{"id":"https://openalex.org/W3163429775","doi":"https://doi.org/10.1109/isqed51717.2021.9424310","title":"Monotonic-HMDs: Exploiting Monotonic Features to Defend Against Evasive Malware","display_name":"Monotonic-HMDs: Exploiting Monotonic Features to Defend Against Evasive Malware","publication_year":2021,"publication_date":"2021-04-07","ids":{"openalex":"https://openalex.org/W3163429775","doi":"https://doi.org/10.1109/isqed51717.2021.9424310","mag":"3163429775"},"language":"en","primary_location":{"id":"doi:10.1109/isqed51717.2021.9424310","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isqed51717.2021.9424310","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 22nd International Symposium on Quality Electronic Design (ISQED)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5092505798","display_name":"Md Shohidul Islam","orcid":"https://orcid.org/0000-0002-5102-8607"},"institutions":[{"id":"https://openalex.org/I4210144275","display_name":"Dhaka University of Engineering & Technology","ror":"https://ror.org/03qxvyy35","country_code":"BD","type":"education","lineage":["https://openalex.org/I4210144275"]},{"id":"https://openalex.org/I162714631","display_name":"George Mason University","ror":"https://ror.org/02jqj7156","country_code":"US","type":"education","lineage":["https://openalex.org/I162714631"]}],"countries":["BD","US"],"is_corresponding":true,"raw_author_name":"Md Shohidul Islam","raw_affiliation_strings":["Dhaka University of Engineering & Technology, Gazipur","George Mason University"],"affiliations":[{"raw_affiliation_string":"Dhaka University of Engineering & Technology, Gazipur","institution_ids":["https://openalex.org/I4210144275"]},{"raw_affiliation_string":"George Mason University","institution_ids":["https://openalex.org/I162714631"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020321835","display_name":"Behnam Omidi","orcid":"https://orcid.org/0000-0002-6724-2093"},"institutions":[{"id":"https://openalex.org/I162714631","display_name":"George Mason University","ror":"https://ror.org/02jqj7156","country_code":"US","type":"education","lineage":["https://openalex.org/I162714631"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Behnam Omidi","raw_affiliation_strings":["George Mason University"],"affiliations":[{"raw_affiliation_string":"George Mason University","institution_ids":["https://openalex.org/I162714631"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5037831461","display_name":"Khaled N. Khasawneh","orcid":"https://orcid.org/0000-0002-2116-2223"},"institutions":[{"id":"https://openalex.org/I162714631","display_name":"George Mason University","ror":"https://ror.org/02jqj7156","country_code":"US","type":"education","lineage":["https://openalex.org/I162714631"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Khaled N. Khasawneh","raw_affiliation_strings":["George Mason University"],"affiliations":[{"raw_affiliation_string":"George Mason University","institution_ids":["https://openalex.org/I162714631"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5092505798"],"corresponding_institution_ids":["https://openalex.org/I162714631","https://openalex.org/I4210144275"],"apc_list":null,"apc_paid":null,"fwci":0.9142,"has_fulltext":false,"cited_by_count":6,"citation_normalized_percentile":{"value":0.73461799,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":null,"issue":null,"first_page":"97","last_page":"102"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9962000250816345,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9944999814033508,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8227168321609497},{"id":"https://openalex.org/keywords/monotonic-function","display_name":"Monotonic function","score":0.8124732971191406},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7334288954734802},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7154380083084106},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.5435632467269897},{"id":"https://openalex.org/keywords/evasion","display_name":"Evasion (ethics)","score":0.5297176837921143},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.43794485926628113},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.43068182468414307},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.35454219579696655},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.09114858508110046}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8227168321609497},{"id":"https://openalex.org/C72169020","wikidata":"https://www.wikidata.org/wiki/Q194404","display_name":"Monotonic function","level":2,"score":0.8124732971191406},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7334288954734802},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7154380083084106},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.5435632467269897},{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.5297176837921143},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.43794485926628113},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.43068182468414307},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.35454219579696655},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.09114858508110046},{"id":"https://openalex.org/C8891405","wikidata":"https://www.wikidata.org/wiki/Q1059","display_name":"Immune