{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T17:43:22Z","timestamp":1777657402795,"version":"3.51.4"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"18","license":[{"start":{"date-parts":[[2020,7,28]],"date-time":"2020-07-28T00:00:00Z","timestamp":1595894400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,7,28]],"date-time":"2020-07-28T00:00:00Z","timestamp":1595894400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Neural Comput &amp; Applic"],"published-print":{"date-parts":[[2020,9]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Label manipulation attacks are a subclass of data poisoning attacks in adversarial machine learning used against different applications, such as malware detection. These types of attacks represent a serious threat to detection systems in environments having high noise rate or uncertainty, such as complex networks and Internet of Thing (IoT). Recent work in the literature has suggested using the <jats:italic>K<\/jats:italic>-nearest neighboring algorithm to defend against such attacks. However, such an approach can suffer from low to miss-classification rate accuracy. In this paper, we design an architecture to tackle the Android malware detection problem in IoT systems. We develop an attack mechanism based on silhouette clustering method, modified for mobile Android platforms. We proposed two convolutional neural network-type deep learning algorithms against this <jats:italic>Silhouette Clustering-based Label Flipping Attack<\/jats:italic>. We show the effectiveness of these two defense algorithms\u2014<jats:italic>label-based semi-supervised defense<\/jats:italic> and <jats:italic>clustering-based semi-supervised defense<\/jats:italic>\u2014in correcting labels being attacked. We evaluate the performance of the proposed algorithms by varying the various machine learning parameters on three Android datasets: Drebin, Contagio, and Genome and three types of features: API, intent, and permission. Our evaluation shows that using random forest feature selection and varying ratios of features can result in an improvement of up to 19% accuracy when compared with the state-of-the-art method in the literature.<\/jats:p>","DOI":"10.1007\/s00521-020-04831-9","type":"journal-article","created":{"date-parts":[[2020,3,17]],"date-time":"2020-03-17T13:02:47Z","timestamp":1584450167000},"page":"14781-14800","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":77,"title":["On defending against label flipping attacks on malware detection systems"],"prefix":"10.1007","volume":"32","author":[{"given":"Rahim","family":"Taheri","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Reza","family":"Javidan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Shojafar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zahra","family":"Pooranian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ali","family":"Miri","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,7,28]]},"reference":[{"key":"4831_CR1","first-page":"23","volume":"14","author":"D Arp","year":"2014","unstructured":"Arp D, Spreitzenbarth M, Hubner M, Gascon H, Rieck K, Siemens C (2014) Drebin: effective and explainable detection of android malware in your pocket. Ndss 14:23\u201326","journal-title":"Ndss"},{"key":"4831_CR2","unstructured":"Aviles-Rivero AI, Papadakis N, Li R, Alsaleh SM, Tan RT, Schonlieb CB (2019) Beyond supervised classification: extreme minimal supervision with the graph 1-Laplacian. arXiv:1906.08635"},{"key":"4831_CR3","doi-asserted-by":"crossref","unstructured":"Baracaldo N, Chen B, Ludwig H, Safavi A, Zhang R (2018) Detecting poisoning attacks on machine learning in IoT environments. In: 2018 IEEE international congress on internet of things (ICIOT). IEEE, pp 57\u201364","DOI":"10.1109\/ICIOT.2018.00015"},{"key":"4831_CR4","unstructured":"Bhagoji AN, Cullina D, Mittal P (2017) Dimensionality reduction as a defense against evasion attacks on machine learning classifiers. arXiv:1704.02654"},{"key":"4831_CR5","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1016\/j.neucom.2015.12.106","volume":"192","author":"J Bootkrajang","year":"2016","unstructured":"Bootkrajang J (2016) A generalised label noise model for classification in the presence of annotation errors. Neurocomputing 192:61\u201371","journal-title":"Neurocomputing"},{"issue":"11","key":"4831_CR6","doi-asserted-by":"publisher","first-page":"3641","DOI":"10.1016\/j.patcog.2014.05.007","volume":"47","author":"J Bootkrajang","year":"2014","unstructured":"Bootkrajang J, Kab\u00e1n A (2014) Learning kernel logistic regression in the presence of class label noise. Pattern Recognit 47(11):3641\u20133655","journal-title":"Pattern Recognit"},{"key":"4831_CR7","doi-asserted-by":"crossref","unstructured":"Bootkrajang J, Kab\u00e1n A (2012) Label-noise robust logistic regression and its applications. In: