EDBT 2026 Demo / reviewers in the wild / expert
Jan Brabec
dblp:232/1723
· DBLP profile ↗
4ranked-venue papers in the field
0as first author
4since 2021 · last 2022
0000-0002-9781-0645ORCID · corroborated
Domains — venue-derived; a paper can count in several
Data Mining & Knowledge Discovery · 2Big Data, Cloud & Distributed Data Systems · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Benchmark of Data Preprocessing Methods for Imbalanced ClassificationabstractSevere class imbalance is one of the main conditions that make machine learning in cybersecurity difficult. A variety of dataset preprocessing methods have been introduced over the years. These methods modify the training dataset by oversampling, undersampling or a combination of both to improve the predictive performance of classifiers trained on this dataset. Although these methods are used in cybersecurity occasionally, a comprehensive, unbiased benchmark comparing their performance over a variety of cybersecurity problems is missing. This paper presents a benchmark of 16 preprocessing methods on six cybersecurity datasets together with 17 public imbalanced datasets from other domains. We test the methods under multiple hyperparameter configurations and use an AutoML system to train classifiers on the preprocessed datasets, which reduces potential bias from specific hyperparameter or classifier choices. Special consideration is also given to evaluating the methods using appropriate performance measures that are good proxies for practical performance in real-world cybersecurity systems. The main findings of our study are: 1) Most of the time, a data preprocessing method that improves classification performance exists. 2) Baseline approach of doing nothing outperformed a large portion of methods in the benchmark. 3) Oversampling methods generally outperform undersampling methods. 4) The most significant performance gains are brought by the standard SMOTE algorithm and more complicated methods provide mainly incremental improvements at the cost of often worse computational performance. Radovan Haluska, Jan Brabec, Tomás Komárek |
IEEE Big Data | 2 |
| 2021 | Threat Hunting as a Similarity Search Problem on Multi-positive and Unlabeled DataabstractWe present a new similarity search method (called Random Separations) that helps threat analysts with identification of unknown variants of known malware in network traffic. The method assumes that for each hunted malware family, few samples of network communication are available to analysts (multi-positive) and others are hidden in abundant (unlabeled) network data. We demonstrate the method on large-scale real-world data, where it outperforms the unsupervised approach (Isolation Forest and Lightweight Online Detector of Anomalies), the supervised approach (Random Forest) and the traditional similarity search algorithm (kNN). The evaluation involves eight high-risk malware families under various known/unknown ratios. Tomás Komárek, Jan Brabec, Cenek Skarda, Petr Somol |
IEEE BigData | 2 |
| 2021 | Explainable Multiple Instance Learning with Instance Selection Randomized Trees
Tomás Komárek, Jan Brabec, Petr Somol |
ECML/PKDD (2) | 2 |
| 2021 | Learning Explainable Representations of Malware Behavior
Paul Prasse, Jan Brabec, Jan Kohout, Martin Kopp, Lukás Bajer, Tobias Scheffer |
ECML/PKDD (4) | 2 |