IP Library › Granted Patent US 12,602,450
Granted Patent B2
US 12,602,450 · App. 18/072,034 · Granted Apr 14, 2026

Learning from mistakes to improve detection rates of machine learning (ML) models

Inventors: Dianhuan Lin (Sunnyvale, CA); Miao Zhang (Palo Alto, CA); Shaleen Taneja (Faridabad, IN); Rex Shang (Los Altos, CA); Howie Xu (Palo Alto, CA)
Assignee: Zscaler, Inc.
G06F18/217G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,602,450
App. No.
18/072,034
Granted
Apr 14, 2026
Kind
B2
Abstract

Systems and methods for learning from mistakes to improve detection rates of Machine Learning (ML) models. The systems and methods including receiving data with labels; running the data through a trained ML model for predictions; identifying errors in the predictions based on the labels received with the data; adjusting weights associated with samples in the data based on the identified errors; and retraining the ML model with the adjusted weights.

Claims (39)

1 . A method for improving precision and recall (detection rates) of Machine Learning (ML) models for malware detection in a computing network environment, the method comprising steps of:

receiving data with labels identifying files, network flows, or executables as malicious or benign;

running the data through a trained ML model for predictions;

identifying errors in the predictions based on the labels received with the data, wherein the errors including false positives and false negatives;

performing error analysis to group error-causing samples by root-cause feature sets;

adjusting weights associated with samples in the data based on the identified errors, wherein adjusting comprises adding weight increments to error-causing samples and combining those increments with pre-existing fixed sample weights; and

retraining the ML model with the adjusted weights to improve subsequent malware detection performance in the cloud-based system.

2 . The method of claim 1 , wherein the ML model is adapted to detect malware in the received data comprising executable binaries, firmware images, or network packet payloads.

3 . The method of claim 1 , wherein higher weights are added to the samples in the data with prediction errors, and the added weights are scaled proportionally to a confidence-score of the error or distance from decision boundary.

4 . The method of claim 1 , wherein the labels received with the data identify the samples in the data as malicious or benign based on static analysis, dynamic execution, sandbox results, or threat intelligence feeds.

5 . The method of claim 1 , wherein the received data includes fixed weights associated with the samples in the data, and wherein added weights are added to the fixed weights for the adjusting, to address class imbalance between benign and malicious samples.

6 . The method of claim 1 , wherein the errors identified in the predictions include false positives and false negatives, and error analysis groups errors by shared feature clusters before weight adjustment.

7 . The method of claim 1 , wherein the steps further include upsampling the received data to rebalance malicious and benign samples prior to retraining.

8 . A cloud-based system for improving detection rates of Machine Learning (ML) models used in a computing network environment, the cloud based system comprising:

one or more processors and memory storing instructions that, when executed, cause the one or more processors to:

receive data with labels identifying files, network flows, or executables as malicious or benign;

run the data through a trained ML model for predictions;

identify errors in the predictions based on the labels received with the data, wherein the errors including false positives and false negatives;

perform error analysis to group error-causing samples root-cause feature sets;

adjust weights associated with samples in the data based on the identified errors, wherein the weights are adjusted by adding weight increments to error-causing samples and combining those increments with pre-existing fixed sample weights; and

retrain the ML model with the adjusted weights to improve subsequent malware detection performance in the cloud-based system.

9 . The cloud-based system of claim 8 , wherein the ML model is adapted to detect malware in the received data comprising executable binaries, firmware images, or network packet payloads.

10 . The cloud-based system of claim 8 , wherein higher weights are added to the samples in the data with prediction errors, and the added weights are scaled proportionally to a confidence-score of the error or distance from decision boundary.

11 . The cloud-based system of claim 8 , wherein the labels received with the data identify the samples in the data as malicious or benign based on static analysis, dynamic execution, sandbox results, or threat intelligence feeds.

12 . The cloud-based system of claim 8 , wherein the received data includes fixed weights associated with the samples in the data, and wherein added weights are added to the fixed weights for the adjusted weights, to address class imbalance between benign and malicious samples.

13 . The cloud-based system of claim 8 , wherein the errors identified in the predictions include false positives and false negatives, and error analysis groups errors by shared feature clusters before weight adjustment.

14 . The cloud-based system of claim 8 , wherein the steps further include upsampling the received data to rebalance malicious and benign samples prior to retraining.

15 . A non-transitory computer-readable medium comprising instructions for improving detection rates of Machine Learning (ML) models for malware detection in a computing network environment that, when executed, cause one or more processors to perform steps of:

receiving data with labels identifying files, network flows, or executables as malicious or benign;

running the data through a trained ML model for predictions;

identifying errors in the predictions based on the labels received with the data, wherein the errors including false positives and false negatives;

performing error analysis to group error-causing samples by root-cause feature sets;

adjusting weights associated with samples in the data based on the identified errors, wherein adjusting comprises adding weight increments to error-causing samples and combining those increments with pre-existing fixed sample weights; and

retraining the ML model with the adjusted weights to improve subsequent malware detection performance in the cloud-based system.

16 . The non-transitory computer-readable medium of claim 15 , wherein the ML model is adapted to detect malware in the received data comprising executable binaries, firmware images, or network packet payloads.

