{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,24]],"date-time":"2026-02-24T09:50:06Z","timestamp":1771926606459,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,4,26]],"date-time":"2021-04-26T00:00:00Z","timestamp":1619395200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,4,26]]},"DOI":"10.1145\/3447852.3458719","type":"proceedings-article","created":{"date-parts":[[2021,4,25]],"date-time":"2021-04-25T09:54:20Z","timestamp":1619344460000},"page":"34-40","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["TagVet"],"prefix":"10.1145","author":[{"given":"Lukas","family":"Pirch","sequence":"first","affiliation":[{"name":"Technische Universit\u00e4t, Braunschweig, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alexander","family":"Warnecke","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t, Braunschweig, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christian","family":"Wressnegger","sequence":"additional","affiliation":[{"name":"Karlsruhe Institute of Technology, Karlsruhe, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Konrad","family":"Rieck","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t, Braunschweig, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,4,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Yara - the pattern matching swiss knife for malware researchers. https:\/\/virustotal.github.io\/yara\/. visited","author":"Alvarez V. M.","year":"2021","unstructured":"V. M. Alvarez . Yara - the pattern matching swiss knife for malware researchers. https:\/\/virustotal.github.io\/yara\/. visited March 2021 . V. M. Alvarez. Yara - the pattern matching swiss knife for malware researchers. https:\/\/virustotal.github.io\/yara\/. visited March 2021."},{"key":"e_1_3_2_1_2_1","volume-title":"Proc. of International Conference on Learning Representations (ICLR)","author":"Ancona M.","year":"2018","unstructured":"M. Ancona , E. Ceolini , C. \u00d6ztireli , and M. Gross . Towards better understanding of gradient-based attribution methods for deep neural networks . In Proc. of International Conference on Learning Representations (ICLR) , 2018 . M. Ancona, E. Ceolini, C. \u00d6ztireli, and M. Gross. Towards better understanding of gradient-based attribution methods for deep neural networks. In Proc. of International Conference on Learning Representations (ICLR), 2018."},{"key":"e_1_3_2_1_3_1","volume-title":"July","author":"Bach S.","year":"2015","unstructured":"S. Bach , A. Binder , G. Montavon , F. Klauschen , K.-R. M\u00fcller , and W. Samek . On pixel-wise explanations for non-linear classifier decisions by layer-wise relevance propagation. PLoS ONE, 10(7) , July 2015 . S. Bach, A. Binder, G. Montavon, F. Klauschen, K.-R. M\u00fcller, and W. Samek. On pixel-wise explanations for non-linear classifier decisions by layer-wise relevance propagation. PLoS ONE, 10(7), July 2015."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74320-0_10"},{"key":"e_1_3_2_1_5_1","volume-title":"Proc. of the Network and Distributed System Security Symposium (NDSS)","author":"Bayer U.","year":"2009","unstructured":"U. Bayer , P. M. Comparetti , C. Hlauschek , C. Kruegel , and E. Kirda . Scalable, behavior-based malware clustering . In Proc. of the Network and Distributed System Security Symposium (NDSS) , 2009 . U. Bayer, P. M. Comparetti, C. Hlauschek, C. Kruegel, and E. Kirda. Scalable, behavior-based malware clustering. In Proc. of the Network and Distributed System Security Symposium (NDSS), 2009."},{"key":"e_1_3_2_1_6_1","volume-title":"Proc. of USENIX Security Symposium","author":"Caballero J.","year":"2011","unstructured":"J. Caballero , C. Grier , C. Kreibich , and V. Paxson . Measuring pay-per-install: The commoditization of malware distribution . In Proc. of USENIX Security Symposium , 2011 . J. Caballero, C. Grier, C. Kreibich, and V. Paxson. Measuring pay-per-install: The commoditization of malware distribution. In Proc. of USENIX Security Symposium, 2011."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1455770.1455779"},{"key":"e_1_3_2_1_8_1","volume-title":"Advances in Neural Information Proccessing Systems (NIPS)","author":"Dombrowski A.-K.","year":"2019","unstructured":"A.-K. Dombrowski , M. Alber , C. J. Anders , M. Ackermann , K.-R. M\u00fcller , and P. Kessel . Explanations can be manipulated and geometry is to blame . In Advances in Neural Information Proccessing Systems (NIPS) , 2019 . A.-K. Dombrowski, M. Alber, C. J. Anders, M. Ackermann, K.-R. M\u00fcller, and P. Kessel. Explanations can be manipulated and geometry is to blame. In Advances in Neural Information Proccessing Systems (NIPS), 2019."},{"key":"e_1_3_2_1_9_1","volume-title":"A survey on automated dynamic malware-analysis techniques and tools. ACM Computing Surveys (CSUR), 44(2): 1--42","author":"Egele M.","year":"2012","unstructured":"M. Egele , T. Scholte , E. Kirda , and C. Kruegel . A survey on automated dynamic malware-analysis techniques and tools. ACM Computing Surveys (CSUR), 44(2): 1--42 , 2012 . M. Egele, T. Scholte, E. Kirda, and C. Kruegel. A survey on automated dynamic malware-analysis techniques and tools. ACM Computing Surveys (CSUR), 44(2): 1--42, 2012."