{"metadata":{"kernelspec":{"language":"python","display_name":"Python 3","name":"python3"},"language_info":{"name":"python","version":"3.11.13","mimetype":"text/x-python","codemirror_mode":{"name":"ipython","version":3},"pygments_lexer":"ipython3","nbconvert_exporter":"python","file_extension":".py"},"kaggle":{"accelerator":"none","dataSources":[{"sourceId":4117,"databundleVersionId":46665,"sourceType":"competition"}],"dockerImageVersionId":31234,"isInternetEnabled":true,"language":"python","sourceType":"notebook","isGpuEnabled":false}},"nbformat_minor":4,"nbformat":4,"cells":[{"cell_type":"code","source":"# This Python 3 environment comes with many helpful analytics libraries installed\n# It is defined by the kaggle/python Docker image: https://github.com/kaggle/docker-python\n# For example, here's several helpful packages to load\n\nimport numpy as np # linear algebra\nimport pandas as pd # data processing, CSV file I/O (e.g. pd.read_csv)\n\n# Input data files are available in the read-only \"../input/\" directory\n# For example, running this (by clicking run or pressing Shift+Enter) will list all files under the input directory\n\nimport os\nfor dirname, _, filenames in os.walk('/kaggle/input'):\n    for filename in filenames:\n        print(os.path.join(dirname, filename))\n\n# You can write up to 20GB to the current directory (/kaggle/working/) that gets preserved as output when you create a version using \"Save & Run All\" \n# You can also write temporary files to /kaggle/temp/, but they won't be saved outside of the current session","metadata":{"_uuid":"8f2839f25d086af736a60e9eeb907d3b93b6e0e5","_cell_guid":"b1076dfc-b9ad-4769-8c92-a6c4dae69d19","trusted":true},"outputs":[],"execution_count":null},{"cell_type":"code","source":"!ls /kaggle/input\n","metadata":{"trusted":true,"execution":{"iopub.status.busy":"2026-01-12T04:25:18.252303Z","iopub.execute_input":"2026-01-12T04:25:18.252576Z","iopub.status.idle":"2026-01-12T04:25:18.381592Z","shell.execute_reply.started":"2026-01-12T04:25:18.252553Z","shell.execute_reply":"2026-01-12T04:25:18.380316Z"}},"outputs":[],"execution_count":null},{"cell_type":"code","source":"import numpy as np # linear algebra\nimport pandas as pd # data processing, CSV file I/O (e.g. pd.read_csv)\n\n# Input data files are available in the read-only \"../input/\" directory\n# For example, running this (by clicking run or pressing Shift+Enter) will list all files under the input directory\n\nimport os\nfor dirname, _, filenames in os.walk('/kaggle/input'):\n    for filename in filenames:\n        print(os.path.join(dirname, filename))\n","metadata":{"trusted":true,"execution":{"iopub.status.busy":"2026-01-12T04:33:41.916503Z","iopub.execute_input":"2026-01-12T04:33:41.916794Z","iopub.status.idle":"2026-01-12T04:33:42.275779Z","shell.execute_reply.started":"2026-01-12T04:33:41.916773Z","shell.execute_reply":"2026-01-12T04:33:42.274697Z"}},"outputs":[],"execution_count":null},{"cell_type":"code","source":"labels_df = pd.read_csv(f\"{data_path}/trainLabels.csv\") # (id, class)\nfamily_map = {\n    1: \"Ramnit\", 2: \"Lollipop\", 3: \"Kelihos_ver3\", 4: \"Vundo\",\n    5: \"Simda\", 6: \"Tracur\", 7: \"Kelihos_ver1\", 8: \"Obfuscator.ACY\", 9: \"Gatak\"\n}\nlabels_df[\"Family\"] = labels_df[\"Class\"].map(family_map)\n# EXPLANATION: Create a new column called \"Family\" that shows the actual malware name\n# instead of just the number. For example, if Class=1, Family will be \"Ramnit\"\n\n\nprint(\"\\nLAST 1000 rows:\")\nprint(labels_df.tail(1000))","metadata":{"trusted":true,"execution":{"iopub.status.busy":"2026-01-12T05:02:41.761577Z","iopub.execute_input":"2026-01-12T05:02:41.762272Z","iopub.status.idle":"2026-01-12T05:02:41.792898Z","shell.execute_reply.started":"2026-01-12T05:02:41.762236Z","shell.execute_reply":"2026-01-12T05:02:41.791924Z"}},"outputs":[],"execution_count":null},{"cell_type":"code","source":"!ls /kaggle/input/malware-classification\n","metadata":{"trusted":true,"execution":{"iopub.status.busy":"2026-01-12T04:36:15.601851Z","iopub.execute_input":"2026-01-12T04:36:15.602192Z","iopub.status.idle":"2026-01-12T04:36:15.730126Z","shell.execute_reply.started":"2026-01-12T04:36:15.602162Z","shell.execute_reply":"2026-01-12T04:36:15.728942Z"}},"outputs":[],"execution_count":null},{"cell_type":"code","source":"sampled_df = labels_df.groupby(\"Class\", group_keys=False).apply(\n    lambda x: x.sample(n=min(10, len(x)), random_state=42)\n).reset_index(drop=True)\n# BREAKDOWN:\n# - groupby(\"Class\") → separate the data by each malware class\n# - apply(lambda x: ...) → for each group, do something\n# - x.sample(n=min(10, len(x))) → take 10 samples, or all if less than 10\n# - random_state=42 → makes the random selection reproducible (same results every time)\n\nprint(\"\\nSample count per class:\")\nprint(sampled_df[\"Class\"].value_counts())\n# EXPLANATION: For each malware class, ","metadata":{"trusted":true,"execution":{"iopub.status.busy":"2026-01-12T04:58:16.935746Z","iopub.execute_input":"2026-01-12T04:58:16.936082Z","iopub.status.idle":"2026-01-12T04:58:16.951985Z","shell.execute_reply.started":"2026-01-12T04:58:16.936053Z","shell.execute_reply":"2026-01-12T04:58:16.950932Z"}},"outputs":[],"execution_count":null},{"cell_type":"code","source":"sampled_df = labels_df.groupby(\"Class\", group_keys=False).apply(\n    lambda x: x.sample(n=min(10, len(x)), random_state=42)\n).reset_index(drop=True)\n\nprint(\"\\nSample count per class:\")\nprint(sampled_df[\"Class\"].value_counts())","metadata":{"trusted":true,"execution":{"iopub.status.busy":"2026-01-12T04:59:33.466176Z","iopub.execute_input":"2026-01-12T04:59:33.466522Z","iopub.status.idle":"2026-01-12T04:59:33.482261Z","shell.execute_reply.started":"2026-01-12T04:59:33.466499Z","shell.execute_reply":"2026-01-12T04:59:33.481269Z"}},"outputs":[],"execution_count":null},{"cell_type":"code","source":"for cls in sorted(sampled_df[\"Class\"].unique()):\n    ids = sampled_df[sampled_df[\"Class\"] == cls][\"Id\"].tolist()\n    print(f\"Class {cls} Sample IDs:\\n\", ids, \"\\n\")\nprint(\"\\nMalware family distribution:\")","metadata":{"trusted":true,"execution":{"iopub.status.busy":"2026-01-12T05:00:05.414872Z","iopub.execute_input":"2026-01-12T05:00:05.41516Z","iopub.status.idle":"2026-01-12T05:00:05.430838Z","shell.execute_reply.started":"2026-01-12T05:00:05.415141Z","shell.execute_reply":"2026-01-12T05:00:05.429872Z"}},"outputs":[],"execution_count":null}]}