Latent Stability Analysis of Malware Representations Under Feature-Space Perturbations
This study addresses the lack of systematic evaluation of latent-space stability and decision boundary sensitivity in existing static malware detectors under feature perturbations. The authors propose a latent-space stability analysis framework that integrates adversarial feature perturbations with multiple representation schemes—including raw EMBER features, PCA-compressed embeddings, variational autoencoders, Mandelbrot escape-time descriptors, and a PINN-based latent flow module. To characterize dynamic evolution under perturbation, they introduce a novel metric, Latent Escape Divergence (LED), alongside PINNFlow-derived residuals, velocity, risk, and gradient shift measures. Experimental results show that while the composite representations do not significantly improve classification performance—achieving ROC AUCs of 0.9962 on clean EMBER samples and 0.9846 with PCA-64 compression—they offer distinctive analytical value for perturbation diagnostics.