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3029806.3029811"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243792"},{"key":"e_1_3_2_1_12_1","first-page":"187","volume-title":"Proc. of USENIX Annual Technical Conference","author":"Hu X.","year":"2013","unstructured":"X. Hu , S. Bhatkar , K. Griffin , and K. G. Shin . Mutantx-s: Scalable malware clustering based on static feature . In Proc. of USENIX Annual Technical Conference , pages 187 -- 198 , 2013 . X. Hu, S. Bhatkar, K. Griffin, and K. G. Shin. Mutantx-s: Scalable malware clustering based on static feature. In Proc. of USENIX Annual Technical Conference, pages 187--198, 2013."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_8"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2017.57"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046742"},{"key":"e_1_3_2_1_16_1","first-page":"351","volume-title":"Proc. of USENIX Security Symposium","author":"Kolbitsch C.","year":"2009","unstructured":"C. Kolbitsch , P. M. Comparetti , C. Kruegel , E. Kirda , X. yong Zhou , and X. Wang . Effective and efficient malware detection at the end host . In Proc. of USENIX Security Symposium , pages 351 -- 366 , 2009 . C. Kolbitsch, P. M. Comparetti, C. Kruegel, E. Kirda, X. yong Zhou, and X. Wang. Effective and efficient malware detection at the end host. In Proc. of USENIX Security Symposium, pages 351--366, 2009."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.48"},{"key":"e_1_3_2_1_18_1","first-page":"739","volume-title":"Proc. of USENIX Security Symposium","author":"Kotzias P.","year":"2016","unstructured":"P. Kotzias , L. Bilge , and J. Caballero . Measuring pup prevalence and pup distribution through pay-per-install services . In Proc. of USENIX Security Symposium , pages 739 -- 756 , 2016 . P. Kotzias, L. Bilge, and J. Caballero. Measuring pup prevalence and pup distribution through pay-per-install services. In Proc. of USENIX Security Symposium, pages 739--756, 2016."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-23644-0_18"},{"key":"e_1_3_2_1_20_1","first-page":"4765","volume-title":"Advances in Neu- ral Information Proccessing Systems (NeurIPS)","author":"Lundberg S. M.","year":"2017","unstructured":"S. M. Lundberg and S.-I. Lee . A unified approach to interpreting model predictions . In Advances in Neu- ral Information Proccessing Systems (NeurIPS) , pages 4765 -- 4774 , 2017 . S. M. Lundberg and S.-I. Lee. A unified approach to interpreting model predictions. In Advances in Neu- ral Information Proccessing Systems (NeurIPS), pages 4765--4774, 2017."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2007.21"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2076732.2076735"},{"key":"e_1_3_2_1_23_1","first-page":"329","volume-title":"Proc. of Annual Computer Security Applications Conference (ACSAC)","author":"Perdisci R.","year":"2012","unstructured":"R. Perdisci and M. U. Vamo : towards a fully automated malware clustering validity analysis . In Proc. of Annual Computer Security Applications Conference (ACSAC) , pages 329 -- 338 , 2012 . R. Perdisci and M. U. Vamo: towards a fully automated malware clustering validity analysis. In Proc. of Annual Computer Security Applications Conference (ACSAC), pages 329--338, 2012."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2008.22"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2946392"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427242"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"e_1_3_2_1_28_1","volume-title":"June","author":"Rieck K.","year":"2011","unstructured":"K. Rieck , P. Trinius , C. Willems , and T. Holz . Automatic analysis of malware behavior using machine learning. Journal of Computer Security (JCS), 19(4): 639--668 , June 2011 . K. Rieck, P. Trinius, C. Willems, and T. Holz. Automatic analysis of malware behavior using machine learning. Journal of Computer Security (JCS), 19(4): 639--668, June 2011."},{"key":"e_1_3_2_1_29_1","volume-title":"https:\/\/www.virusshare.com. visited","author":"Roberts J.-M.","year":"2021","unstructured":"J.-M. Roberts . Virusshare.com. https:\/\/www.virusshare.com. visited March 2021 . J.-M. Roberts. Virusshare.com. https:\/\/www.virusshare.com. visited March 2021."},{"key":"e_1_3_2_1_30_1","first-page":"303","volume-title":"Proc. of USENIX Security Symposium","author":"Rudd E. M.","year":"2019","unstructured":"E. M. Rudd , F. N. Ducau , C. Wild , K. Berlin , and R. E. Harang . Aloha: Auxiliary loss optimization for hypothesis augmentation . In Proc. of USENIX Security Symposium , pages 303 -- 320 , 2019 . E. M. Rudd, F. N. Ducau, C. Wild, K. Berlin, and R. E. Harang. Aloha: Auxiliary loss optimization for hypothesis augmentation. In Proc. of USENIX Security Symposium, pages 303--320, 2019."