Joint European conference on machine learning and knowledge discovery in databases. Springer, pp 143\u2013158","DOI":"10.1007\/978-3-642-33460-3_15"},{"key":"4831_CR8","unstructured":"Contagio Dataset (2020) http:\/\/contagiominidump.blogspot.com\/. Accessed 22 Feb 2020"},{"key":"4831_CR9","doi-asserted-by":"crossref","unstructured":"Dong-DongChen W, WeiGao ZH (2018) Tri-net for semi-supervised deep learning. In: Proceedings of twenty-seventh international joint conference on artificial intelligence, pp 2014\u20132020","DOI":"10.24963\/ijcai.2018\/278"},{"key":"4831_CR10","unstructured":"Fr\u00e9nay B, Kab\u00e1n A et al (2014) A comprehensive introduction to label noise. In: ESANN, pp 667\u2013676"},{"issue":"1","key":"4831_CR11","first-page":"2030","volume":"17","author":"Y Ganin","year":"2016","unstructured":"Ganin Y, Ustinova E, Ajakan H, Germain P, Larochelle H, Laviolette F, Marchand M, Lempitsky V (2016) Domain-adversarial training of neural networks. J Mach Learn Res 17(1):2030\u20132096","journal-title":"J Mach Learn Res"},{"key":"4831_CR12","unstructured":"Guo B, Tian L, Zhang J, Zhang Y, Yu L, Zhang J, Liu Z (2019) A clustering algorithm based on joint kernel density for millimeter wave radio channels. In: 2019 13th European conference on antennas and propagation (EuCAP). IEEE, pp 1\u20135"},{"key":"4831_CR13","doi-asserted-by":"crossref","unstructured":"He K, Sun J (2015) Convolutional neural networks at constrained time cost. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 5353\u20135360","DOI":"10.1109\/CVPR.2015.7299173"},{"issue":"3","key":"4831_CR14","doi-asserted-by":"publisher","first-page":"360","DOI":"10.1109\/TIP.2004.838691","volume":"14","author":"K Hirakawa","year":"2005","unstructured":"Hirakawa K, Parks TW (2005) Adaptive homogeneity-directed demosaicing algorithm. IEEE Trans Image Process 14(3):360\u2013369","journal-title":"IEEE Trans Image Process"},{"key":"4831_CR15","doi-asserted-by":"crossref","unstructured":"Iscen A, Tolias G, Avrithis Y, Chum O (2019) Label propagation for deep semi-supervised learning. In: Proceedings of the IEEE conference on computer vision and pattern recognition, pp 5070\u20135079","DOI":"10.1109\/CVPR.2019.00521"},{"key":"4831_CR16","doi-asserted-by":"crossref","unstructured":"Jiang X, Zhou Y (2012) Dissecting android malware: characterization and evolution. In: Proceedings of IEEE S&P, pp 95\u2013109","DOI":"10.1109\/SP.2012.16"},{"key":"4831_CR17","unstructured":"Kaiser \u0141, Sutskever I (2015) Neural gpus learn algorithms. arXiv:1511.08228"},{"key":"4831_CR18","unstructured":"Label Propagation (2020) https:\/\/scikit-learn.org\/stable\/modules\/label_propagation.html. Accessed 22 Feb 2020"},{"key":"4831_CR19","unstructured":"Laishram R, Phoha VV (2016) Curie: a method for protecting SVM classifier from poisoning attack. arXiv:1606.01584"},{"issue":"1","key":"4831_CR20","first-page":"175","volume":"37","author":"YF Li","year":"2014","unstructured":"Li YF, Zhou ZH (2014) Towards making unlabeled data never hurt. IEEE Trans Pattern Anal Mach Intell 37(1):175\u2013188","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"4831_CR21","unstructured":"Maclaurin D, Duvenaud D, Adams R (2015) Gradient-based hyperparameter optimization through reversible learning. In: International conference on machine learning, pp 2113\u20132122"},{"key":"4831_CR22","doi-asserted-by":"crossref","unstructured":"Mu\u00f1oz-Gonz\u00e1lez L, Biggio B, Demontis A, Paudice A, Wongrassamee V, Lupu EC, Roli F (2017) Towards poisoning of deep learning algorithms with back-gradient optimization. In: Proceedings of the 10th ACM workshop on artificial intelligence and security. ACM, pp 27\u201338","DOI":"10.1145\/3128572.3140451"},{"key":"4831_CR23","unstructured":"Mutual Information (2020) https:\/\/nlp.stanford.edu\/IR-book\/html\/htmledition\/mutual-information-1.html. Accessed 22 Feb 2020"},{"key":"4831_CR24","unstructured":"Natarajan N, Dhillon IS, Ravikumar PK, Tewari A (2013) Learning with noisy labels. In: Advances in neural information processing systems, pp 1196\u20131204"},{"key":"4831_CR25","doi-asserted-by":"crossref","unstructured":"Papernot N et\u00a0al (2016) Distillation as a defense to adversarial perturbations against deep neural networks. In: Proceedings of IEEE S&P, pp 582\u2013597","DOI":"10.1109\/SP.2016.41"},{"key":"4831_CR26","doi-asserted-by":"crossref","unstructured":"Paudice A, Mu\u00f1oz-Gonz\u00e1lez L, Lupu EC (2018) Label sanitization against label flipping poisoning attacks. In: Joint European conference on machine learning and knowledge discovery in databases. Springer, pp 5\u201315","DOI":"10.1007\/978-3-030-13453-2_1"},{"issue":"336","key":"4831_CR27","doi-asserted-by":"publisher","first-page":"846","DOI":"10.1080\/01621459.1971.10482356","volume":"66","author":"WM Rand","year":"1971","unstructured":"Rand