{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/lemna-explaining-deep-learning-based-security","title":"Lemna: Explaining deep learning based security applications","arxiv_id":null,"date":"2018-01-15","proceeding":"Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security 2018 1","authors":["Wenbo Guo","Dongliang Mu5","Jun Xu4","Purui Su6","Gang Wang3","Xinyu Xing"],"abstract":"While deep learning has shown a great potential in various domains,the lack of transparency has limited its application in security orsafety-critical areas. Existing research has attempted to developexplanation techniques to provide interpretable explanations foreach classication decision. Unfortunately, current methods areoptimized for non-security tasks (e.g., image analysis). Their keyassumptions are often violated in security applications, leading toa poor explanation delity.In this paper, we proposeLEMNA, a high-delity explanationmethod dedicated for security applications. Given an input datasample,LEMNAgenerates a small set of interpretable features to ex-plain how the input sample is classied. The core idea is to approx-imate a local area of the complex deep learning decision boundaryusing a simple interpretable model. The local interpretable modelis specially designed to (1) handle feature dependency to betterwork with security applications (e.g., binary code analysis); and(2) handle nonlinear local boundaries to boost explanation delity.We evaluate our system using two popular deep learning applica-tions in security (a malware classier, and a function start detectorfor binary reverse-engineering). Extensive evaluations show thatLEMNA’s explanation has a much higher delity level compared toexisting methods. In addition, we demonstrate practical use casesofLEMNAto help machine learning developers to validate model be-havior, troubleshoot classication errors, and automatically patchthe errors of the target models.","url_abs":"https://dl.acm.org/doi/pdf/10.1145/3243734.3243792","url_pdf":"https://dl.acm.org/doi/pdf/10.1145/3243734.3243792","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"lemna-explaining-deep-learning-based-security","repo_url":"https://github.com/nitishabharathi/LEMNA","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"none","reach":null}],"tasks":[{"task_slug":"deep-learning","task_name":"Deep Learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}