<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Script-Detection on CYR&#39;ML</title>
    <link>https://chengyongru.github.io/tags/script-detection/</link>
    <description>Recent content in Script-Detection on CYR&#39;ML</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 12 Jun 2026 00:00:00 +0800</lastBuildDate>
    <atom:link href="https://chengyongru.github.io/tags/script-detection/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>恶意脚本检测中的分块聚合与 MIL</title>
      <link>https://chengyongru.github.io/blog/notebook/%E6%81%B6%E6%84%8F%E8%84%9A%E6%9C%AC%E6%A3%80%E6%B5%8B%E4%B8%AD%E7%9A%84%E5%88%86%E5%9D%97%E8%81%9A%E5%90%88%E4%B8%8E%20mil/</link>
      <pubDate>Tue, 03 Feb 2026 14:07:17 +0800</pubDate>
      <guid>https://chengyongru.github.io/blog/notebook/%E6%81%B6%E6%84%8F%E8%84%9A%E6%9C%AC%E6%A3%80%E6%B5%8B%E4%B8%AD%E7%9A%84%E5%88%86%E5%9D%97%E8%81%9A%E5%90%88%E4%B8%8E%20mil/</guid>
      <description>&lt;p&gt;恶意脚本检测有一个很实际的问题：真正有问题的代码可能只占一小段。脚本整体很长，但危险行为往往集中在某几行，例如解码、下载、执行或跳转。如果直接把长脚本截断成固定长度输入，就有可能把关键负载切掉，模型最后是在一段看起来正常的文本上学习“恶意”标签。&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
