Malware Data Transformation for Secure Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing machine learning systems using malware as training data are vulnerable to attacks and compromised by the malware, leading to security risks and interference from antivirus software.

Innovation Solution

Generating post-replacement data by replacing malware values with other values using bijective relationships while maintaining predetermined characteristics, creating learning data that prevents executable malware and avoids signature matching with antivirus software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If malware is used as learning data for machine learning, then the learning model can be trained with real malware characteristics, but the computer performing machine learning is exposed to security risks and attack using the malware

Engineering Contradiction:
Improvelearning accuracyVSAvoidsecurity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent creates a copy of the malware data that preserves the essential characteristics needed for machine learning while removing the harmful executable content. The copying process transforms the malware into a safe representation that can be used for training without posing security risks to the learning system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary processing step that transforms raw malware data into a safe format for machine learning. This intermediary process acts as a mediator between the harmful malware and the vulnerable learning system, converting the data into a form that preserves learning value while eliminating security threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If malware is used as learning data, then the model can learn malware patterns, but antivirus software may interfere with the machine learning process by detecting and blocking the malware

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidantivirus interference
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The patent creates a copy of malware data that retains the patterns and characteristics needed for training detection models, while the copied data is in a format that antivirus software does not recognize as threats, thus avoiding interference with the learning process.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms the malware data by changing its parameters or representation format, such that the essential malware characteristics are preserved for learning purposes while the transformed parameters prevent antivirus software from detecting and blocking the data during the machine learning process.

Inventive Principle:
Principle #35Parameter changes

3Quantity of substance

If malware is used for machine learning, then training data is available, but the system is vulnerable to attacks and compromised by the malware

Engineering Contradiction:
Improvetraining data availabilityVSAvoidsystem security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent creates safe copies of malware data that can be used abundantly for training purposes without compromising system security. The copying process ensures that multiple training samples can be generated while maintaining system integrity and protection against malware attacks.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent converts the harmful malware data into a beneficial training resource by transforming it into a safe format. The previously harmful malware is turned into a useful training dataset that improves machine learning models while the transformation process eliminates the security risks, effectively converting a threat into an asset.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP3985536B1Information processing program, method of processing information, and information processing device
Publication Date: 2022.12.14 FUJITSU LTD
  • EP3985536B1 patent drawingFigure 1
  • EP3985536B1 patent drawingFigure 2
  • EP3985536B1 patent drawingFigure 3

AI summary

The present invention relates to an information processing program including instructions which, when the program is executed by a computer, cause the computer to perform processing, the processing including: generating post-replacement data by replacing values, with other values, of individual unit data pieces, which have a predetermined data length, of malware in accordance with a replacement rule by which replacement is performed in bijective relationships on a unit data piece basis while a predetermined characteristic indicated in the malware is maintained; and generating, based on the post-replacement data, machine learning data to be used for machine learning in which the predetermined characteristic is used.