WM (1971) Objective criteria for the evaluation of clustering methods. J Am Stat Assoc 66(336):846\u2013850","journal-title":"J Am Stat Assoc"},{"key":"4831_CR28","unstructured":"Ren M, Zeng W, Yang B, Urtasun R (2018) Learning to reweight examples for robust deep learning. arXiv:1803.09050"},{"key":"4831_CR29","unstructured":"Shafahi A, Huang WR, Najibi M, Suciu O, Studer C, Dumitras T, Goldstein T (2018) Poison frogs! targeted clean-label poisoning attacks on neural networks. In: Advances in neural information processing systems, pp 6103\u20136113"},{"key":"4831_CR30","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-020-03083-5","author":"R Taheri","year":"2020","unstructured":"Taheri R, Javidan R, Shojafar M, Conti M et\u00a0al (2020) Can machine learning model with static features be fooled: an adversarial machine learning approach. Cluster Comput.\u00a0https:\/\/doi.org\/10.1007\/s10586-020-03083-5","journal-title":"Cluster Comput"},{"key":"4831_CR31","unstructured":"Taheri R, Shojafar M (2020) Source code of label flipping attack\/defenses on android data. https:\/\/github.com\/mshojafar\/sourcecodes\/blob\/master\/Taheri%20et%20al-NCAA2020.zip. Accessed 22 Feb 2020"},{"key":"4831_CR32","unstructured":"Wang Y, Chaudhuri K (2018) Data poisoning attacks against online learning. arXiv:1808.08994"},{"key":"4831_CR33","unstructured":"Xia Y, Liu F, Yang D, Cai J, Yu L, Zhu Z, Xu D, Yuille A, Roth H (2018) 3D semi-supervised learning with uncertainty-aware multi-view co-training. arXiv:1811.12506"},{"key":"4831_CR34","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/j.neucom.2014.08.081","volume":"160","author":"H Xiao","year":"2015","unstructured":"Xiao H, Biggio B, Nelson B, Xiao H, Eckert C, Roli F (2015) Support vector machines under adversarial label contamination. Neurocomputing 160:53\u201362","journal-title":"Neurocomputing"},{"key":"4831_CR35","unstructured":"Xiao H, Biggio B, Brown G, Fumera G, Eckert C, Roli F (2015) Is feature selection secure against training data poisoning? In: International conference on machine learning, pp 1689\u20131698"},{"key":"4831_CR36","unstructured":"Yang C, Wu Q, Li H, Chen Y (2017) Generative poisoning attack method against neural networks. arXiv:1703.01340"},{"issue":"3","key":"4831_CR37","doi-asserted-by":"publisher","first-page":"766","DOI":"10.1109\/TCYB.2015.2415032","volume":"46","author":"F Zhang","year":"2016","unstructured":"Zhang F, Chan PP, Biggio B, Yeung DS, Roli F (2016) Adversarial feature selection against evasion attacks. IEEE Trans Cybernet 46(3):766\u2013777","journal-title":"IEEE Trans Cybernet"},{"key":"4831_CR38","doi-asserted-by":"crossref","unstructured":"Zhou Y, Kantarcioglu M, Thuraisingham B, Xi B (2012) Adversarial support vector machine learning. In: Proceedings of the 18th ACM SIGKDD international conference on Knowledge discovery and data mining. ACM, pp 1059\u20131067","DOI":"10.1145\/2339530.2339697"}],"updated-by":[{"DOI":"10.1007\/s00521-020-04904-9","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2020,4,18]],"date-time":"2020-04-18T00:00:00Z","timestamp":1587168000000}},{"DOI":"10.1007\/s00521-020-05043-x","type":"correction","label":"Correction","source":"publisher","updated":{"date-parts":[[2020,6,5]],"date-time":"2020-06-05T00:00:00Z","timestamp":1591315200000}}],"container-title":["Neural Computing and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-020-04831-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s00521-020-04831-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s00521-020-04831-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,7,27]],"date-time":"2021-07-27T23:38:32Z","timestamp":1627429112000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s00521-020-04831-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,28]]},"references-count":38,"journal-issue":{"issue":"18","published-print":{"date-parts":[[2020,9]]}},"alternative-id":["4831"],"URL":"https:\/\/doi.org\/10.1007\/s00521-020-04831-9","relation":{},"ISSN":["0941-0643","1433-3058"],"issn-type":[{"value":"0941-0643","type":"print"},{"value":"1433-3058","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,7,28]]},"assertion":[{"value":"23 July 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 March 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 July 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 July 2020","order":4,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Update","order":5,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Publisher's Note: two Corrections containing incorrect information about the licensing terms for this article have been removed.","order":6,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Compliance with ethical standards"}},{"value":"There is no conflict of interest for the paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}