{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,2]],"date-time":"2025-11-02T17:20:01Z","timestamp":1762104001666,"version":"build-2065373602"},"publisher-location":"New York, NY, USA","reference-count":39,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,14]],"date-time":"2024-04-14T00:00:00Z","timestamp":1713052800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100014037","name":"National Defense Science and Engineering Graduate","doi-asserted-by":"publisher","award":["FA9550-21-F-0003"],"award-info":[{"award-number":["FA9550-21-F-0003"]}],"id":[{"id":"10.13039\/100014037","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["2220426","2220401"],"award-info":[{"award-number":["2220426","2220401"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000185","name":"Defense Advanced Research Projects Agency","doi-asserted-by":"publisher","award":["FA8750-23-C-0518"],"award-info":[{"award-number":["FA8750-23-C-0518"]}],"id":[{"id":"10.13039\/100000185","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-22-1-0019","FA9550-23-1-0135"],"award-info":[{"award-number":["FA9550-22-1-0019","FA9550-23-1-0135"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,14]]},"DOI":"10.1145\/3644033.3644372","type":"proceedings-article","created":{"date-parts":[[2024,6,6]],"date-time":"2024-06-06T16:56:27Z","timestamp":1717692987000},"page":"127-137","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Case Study: Neural Network Malware Detection Verification for Feature and Image Datasets"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4906-2179","authenticated-orcid":false,"given":"Preston K.","family":"Robinette","sequence":"first","affiliation":[{"name":"Vanderbilt University, Nashville, TN, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0721-1241","authenticated-orcid":false,"given":"Diego","family":"Manzanas Lopez","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9259-1586","authenticated-orcid":false,"given":"Serena","family":"Serbinowska","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4001-3442","authenticated-orcid":false,"given":"Kevin","family":"Leach","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8021-9923","authenticated-orcid":false,"given":"Taylor T","family":"Johnson","sequence":"additional","affiliation":[{"name":"Vanderbilt University, Nashville, TN, United States of America"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,6,6]]},"reference":[{"unstructured":"[n. d.]. 2022 Incident Response Report. https:\/\/www.paloaltonetworks.com\/unit42\/2022-incident-response-report","key":"e_1_3_2_1_1_1"},{"key":"e_1_3_2_1_2_1","volume-title":"NASA Formal Methods Symposium. Springer.","author":"Bak Stanley","year":"2021","unstructured":"Stanley Bak. 2021. nnenum: Verification of ReLU Neural Networks with Optimized Abstraction Refinement. In NASA Formal Methods Symposium. Springer."},{"key":"e_1_3_2_1_3_1","article-title":"Branch and Bound for Piecewise Linear Neural Network Verification","volume":"21","author":"Bunel Rudy","year":"2020","unstructured":"Rudy Bunel, Ilker Turkaslan, Philip H. S. Torr, M. Pawan Kumar, Jingyue Lu, and Pushmeet Kohli. 2020. Branch and Bound for Piecewise Linear Neural Network Verification. J. Mach. Learn. Res. 21, 1, Article 42 (jan 2020), 39 pages.","journal-title":"J. Mach. Learn. Res."},{"key":"e_1_3_2_1_4_1","volume-title":"The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=JLg5aHHv7j","author":"Carlini Nicholas","year":"2023","unstructured":"Nicholas Carlini, Florian Tramer, Krishnamurthy Dj Dvijotham, Leslie Rice, Mingjie Sun, and J Zico Kolter. 2023. (Certified!!) Adversarial Robustness for Free!. In The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=JLg5aHHv7j"},{"key":"e_1_3_2_1_5_1","volume-title":"arXiv preprint arXiv:1711.08478","author":"Carlini Nicholas","year":"2017","unstructured":"Nicholas Carlini and David Wagner. 2017. Magnet and\" efficient defenses against adversarial attacks\" are not robust to adversarial examples. arXiv preprint arXiv:1711.08478 (2017)."},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the 29th USENIX Conference on Security Symposium. 