{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T03:40:42Z","timestamp":1780458042761,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":66,"publisher":"ACM","license":[{"start":{"date-parts":[[2016,10,16]],"date-time":"2016-10-16T00:00:00Z","timestamp":1476576000000},"content-version":"vor","delay-in-days":366,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["FA8750-12-2-0331"],"award-info":[{"award-number":["FA8750-12-2-0331"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"name":"US State Department DRL"},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["0424422,1139158"],"award-info":[{"award-number":["0424422,1139158"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006235","name":"Lawrence Berkely National Laboratory","doi-asserted-by":"publisher","award":["7076018"],"award-info":[{"award-number":["7076018"]}],"id":[{"id":"10.13039\/100006235","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Intel Science and Technology Center for Secure Computing"},{"name":"Freedom 2 Connect Foundation"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2015,10,16]]},"DOI":"10.1145\/2808769.2808780","type":"proceedings-article","created":{"date-parts":[[2015,10,6]],"date-time":"2015-10-06T11:22:12Z","timestamp":1444130532000},"page":"45-56","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":65,"title":["Better Malware Ground Truth"],"prefix":"10.1145","author":[{"given":"Alex","family":"Kantchelian","sequence":"first","affiliation":[{"name":"UC Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael Carl","family":"Tschantz","sequence":"additional","affiliation":[{"name":"International Computer Science Institute, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sadia","family":"Afroz","sequence":"additional","affiliation":[{"name":"UC Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Brad","family":"Miller","sequence":"additional","affiliation":[{"name":"UC Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vaishaal","family":"Shankar","sequence":"additional","affiliation":[{"name":"UC Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rekha","family":"Bachwani","sequence":"additional","affiliation":[{"name":"Netflix, San Francisco, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Anthony D.","family":"Joseph","sequence":"additional","affiliation":[{"name":"UC Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"J. D.","family":"Tygar","sequence":"additional","affiliation":[{"name":"UC Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2015,10,16]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.5555\/2483628.2483648"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.5555\/1776434.1776449"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.5555\/1776434.1776449"},{"key":"e_1_3_2_1_4_1","volume-title":"In International Conference on Machine Learning (ICML","author":"Biggio B.","year":"2012","unstructured":"Biggio, B., Nelson, B., and Laskov, P. Poisoning attacks against support vector machines. In In International Conference on Machine Learning (ICML (2012)."},{"key":"e_1_3_2_1_5_1","volume-title":"IEEE SRDS Workshop on Sharing Field Data and Experiment Measurements on Resilience of Distributed Computing Systems","author":"Canto J.","year":"2008","unstructured":"Canto, J., Dacier, M., Kirda, E., and Leita, C. Large scale malware collection: Lessons learned. In IEEE SRDS Workshop on Sharing Field Data and Experiment Measurements on Resilience of Distributed Computing Systems (2008)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611972818.12"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.5555\/2028067.2028070"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6638293"},{"key":"e_1_3_2_1_9_1","volume-title":"State of Infections Report: Q4","author":"Damballa","year":"2014","unstructured":"Damballa. State of Infections Report: Q4 2014. Tech. rep., Damballa, 2015."},{"key":"e_1_3_2_1_10_1","volume-title":"Maximum likelihood estimation of observer error-rates using the em algorithm. Applied Statistics","author":"Dawid A. P.","year":"1979","unstructured":"Dawid, A. P., and Skene, A. M. Maximum likelihood estimation of observer error-rates using the em algorithm. Applied Statistics (1979), 20--28."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.5555\/1390681.1442794"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517312.2517315"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ComputationWorld.2009.85"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2006.4"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/1248547.1248646"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076785"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/1894166.1894183"},{"key":"e_1_3_2_1_18_1","first-page":"692","volume-title":"Advances in Neural Information Processing Systems","author":"Liu Q.","year":"2012","unstructured":"Liu, Q., Peng, J., and Ihler, A. T. Variational inference for crowdsourcing. In Advances in Neural Information Processing Systems (2012), pp. 692--700."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-25560-1_10"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-31537-4_40"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.5555\/1756006.1756038"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/WATeR.2014.7015757"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2007.242"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-007-9054-3"},{"key":"e_1_3_2_1_25_1","volume-title":"McAfee","author":"McAfee Labs","year":"2014","unstructured":"McAfee Labs. McAfee Labs Threats Report. Tech. rep., McAfee, 2014."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.csda.2008.10.015"},{"key":"e_1_3_2_1_27_1","volume-title":"Back to the future: Malware detection with temporally consistent labels. Under submission","author":"Miller B.","year":"2015","unstructured":"Miller, B., Kantchelian, A., Afroz, S., Bachwani, R., Faizullabhoy, R., Huang, L., Shankar, V., Tschantz, M. C., Wu, T., Yiu, G., Joseph, A. D., and Tygar, J. D. Back to the future: Malware detection with temporally consistent labels. Under submission, 2015."},{"key":"e_1_3_2_1_28_1","first-page":"112","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Mohaisen A.","year":"2014","unstructured":"Mohaisen, A., and Alrawi, O. Av-meter: An evaluation of antivirus scans and labels. In Detection of Intrusions and Malware, and Vulnerability Assessment. Springer, 2014, pp. 112--131."