McFadden, Shae;
Kan, Zeliang;
Cavallaro, Lorenzo;
Pierazzi, Fabio;
(2025)
The Impact of Active Learning on Availability Data Poisoning for Android Malware Classifiers.
In:
2024 Annual Computer Security Applications Conference Workshops (ACSAC Workshops).
(pp. pp. 73-84).
IEEE: Honolulu, HI, USA.
Preview |
Text
rpal_artman.pdf - Accepted Version Download (743kB) | Preview |
Abstract
Can a poisoned machine learning (ML) model passively recover from its adversarial manipulation by retraining with new samples, and regain non-poisoned performance? And if passive recovery is possible, how can it be quantified? From an adversarial perspective, is a small amount of poisoning sufficient to force the defender to retrain more over time?This paper proposes the evaluation of passive recovery from "availability data poisoning" using active learning in the context of Android malware detection. To quantify passive recovery, we propose two metrics: intercept to assess the speed of recovery, and recovery rate to quantify the stability of recovery. To investigate passive recovery, we conduct our experiments at different rates of active learning, in conjunction with varying strengths of availability data poisoning. We perform our evaluation on 259,230 applications from AndroZoo, using the Drebin feature representation, with linear SVM, DNN, and Random Forest as classifiers. Our findings show the convergence of the poisoned models to their respective hypothetical non-poisoned models. Therefore, demonstrating that through the use of active learning as a concept drift mitigation strategy, passive recovery is feasible across the three classifiers evaluated.
| Type: | Proceedings paper |
|---|---|
| Title: | The Impact of Active Learning on Availability Data Poisoning for Android Malware Classifiers |
| Event: | 2024 Annual Computer Security Applications Conference Workshops (ACSAC Workshops) |
| Dates: | 9 Dec 2024 - 10 Dec 2024 |
| ISBN-13: | 979-8-3315-3281-9 |
| Open access status: | An open access version is available from UCL Discovery |
| DOI: | 10.1109/ACSACW65225.2024.00016 |
| Publisher version: | https://doi.org/10.1109/acsacw65225.2024.00016 |
| Language: | English |
| Additional information: | This version is the author accepted manuscript. For information on re-use, please refer to the publisher’s terms and conditions. |
| Keywords: | Supervised learning, malware detection, poisoning, active learning, passive recovery |
| UCL classification: | UCL UCL > Provost and Vice Provost Offices > UCL BEAMS UCL > Provost and Vice Provost Offices > UCL BEAMS > Faculty of Engineering Science > Dept of Computer Science |
| URI: | https://discovery.ucl.ac.uk/id/eprint/10208029 |
Archive Staff Only
![]() |
View Item |

