Skip to main navigation Skip to search Skip to main content

Mitigating emergent malware label noise in DNN-based Android malware detection

Haodong Li, Xiao Cheng, Guohan Zhang*, Guosheng Xu, Guoai Xu, Haoyu Wang*

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

507 Downloads (Pure)

Abstract

Learning-based Android malware detection has earned significant recognition across industry and academia, yet its effectiveness hinges on the accuracy of labeled training data. Manual labeling, being prohibitively expensive, has prompted the use of automated methods, such as leveraging anti-virus engines like VirusTotal, which unfortunately introduces mislabeling, aka "label noise". The state-of-the-art label noise reduction approach, MalWhiteout, can effectively reduce random label noise but underperforms in mitigating real-world emergent malware (EM) label noise stemming from newly emerging Android malware variants overlooked by VirusTotal. To tackle this, we conceptualize EM label noise detection as an anomaly detection problem and introduce a novel tool, MalCleanse, that surpasses MalWhiteout's ability to address EM label noise. MalCleanse combines uncertainty estimation with unsupervised anomaly detection, identifying samples with high uncertainty as mislabeled, thereby enhancing its capability to remove EM label noise. Our experimental results demonstrate a significant reduction in EM label noise by approximately 25.25%, achieving an F1 Score of 80.32% for label noise detection at a noise ratio of 40.61%. Notably, MalCleanse outperforms MalWhiteout with an increase of 40.9% in overall F1 score for mitigating EM label noise. This paper pioneers the integration of deep neural network model uncertainty to refine label accuracy, thereby enhancing the reliability of malware detection systems. Our approach represents a significant step forward in addressing the challenges posed by emergent malware in automated labeling systems.
Original languageEnglish
Article numberFSE052
Pages (from-to)1-24
Number of pages24
JournalProceedings of the ACM on Software Engineering
Volume2
Issue numberFSE
DOIs
Publication statusPublished - Jul 2025
Externally publishedYes

Bibliographical note

Copyright the Author(s) 2025. Version archived for private and non-commercial use with the permission of the author/s and according to publisher conditions. For further rights please contact the publisher.

Keywords

  • Label noise
  • Android malware dataset
  • Uncertainty

Fingerprint

Dive into the research topics of 'Mitigating emergent malware label noise in DNN-based Android malware detection'. Together they form a unique fingerprint.

Cite this