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1023\/A:1007692713085"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/JISIC.2014.23"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2014.02.053"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2014.02.053"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-33338-5_14"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420999"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.22"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.5555\/1855711.1855737"},{"key":"e_1_3_2_1_37_1","volume-title":"20th Annual Network and Distributed System Security Symposium, NDSS","author":"Rajab M. A.","year":"2013","unstructured":"Rajab, M. A., Ballard, L., Lutz, N., Mavrommatis, P., and Provos, N. CAMP: Content-agnostic malware protection. In 20th Annual Network and Distributed System Security Symposium, NDSS (2013)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102351.1102437"},{"key":"e_1_3_2_1_39_1","first-page":"1809","volume-title":"Advances in Neural Information Processing Systems","author":"Raykar V. C.","year":"2011","unstructured":"Raykar, V. C., and Yu, S. Ranking annotators for crowdsourced labeling tasks. In Advances in Neural Information Processing Systems (2011), pp. 1809--1817."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1553374.1553488"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0027-8"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920267"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.5555\/2011216.2011217"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/EISIC.2012.34"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-11747-3_3"},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-19934-9_53"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.5220\/0001863603170320"},{"key":"e_1_3_2_1_49_1","volume-title":"International Joint Conference CISIS'12-ICEUTE'12-SOCO'12 Special Sessions","volume":"189","author":"Sanz B.","year":"2012","unstructured":"Sanz, B., Santos, I., Laorden, C., Ugarte-Pedrero, X., Bringas, P. G., and Maran\u00f3n, G. \u00c1. PUMA: permission usage to detect malware in android. In International Joint Conference CISIS'12-ICEUTE'12-SOCO'12 Special Sessions (2012), \u00c1. Herrero, V. Sn\u00e1sel, A. Abraham, I. Zelinka, B. Baruque, H. Quinti\u00e1n-Pardo, J. L. Calvo-Rolle, J. Sedano, and E. Corchado, Eds., vol. 189 of Advances in Intelligent Systems and Computing, Springer, pp. 289--298."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.5555\/1817271.1817389"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884439"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/2381896.2381911"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/1401890.1401965"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2004.06.003"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420987"},{"key":"e_1_3_2_1_56_1","volume-title":"Network & Distributed System Security Symp.","author":"Srndic N.","year":"2013","unstructured":"vSrndic, N., and Laskov, P. Detection of malicious PDF files based on hierarchical document structure. In Network & Distributed System Security Symp. (2013)."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"crossref","unstructured":"Stolfo S. Wang K. and Li W.-J. Towards stealthy malware detection. In Malware Detection M. Christodorescu S. Jha D. Maughan D. Song and C. Wang Eds. vol. 27 of Advances in Information Security. Springer US 2007 pp. 231--249.","DOI":"10.1007\/978-0-387-44599-1_11"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516682"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/1599272.1599278"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.5555\/2503308.2343677"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2009.5403021"},{"key":"e_1_3_2_1_62_1","volume-title":"https:\/\/www.virustotal.com\/en\/statistics\/. Retrieved on","author":"VirusTotal","year":"2014","unstructured":"VirusTotal. https:\/\/www.virustotal.com\/en\/statistics\/. Retrieved on July 30, 2014."},{"key":"e_1_3_2_1_63_1","first-page":"2424","volume-title":"Advances in Neural Information Processing Systems","author":"Welinder P.","year":"2010","unstructured":"Welinder, P., Branson, S., Perona, P., and Belongie, S. J. The multidimensional wisdom of crowds. In Advances in Neural Information Processing Systems (2010), pp. 2424--2432."},{"key":"e_1_3_2_1_64_1","first-page":"2035","volume-title":"Advances in Neural Information Processing Systems","author":"Whitehill J.","year":"2009","unstructured":"Whitehill, J., Wu, T.-f., Bergsma, J., Movellan, J. R., and Ruvolo, P. L. Whose vote should count more: Optimal integration of labels from labelers of unknown expertise. In Advances in Neural Information Processing Systems (2009), pp. 2035--2043."},{"key":"e_1_3_2_1_65_1","volume-title":"SBMDS: An interpretable string based malware detection system using SVM ensemble with bagging","author":"Ye Y.","year":"2009","unstructured":"Ye, Y., Chen, L., Wang, D., Li, T., Jiang, Q., and Zhao, M. SBMDS: An interpretable string based malware detection system using SVM ensemble with bagging, 2009."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-008-0082-4"}],"event":{"name":"CCS'15: The 22nd ACM Conference on Computer and Communications Security","location":"Denver Colorado USA","acronym":"CCS'15","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 8th ACM Workshop on Artificial Intelligence and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2808769.2808780","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2808769.2808780","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2808769.2808780","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T09:40:20Z","timestamp":1763458820000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2808769.2808780"}},"subtitle":["Techniques for Weighting Anti-Virus Vendor Labels"],"short-title":[],"issued":{"date-parts":[[2015,10,16]]},"references-count":66,"alternative-id":["10.1145\/2808769.2808780","10.1145\/2808769"],"URL":"https:\/\/doi.org\/10.1145\/2808769.2808780","relation":{},"subject":[],"published":{"date-parts":[[2015,10,16]]},"assertion":[{"value":"2015-10-16","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}