2343--2360","author":"Chen Yizheng","year":"2020","unstructured":"Yizheng Chen, Shiqi Wang, Dongdong She, and Suman Jana. 2020. On training robust PDF malware classifiers. In Proceedings of the 29th USENIX Conference on Security Symposium. 2343--2360."},{"key":"e_1_3_2_1_7_1","first-page":"34912","article-title":"Understanding robust learning through the lens of representation similarities","volume":"35","author":"Cianfarani Christian","year":"2022","unstructured":"Christian Cianfarani, Arjun Nitin Bhagoji, Vikash Sehwag, Ben Zhao, Heather Zheng, and Prateek Mittal. 2022. Understanding robust learning through the lens of representation similarities. Advances in Neural Information Processing Systems 35 (2022), 34912--34925.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_8_1","volume-title":"international conference on machine learning. PMLR, 1310--1320","author":"Cohen Jeremy","year":"2019","unstructured":"Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. 2019. Certified adversarial robustness via randomized smoothing. In international conference on machine learning. PMLR, 1310--1320."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_9_1","DOI":"10.29007\/5pdh"},{"key":"e_1_3_2_1_10_1","volume-title":"Software Engineering and Formal Methods: 20th International Conference, SEFM 2022, Berlin, Germany, September 26--30, 2022, Proceedings. Springer, 173--189","author":"Elboher Yizhak Yisrael","year":"2022","unstructured":"Yizhak Yisrael Elboher, Elazar Cohen, and Guy Katz. 2022. Neural network verification using residual reasoning. In Software Engineering and Formal Methods: 20th International Conference, SEFM 2022, Berlin, Germany, September 26--30, 2022, Proceedings. Springer, 173--189."},{"volume-title":"Thirty-seventh Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=ffFcRPpnWx","author":"Huang Zhuoqun","unstructured":"Zhuoqun Huang, Neil G Marchant, Keane Lucas, Lujo Bauer, Olga Ohrimenko, and Benjamin I. P. Rubinstein. 2023. RS-Del: Edit Distance Robustness Certificates for Sequence Classifiers via Randomized Deletion. In Thirty-seventh Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=ffFcRPpnWx","key":"e_1_3_2_1_11_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_12_1","DOI":"10.1007\/978-3-319-63387-9_5"},{"volume-title":"The Marabou Framework for Verification and Analysis of Deep Neural Networks","author":"Katz Guy","unstructured":"Guy Katz, Derek A. Huang, Duligur Ibeling, Kyle Julian, Christopher Lazarus, Rachel Lim, Parth Shah, Shantanu Thakoor, Haoze Wu, Aleksandar Zelji\u0107, David L. Dill, Mykel J. Kochenderfer, and Clark Barrett. 2019. The Marabou Framework for Verification and Analysis of Deep Neural Networks. In Computer Aided Verification, Isil Dillig and Serdar Tasiran (Eds.). Springer International Publishing, Cham, 443--452.","key":"e_1_3_2_1_13_1"},{"volume-title":"Advances in Computer Science and Ubiquitous Computing: CSA-CUTE 17","author":"Kim Hae-Jung","unstructured":"Hae-Jung Kim. 2018. Image-based malware classification using convolutional neural network. In Advances in Computer Science and Ubiquitous Computing: CSA-CUTE 17. Springer, 1352--1357.","key":"e_1_3_2_1_14_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_15_1","DOI":"10.1145\/1014052.1014105"},{"key":"e_1_3_2_1_16_1","volume-title":"2018 IEEE Applied Imagery Pattern Recognition Workshop (AIPR). IEEE, 1--6.","author":"Kornish David","year":"2018","unstructured":"David Kornish, Justin Geary, Victor Sansing, Soundararajan Ezekiel, Larry Pearlstein, and Laurent Njilla. 2018. Malware classification using deep convolutional neural networks. In 2018 IEEE Applied Imagery Pattern Recognition Workshop (AIPR). IEEE, 1--6."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_17_1","DOI":"10.1109\/SP.2019.00044"},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of 9th International Workshop on Applied Verification of Continuous and Hybrid Systems (ARCH22)","volume":"184","author":"Lopez Diego Manzanas","year":"2022","unstructured":"Diego Manzanas Lopez, Matthias Althoff, Luis Benet, Xin Chen, Jiameng Fan, Marcelo Forets, Chao Huang, Taylor T Johnson, Tobias Ladner, Wenchao Li, Christian Schilling, and Qi Zhu. 2022. ARCH-COMP22 Category Report: Artificial Intelligence and Neural Network Control Systems (AINNCS) for Continuous and Hybrid Systems Plants. In Proceedings of 9th International Workshop on Applied Verification of Continuous and Hybrid Systems (ARCH22) (EPiC Series in Computing, Vol. 90), Goran Frehse, Matthias Althoff, Erwin Schoitsch, and Jeremie Guiochet (Eds.). EasyChair, 142--184."