GRU) and skipgram to build temporal sentiment profiles for the employees. It then performs anomaly detection on the profiles and ranks the employees based on their respective anomaly score. Due to the absence of relevant benchmark dataset, we augmented the publicly available real-world Enron email corpus with an insider threat scenario to evaluate our framework. The evaluation results demonstrate that the augmentation is indeed reflected in the augmented employee’s anomaly ranking (i.e., from normal to abnormal) and her close associates are indeed placed closely to her when the profiles are visualized in the 2D space. The profiles obtained from our framework can also be used to complement any existing expert and intelligent systems with additional capabilities in handling textual information such as, integration with profiles obtained from biometric behavior to form a more comprehensive threat detection system. Charlie Soh, Sicheng Yu, Annamalai Narayanan, Santhiya Duraisamy, Lihui Chen 0001 |
Expert Syst. Appl. | 3 |
| 2018 | Apk2vec: Semi-Supervised Multi-view Representation Learning for Profiling Android ApplicationsabstractBuilding behavior profiles of Android applications (apps) with holistic, rich and multi-view information (e.g., incorporating several semantic views of an app such as API sequences, system calls, etc.) would help catering downstream analytics tasks such as app categorization, recommendation and malware analysis significantly better. Towards this goal, we design a semisupervised Representation Learning (RL) framework named apk2vec to automatically generate a compact representation (aka profile/embedding) for a given app. More specifically, apk2vec has the three following unique characteristics which make it an excellent choice for large-scale app profiling: (1) it encompasses information from multiple semantic views such as API sequences, permissions, etc., (2) being a semi-supervised embedding technique, it can make use of labels associated with apps (e.g., malware family or app category labels) to build high quality app profiles, and (3) it combines RL and feature hashing which allows it to efficiently build profiles of apps that stream over time (i.e., online learning). The resulting semi-supervised multi-view hash embeddings of apps could then be used for a wide variety of downstream tasks such as the ones mentioned above. Our extensive evaluations with more than 42,000 apps demonstrate that apk2vec's app profiles could significantly outperform state-of-the-art techniques in four app analytics tasks namely, malware detection, familial clustering, app clone detection and app recommendation. Annamalai Narayanan, Charlie Soh, Lihui Chen 0001, Yang Liu 0003, Lipo Wang 0001 |
ICDM | 1 |
| 2018 | A multi-view context-aware approach to Android malware detection and malicious code localization
Annamalai Narayanan, Mahinthan Chandramohan, Lihui Chen 0001, Yang Liu 0003 |
Empir. Softw. Eng. | 1 |
| 2016 | LibSift: Automated Detection of Third-Party Libraries in Android ApplicationsabstractAndroid applications typically contain multiple third-party libraries and recent studies have shown that the presence of third-party libraries may introduce privacy risks and security threats. Furthermore, researchers have reported the importance of considering the third-party libraries for their program analysis tasks. A reason being that the presence of third-party libraries may dilute the features and affect the accuracy of their results. Existing literature typically employs a whitelist to exclude the third-party libraries from their analysis in order to achieve accurate results. However, these whitelists are generally incomplete and weak against the renaming obfuscation technique that is commonly employed in Android applications. In this paper, we propose LibSift, a tool to automatically detect third-party libraries in Android applications. LibSift detects third-party libraries based on package dependencies that are resilient to most common obfuscations. The evaluation results not only indicate that LibSift can detect third-party libraries accurately and effectively, but also show that LibSift can detect even the less popular libraries that are not detected by two of the state-of-the-art approaches. Charlie Soh, Hee Beng Kuan Tan, Yauhen Arnatovich, Annamalai Narayanan, Lipo Wang 0001 |
APSEC | 4 |
| 2016 | Mystique: Evolving Android Malware for Auditing Anti-Malware ToolsabstractIn the arms race of attackers and defenders, the defense is usually more challenging than the attack due to the unpredicted vulnerabilities and newly emerging attacks every day. Currently, most of existing malware detection solutions are individually proposed to address certain types of attacks or certain evasion techniques. Thus, it is desired to conduct a systematic investigation and evaluation of anti-malware solutions and tools based on different attacks and evasion techniques. In this paper, we first propose a meta model for Android malware to capture the common attack features and evasion features in the malware. Based on this model, we develop a framework, MYSTIQUE, to automatically generate malware covering four attack features and two evasion features, by adopting the software product line engineering approach. With the help of MYSTIQUE, we conduct experiments to 1) understand Android malware and the associated attack features as well as evasion techniques; 2) evaluate and compare the 57 off-the-shelf anti-malware tools, 9 academic solutions and 4 App market vetting processes in terms of accuracy in detecting attack features and capability in addressing evasion. Last but not least, we provide a benchmark of Android malware with proper labeling of contained attack and evasion features. Guozhu Meng, Yinxing Xue, Mahinthan Chandramohan, Annamalai Narayanan, Yang Liu 0003, Jie Zhang 0002, Tieming Chen |