system","level":2,"score":0.0},{"id":"https://openalex.org/C203014093","wikidata":"https://www.wikidata.org/wiki/Q101929","display_name":"Immunology","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isqed51717.2021.9424310","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isqed51717.2021.9424310","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 22nd International Symposium on Quality Electronic Design (ISQED)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W1945616565","https://openalex.org/W2034053858","https://openalex.org/W2113261561","https://openalex.org/W2132874238","https://openalex.org/W2134633067","https://openalex.org/W2166844173","https://openalex.org/W2201006485","https://openalex.org/W2285181575","https://openalex.org/W2292977173","https://openalex.org/W2295290223","https://openalex.org/W2344380211","https://openalex.org/W2625408821","https://openalex.org/W2625850712","https://openalex.org/W2766613627","https://openalex.org/W2793420030","https://openalex.org/W2809457377","https://openalex.org/W2883173712","https://openalex.org/W2911182009","https://openalex.org/W2945698147","https://openalex.org/W2950774332","https://openalex.org/W2963207607","https://openalex.org/W3007346474","https://openalex.org/W3117158982","https://openalex.org/W4256383029","https://openalex.org/W4293416593","https://openalex.org/W6640425456","https://openalex.org/W6696022951","https://openalex.org/W6696935964","https://openalex.org/W6697393818","https://openalex.org/W6757862169","https://openalex.org/W6764268162","https://openalex.org/W6788415604","https://openalex.org/W6838743003"],"related_works":["https://openalex.org/W4320018150","https://openalex.org/W2783112941","https://openalex.org/W2526398307","https://openalex.org/W4239582170","https://openalex.org/W2918664383","https://openalex.org/W106056076","https://openalex.org/W4320855730","https://openalex.org/W2135200719","https://openalex.org/W2470029541","https://openalex.org/W4387065217"],"abstract_inverted_index":{"Machine":[0],"learning-based":[1],"hardware":[2,205],"malware":[3,32,102,166],"detectors":[4],"(HMDs)":[5],"offer":[6,136],"a":[7,152],"potential":[8],"game-changing":[9],"advantage":[10],"in":[11,57,109,156],"defending":[12],"systems":[13],"against":[14,72,139],"malware.":[15,129,158],"However,":[16],"HMDs":[17,65],"suffer":[18],"from":[19,35],"adversarial":[20,73,140],"attacks;":[21],"they":[22,105],"can":[23,148,168],"be":[24,29,49,149],"effectively":[25],"reverse-engineered":[26],"and":[27,180,216],"subsequently":[28],"evaded,":[30],"allowing":[31],"to":[33,44,48,51,70,100,197,221],"hide":[34],"detection.":[36,53],"Adversarial":[37],"evasion":[38,74],"attacks":[39,141],"requires":[40],"adding":[41,97,115],"benign":[42,98],"features":[43,69,83,99,117],"the":[45,93,101,110,121,125,173,192,204,209],"program":[46,127],"execution":[47],"able":[50],"evade":[52,92,170],"Against":[54],"these":[55],"attacks,":[56],"this":[58,182],"paper,":[59],"we":[60],"propose":[61],"Monotonic-HMDs,":[62],"which":[63,147],"are":[64,78,106],"built":[66],"using":[67,80],"monotonic":[68,81],"defend":[71],"attacks.":[75,188],"Specifically,":[76],"Monotonic-HMDs":[77,86,135,175,190,210,213],"build":[79],"malicious":[82,116],"only.":[84],"Thus,":[85],"ensures":[87],"that":[88,134,163,167,212],"an":[89],"adversary":[90],"cannot":[91],"detection":[94,145,178],"by":[95,201],"simply":[96],"programs":[103],"since":[104],"not":[107],"used":[108],"Monotonic-HMD":[111],"model.":[112],"In":[113],"addition,":[114],"will":[118],"only":[119],"increase":[120],"probability":[122],"of":[123,208],"detecting":[124],"input":[126],"as":[128,151],"Our":[130],"experimental":[131],"results":[132,161,207],"demonstrate":[133],"effective":[137],"defense":[138],"without":[142],"sacrificing":[143],"significant":[144],"accuracy,":[146],"interpreted":[150],"cost":[153],"for":[154,164],"security":[155],"classifying":[157],"Importantly,":[159],"our":[160],"shows":[162,211],"evasive":[165],"completely":[169],"current":[171,222],"HMDs,":[172],"proposed":[174],"achieve":[176],"83%":[177],"accuracy":[179,183],"maintain":[181],"even":[184],"under":[185],"more":[186],"aggressive":[187],"Moreover,":[189],"reduce":[191],"inference":[193],"time,":[194],"i.e.,":[195],"time":[196],"perform":[198],"one":[199],"detection,":[200],"61.11%.":[202],"Furthermore,":[203],"implementation":[206],"offers":[214],"area":[215],"power":[217],"consumption":[218],"savings":[219],"compared":[220],"HMDs.":[223]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":4},{"year":2021,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