},{"volume-title":"35th International Conference on Computer-Aided Verification (CAV).","author":"Lopez Diego Manzanas","unstructured":"Diego Manzanas Lopez, Sung Woo Choi, Hoang-Dung Tran, and Taylor T. Johnson. 2023. NNV 2.0: The Neural Network Verification Tool. In 35th International Conference on Computer-Aided Verification (CAV).","key":"e_1_3_2_1_19_1"},{"key":"e_1_3_2_1_20_1","volume-title":"International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rJzIBfZAb","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of the 20th International Conference on Formal Modeling and Analysis of Timed Systems (FORMATS 2022), Co-Located with CONCUR, FMICS, and QEST as part of CONFEST 2022","author":"Lopez Diego Manzanas","year":"2022","unstructured":"Diego Manzanas Lopez, Patrick Musau, Nathaniel Hamilton, and Taylor Johnson. 2022. Reachability Analysis of a General Class of Neural Ordinary Differential Equation. In Proceedings of the 20th International Conference on Formal Modeling and Analysis of Timed Systems (FORMATS 2022), Co-Located with CONCUR, FMICS, and QEST as part of CONFEST 2022. Warsaw, Poland."},{"key":"e_1_3_2_1_22_1","volume-title":"Johnson","author":"M\u00fcller Mark Niklas","year":"2022","unstructured":"Mark Niklas M\u00fcller, Christopher Brix, Stanley Bak, Changliu Liu, and Taylor T. Johnson. 2022. The Third International Verification of Neural Networks Competition (VNN-COMP 2022): Summary and Results."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_23_1","DOI":"10.1145\/2016904.2016908"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_24_1","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_1_25_1","volume-title":"SAFECOMP 2021, York, UK, September 8--10, 2021, Proceedings 40","author":"Paterson Colin","year":"2021","unstructured":"Colin Paterson, Haoze Wu, John Grese, Radu Calinescu, Corina S P\u00e1s\u00e1reanu, and Clark Barrett. 2021. Deepcert: Verification of contextually relevant robustness for neural network image classifiers. In Computer Safety, Reliability, and Security: 40th International Conference, SAFECOMP 2021, York, UK, September 8--10, 2021, Proceedings 40. Springer, 3--17."},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings 2001 IEEE Symposium on Security and Privacy. S&P","author":"Schultz Matthew G","year":"2000","unstructured":"Matthew G Schultz, Eleazar Eskin, F Zadok, and Salvatore J Stolfo. 2000. Data mining methods for detection of new malicious executables. In Proceedings 2001 IEEE Symposium on Security and Privacy. S&P 2001. IEEE, 38--49."},{"key":"e_1_3_2_1_27_1","volume-title":"Cyber Security Cryptography and Machine Learning: Third International Symposium, CSCML 2019, Beer-Sheva, Israel, June 27--28, 2019, Proceedings 3. Springer, 75--92","author":"Singh Ajay","year":"2019","unstructured":"Ajay Singh, Anand Handa, Nitesh Kumar, and Sandeep Kumar Shukla. 2019. Malware classification using image representation. In Cyber Security Cryptography and Machine Learning: Third International Symposium, CSCML 2019, Beer-Sheva, Israel, June 27--28, 2019, Proceedings 3. Springer, 75--92."},{"key":"e_1_3_2_1_28_1","volume-title":"Evaluating Robustness of Neural Networks with Mixed Integer Programming. arXiv preprint arXiv:1711.07356","author":"Tjeng Vincent","year":"2017","unstructured":"Vincent Tjeng, Kai Xiao, and Russ Tedrake. 2017. Evaluating Robustness of Neural Networks with Mixed Integer Programming. arXiv preprint arXiv:1711.07356 (2017)."},{"key":"e_1_3_2_1_29_1","volume-title":"Johnson","author":"Tran Hoang-Dung","year":"2020","unstructured":"Hoang-Dung Tran, Stanley Bak, Weiming Xiang, and Taylor T. Johnson. 2020. Verification of Deep Convolutional Neural Networks Using ImageStars. In 32nd International Conference on Computer-Aided Verification (CAV). Springer."