AsiaCCS | 4 |
| 2016 | Adaptive and scalable Android malware detection through online learningabstractIt is well-known that malware constantly evolves so as to evade detection and this causes the entire malware population to be non-stationary. Contrary to this fact, prior works on machine learning based Android malware detection have assumed that the distribution of the observed malware characteristics (i.e., features) do not change over time. In this work, we address the problem of malware population drift and propose a novel online machine learning based framework, named DroidOL to handle it and effectively detect malware. In order to perform accurate detection, security-sensitive behavior are captured from apps in form of inter-procedural control-flow sub-graph features using a state-of-the-art graph kernel. In order to perform scalable detection and to adapt to the drift and evolution in malware population, an online passive-aggressive classifier is used. In a large-scale comparative analysis with more than 87,000 apps, DroidOL achieves 84.29% accuracy outperforming two state-of-the-art malware techniques by more than 20% in their typical batch learning setting and more than 3% when they are continuously re-trained. Our experimental findings strongly indicate that online learning based approaches are highly suitable for real-world malware detection. Annamalai Narayanan, Yang Liu 0003, Lihui Chen 0001 |
IJCNN | 1 |
| 2016 | Contextual Weisfeiler-Lehman graph kernel for malware detectionabstractIn this paper, we propose a novel graph kernel specifically to address a challenging problem in the field of cyber-security, namely, malware detection. Previous research has revealed the following: (1) Graph representations of programs are ideally suited for malware detection as they are robust against several attacks, (2) Besides capturing topological neighbourhoods (i.e., structural information) from these graphs it is important to capture the context under which the neighbourhoods are reachable to accurately detect malicious neighbourhoods. We observe that state-of-the-art graph kernels, such as Weisfeiler-Lehman kernel (WLK) capture the structural information well but fail to capture contextual information. To address this, we develop the Contextual Weisfeiler-Lehman kernel (CWLK) which is capable of capturing both these types of information. We show that for the malware detection problem, CWLK is more expressive and hence more accurate than WLK while maintaining comparable efficiency. Through our largescale experiments with more than 50,000 real-world Android apps, we demonstrate that CWLK outperforms two state-of-the-art graph kernels (including WLK) and three malware detection techniques by more than 5.27% and 4.87% F-measure, respectively, while maintaining high efficiency. This high accuracy and efficiency make CWLK suitable for large-scale real-world malware detection. Annamalai Narayanan, Guozhu Meng, Yang Liu 0003, Lihui Chen 0001 |
IJCNN | 1 |
| 2016 | Semantic modelling of Android malware for effective malware comprehension, detection, and classificationabstractMalware has posed a major threat to the Android ecosystem. Existing malware detection tools mainly rely on signature- or feature- based approaches, failing to provide detailed information beyond the mere detection. In this work, we propose a precise semantic model of Android malware based on Deterministic Symbolic Automaton (DSA) for the purpose of malware comprehension, detection and classification. It shows that DSA can capture the common malicious behaviors of a malware family, as well as the malware variants. Based on DSA, we develop an automatic analysis framework, named SMART, which learns DSA by detecting and summarizing semantic clones from malware families, and then extracts semantic features from the learned DSA to classify malware according to the attack patterns. We conduct the experiments in both malware benchmark and 223,170 real-world apps. The results show that SMART builds meaningful semantic models and outperforms both state-of-the-art approaches and anti-virus tools in malware detection. SMART identifies 4583 new malware in real-world apps that are missed by most anti-virus tools. The classification step further identifies new malware variants and unknown families. Guozhu Meng, Yinxing Xue, Zhengzi Xu, Yang Liu 0003, Jie Zhang 0002, Annamalai Narayanan |
ISSTA | 6 |