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45719-2_11"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427261"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-88313-5_31"},{"key":"e_1_3_2_1_34_1","volume-title":"Proc. of International Conference on Learning Representations (ICLR)","author":"Simonyan K.","year":"2014","unstructured":"K. Simonyan , A. Vedaldi , and A. Zisserman . Deep inside convolutional networks: Visualising image classification models and saliency maps . In Proc. of International Conference on Learning Representations (ICLR) , 2014 . K. Simonyan, A. Vedaldi, and A. Zisserman. Deep inside convolutional networks: Visualising image classification models and saliency maps. In Proc. of International Conference on Learning Representations (ICLR), 2014."},{"key":"e_1_3_2_1_35_1","first-page":"3319","volume-title":"Proc. of International Conference on Machine Learning (ICML)","author":"Sundararajan M.","year":"2017","unstructured":"M. Sundararajan , A. Taly , and Q. Yan . Axiomatic attribution for deep networks . In Proc. of International Conference on Machine Learning (ICML) , pages 3319 -- 3328 , 2017 . M. Sundararajan, A. Taly, and Q. Yan. Axiomatic attribution for deep networks. In Proc. of International Conference on Machine Learning (ICML), pages 3319--3328, 2017."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3291061"},{"key":"e_1_3_2_1_37_1","volume-title":"Vt intelligence: Combine Google and Facebook and apply it to the field of malware. https:\/\/www.virustotal.com\/gui\/intelligence-overview, visited","year":"2021","unstructured":"VirusTotal. Vt intelligence: Combine Google and Facebook and apply it to the field of malware. https:\/\/www.virustotal.com\/gui\/intelligence-overview, visited March 2021 . VirusTotal. Vt intelligence: Combine Google and Facebook and apply it to the field of malware. https:\/\/www.virustotal.com\/gui\/intelligence-overview, visited March 2021."},{"key":"e_1_3_2_1_38_1","volume-title":"Malware analysis sandbox & malware detection software. https:\/\/www.vmray.com\/products\/analyzer-malware-sandbox\/. visited","author":"H.","year":"2021","unstructured":"VMRay Gmb H. Malware analysis sandbox & malware detection software. https:\/\/www.vmray.com\/products\/analyzer-malware-sandbox\/. visited March 2021 . VMRay GmbH. Malware analysis sandbox & malware detection software. https:\/\/www.vmray.com\/products\/analyzer-malware-sandbox\/. visited March 2021."},{"key":"e_1_3_2_1_39_1","volume-title":"Proc. of the IEEE European Symposium on Security and Privacy (EuroS&P)","author":"Warnecke A.","year":"2020","unstructured":"A. Warnecke , D. Arp , C. Wressnegger , and K. Rieck . Evaluating explanation methods for deep learning in computer security . In Proc. of the IEEE European Symposium on Security and Privacy (EuroS&P) , Sept. 2020 . A. Warnecke, D. Arp, C. Wressnegger, and K. Rieck. Evaluating explanation methods for deep learning in computer security. In Proc. of the IEEE European Symposium on Security and Privacy (EuroS&P), Sept. 2020."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_6"},{"key":"e_1_3_2_1_41_1","volume-title":"Proc. of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET)","author":"Wicherski G.","year":"2009","unstructured":"G. Wicherski . peHash : A novel approach to fast malware clustering . In Proc. of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET) , 2009 . G. Wicherski. peHash: A novel approach to fast malware clustering. In Proc. of the USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET), 2009."},{"key":"e_1_3_2_1_42_1","first-page":"1659","volume-title":"Proc. of USENIX Security Symposium","author":"Zhang X.","year":"2020","unstructured":"X. Zhang , N. Wang , H. Shen , S. Ji , X. Luo , and T. Wang . Interpretable deep learning under fire . In Proc. of USENIX Security Symposium , pages 1659 -- 1676 , 2020 . X. Zhang, N. Wang, H. Shen, S. Ji, X. Luo, and T. Wang. Interpretable deep learning under fire. In Proc. of USENIX Security Symposium, pages 1659--1676, 2020."}],"event":{"name":"EuroSys '21: Sixteenth European Conference on Computer Systems","location":"Online United Kingdom","acronym":"EuroSys '21","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 14th European Workshop on Systems Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447852.3458719","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3447852.3458719","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:49:27Z","timestamp":1750268967000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3447852.3458719"}},"subtitle":["Vetting Malware Tags using Explainable Machine Learning"],"short-title":[],"issued":{"date-parts":[[2021,4,26]]},"references-count":42,"alternative-id":["10.1145\/3447852.3458719","10.1145\/3447852"],"URL":"https:\/\/doi.org\/10.1145\/3447852.3458719","relation":{},"subject":[],"published":{"date-parts":[[2021,4,26]]},"assertion":[{"value":"2021-04-26","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}