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_30_1","DOI":"10.1145\/3575870.3587112"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_31_1","DOI":"10.1145\/3575870.3587128"},{"key":"e_1_3_2_1_32_1","volume-title":"Stanley Bak, and Taylor T. Johnson.","author":"Tran Hoang-Dung","year":"2021","unstructured":"Hoang-Dung Tran, Neelanjana Pal, Patrick Musau, Xiaodong Yang, Nathaniel P. Hamilton, Diego Manzanas Lopez, Stanley Bak, and Taylor T. Johnson. 2021. Robustness Verification of Semantic Segmentation Neural Networks using Relaxed Reachability. In 33rd International Conference on Computer-Aided Verification (CAV). Springer."},{"volume-title":"NNV: The Neural Network Verification Tool for Deep Neural Networks and Learning-Enabled Cyber-Physical Systems. In 32nd International Conference on Computer-Aided Verification (CAV).","author":"Tran Hoang-Dung","unstructured":"Hoang-Dung Tran, Xiaodong Yang, Diego Manzanas Lopez, Patrick Musau, Luan Viet Nguyen, Weiming Xiang, Stanley Bak, and Taylor T. Johnson. 2020. NNV: The Neural Network Verification Tool for Deep Neural Networks and Learning-Enabled Cyber-Physical Systems. In 32nd International Conference on Computer-Aided Verification (CAV).","key":"e_1_3_2_1_33_1"},{"volume-title":"Medical Imaging 2019: Image Processing","author":"Uzunova Hristina","unstructured":"Hristina Uzunova, Jan Ehrhardt, Timo Kepp, and Heinz Handels. 2019. Interpretable explanations of black box classifiers applied on medical images by meaningful perturbations using variational autoencoders. In Medical Imaging 2019: Image Processing, Vol. 10949. SPIE, 264--271.","key":"e_1_3_2_1_34_1"},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_35_1","DOI":"10.1016\/j.cose.2020.101748"},{"volume-title":"27th {USENIX} Security Symposium ({USENIX} Security 18). 1599--1614.","author":"Wang Shiqi","unstructured":"Shiqi Wang, Kexin Pei, Justin Whitehouse, Junfeng Yang, and Suman Jana. 2018. Formal security analysis of neural networks using symbolic intervals. In 27th {USENIX} Security Symposium ({USENIX} Security 18). 1599--1614.","key":"e_1_3_2_1_36_1"},{"key":"e_1_3_2_1_37_1","first-page":"29909","article-title":"Beta-crown: Efficient bound propagation with per-neuron split constraints for neural network robustness verification","volume":"34","author":"Wang Shiqi","year":"2021","unstructured":"Shiqi Wang, Huan Zhang, Kaidi Xu, Xue Lin, Suman Jana, Cho-Jui Hsieh, and J Zico Kolter. 2021. Beta-crown: Efficient bound propagation with per-neuron split constraints for neural network robustness verification. Advances in Neural Information Processing Systems 34 (2021), 29909--29921.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_38_1","volume-title":"International Conference on Machine Learning. PMLR, 10693--10705","author":"Yang Greg","year":"2020","unstructured":"Greg Yang, Tony Duan, J Edward Hu, Hadi Salman, Ilya Razenshteyn, and Jerry Li. 2020. Randomized smoothing of all shapes and sizes. In International Conference on Machine Learning. PMLR, 10693--10705."},{"doi-asserted-by":"publisher","key":"e_1_3_2_1_39_1","DOI":"10.1109\/SPW53761.2021.00020"}],"event":{"sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS"],"acronym":"FormaliSE '24","name":"FormaliSE '24: 2024 IEEE\/ACM 12th International Conference on Formal Methods in Software Engineering (FormaliSE)","location":"Lisbon Portugal"},"container-title":["Proceedings of the 2024 IEEE\/ACM 12th International Conference on Formal Methods in Software Engineering (FormaliSE)"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3644033.3644372","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3644033.3644372","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T23:56:58Z","timestamp":1750291018000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3644033.3644372"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,14]]},"references-count":39,"alternative-id":["10.1145\/3644033.3644372","10.1145\/3644033"],"URL":"https:\/\/doi.org\/10.1145\/3644033.3644372","relation":{},"subject":[],"published":{"date-parts":[[2024,4,14]]},"assertion":[{"value":"2024-06-06","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}