A Malicious PDF File Detection Method Based on Improved Ensemble Learning Stacking
Yidan Tang, Jinjin Dong, Yixuan Guo, Yihan Zhou, Feifan Lu, Bo Zhang · 2022
A malicious PDF file detection method based on ensemble learning is proposed to address the problem that malicious PDF files are highly concealed and difficult to detect. In order to efficiently identify malicious PDF files that are highly concealed, the detection range of malicious PDF files by machine learning models is improved by combining the conventional features of PDF files with structural features. The recognition module adopts Stacking method of ensemble learning, adds weighting operation to improve the combination performance of multiple base learners, and finds the best combination of base learners and meta learner through experiments. After experiments, NB, RF and DT are selected as the optimal Stacking model base learners and Logistic Regression as the meta learner. the optimal Stacking model achieves 98.70% accuracy on the test set, which is better than Adaboost model and deep learning DNN model.