17 . The non-transitory computer-readable medium of claim 15 , wherein higher weights are added to the samples in the data with prediction errors, and the added weights are scaled proportionally to a confidence-score of the error or distance from decision boundary.

18 . The non-transitory computer-readable medium of claim 15 , wherein the labels received with the data identify the samples in the data as malicious or benign based on static analysis, dynamic execution, sandbox results, or threat intelligence feeds.

19 . The non-transitory computer-readable medium of claim 15 , wherein the received data includes fixed weights associated with the samples in the data, and wherein added weights are added to the fixed weights for the adjusting, to address class imbalance between benign and malicious samples.

20 . The non-transitory computer-readable medium of claim 15 , wherein the steps further include upsampling the received data to rebalance malicious and benign samples prior to retraining.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2022
From: LIN, DIANHUAN; ZHANG, MIAO; TANEJA, SHALEEN; SHANG, REX; XU, HOWIE
To: ZSCALER, INC.
Reel/Frame 061923/0702 →
Priority Claims (1)
IN 202211057867 · Oct 10, 2022 · national
Continuity (2)
Continuation 17961072 · Oct 6, 2022
Related Publication 20240119121A1 · Apr 11, 2024
References Cited (48)
US 6009475A · Shrader · 1999 [cited by applicant]
US 6138162A · Pistriotto et al. · 2000 [cited by applicant]
US 7316029B1 · Parker et al. · 2008 [cited by applicant]
US 7383569B1 · Elgressy et al. · 2008 [cited by applicant]
US 7620985B1 · Bush et al. · 2009 [cited by applicant]
US 8166533B2 · Yuan · 2012 [cited by applicant]
US 8499348B1 · Rubin · 2013 [cited by applicant]
US 8677471B2 · Karels et al. · 2014 [cited by applicant]
US 9065850B1 · Sobrier · 2015 [cited by applicant]
US 9152789B2 · Natarajan et al. · 2015 [cited by applicant]
US 9773107B2 · White et al. · 2017 [cited by applicant]
US 10142362B2 · Weith et al. · 2018 [cited by applicant]
US 10154067B2 · Smith et al. · 2018 [cited by applicant]
US 10348599B2 · O'Neil et al. · 2019 [cited by applicant]
US 10362048B2 · Alexander et al. · 2019 [cited by applicant]
US 10419477B2 · Desai et al. · 2019 [cited by applicant]
US 10439985B2 · D'Neil · 2019 [cited by applicant]
US 10498605B2 · Weith et al. · 2019 [cited by applicant]
US 10505899B1 · Singh et al. · 2019 [cited by applicant]
US 20050193222A1 · Greene · 2005 [cited by applicant]
US 20060095970A1 · Rajagopal et al. · 2006 [cited by applicant]
US 20070233477A1 · Halowani et al. · 2007 [cited by applicant]
US 20100115621A1 · Staniford et al. · 2010 [cited by applicant]
US 20160162802A1 · Chickering · 2016 [cited by examiner]
US 20160344770A1 · Verma et al. · 2016 [cited by applicant]
US 20170063886A1 · Muddu et al. · 2017 [cited by applicant]
US 20170078329A1 · Hwang et al. · 2017 [cited by applicant]
US 20170272465A1 · Steele · 2017 [cited by applicant]
US 20180041471A1 · Sudo et al. · 2018 [cited by applicant]
US 20180150758A1 · Niininen et al. · 2018 [cited by applicant]
US 20180174275A1 · Bourdev · 2018 [cited by examiner]
US 20180293381A1 · Tseng et al. · 2018 [cited by applicant]
US 20190281073A1 · Weith et al. · 2019 [cited by applicant]
US 20190319972A1 · Desai · 2019 [cited by applicant]
US 20190349283A1 · O'Neil et al. · 2019 [cited by applicant]
US 20200021618A1 · Smith et al. · 2020 [cited by applicant]
US 20210146241A1 · Bleasdale-Shepherd · 2021 [cited by examiner]
US 20210326698A1 · Bukharev · 2021 [cited by examiner]
US 20220036208A1 · Rao · 2022 [cited by examiner]
US 20230032822A1 · Wang · 2023 [cited by examiner]
US 20230251856A1 · Ni · 2023 [cited by examiner]
US 20230259883A1 · Misler · 2023 [cited by examiner]
WO 2018152303A1 · 2018 [cited by applicant]
Jordaney, Roberto, et al., “Transcend: Detecting concept drift in malware classification models,” 26th {USENIX} Security Symposium ({USENIX} Security 17), 2017. [cited by applicant]
Kantchelian, Alex, J. D. Tygar, and Anthony Joseph, “Evasion and hardening of tree ensemble classifiers,” International Conference on Machine Learning, 2016. [cited by applicant]
Tolomei, Gabriele, et al., “Interpretable predictions of tree-based ensembles via actionable feature tweaking,” Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. ACM, 20… [cited by applicant]
Aug. 13, 2019, International Preliminary Report on Patentability and Written Opinion for International Application No. PCT/US2018/015902. [cited by applicant]
Aug. 20, 2019, International Preliminary Report on Patentability and Written Opinion for International Application No. PCT/US2018/018325. [cited by applicant]