ARTFEED — Contemporary Art Intelligence

Malware Detection Stability Under Feature Perturbations

other · 2026-07-29

A new study introduces a latent-stability analysis pipeline for assessing malware detector robustness under feature-space perturbations. The pipeline evaluates five representations: full EMBER features, PCA compression, beta/denoising variational autoencoders, Mandelbrot-inspired escape-time descriptors, and a PINN-style latent-flow module. A novel metric, Latent Escape Divergence (LED), quantifies changes in escape-time profiles, while PINNFlow-derived metrics (residual, velocity, risk, gradient-shift) characterize latent movement. Experiments use the EMBER dataset. The work addresses limitations of standard metrics like accuracy and F1, which fail to capture behavior near decision boundaries or in compressed spaces.

Key facts

  • Paper introduces latent-stability analysis pipeline for malware perturbation assessment in EMBER feature space.
  • Compares five representations: full EMBER features, PCA, beta/denoising VAE, Mandelbrot-inspired escape-time descriptors, PINN-style latent-flow module.
  • Defines Latent Escape Divergence (LED) to measure changes in escape-time profiles under perturbation.
  • Uses PINNFlow-derived metrics: residual, velocity, risk, gradient-shift.
  • Experiments conducted on EMBER dataset.
  • Addresses limitations of standard metrics (accuracy, F1, ROC AUC, PR AUC) for perturbation analysis.

Entities

Sources