Malware detection traditionally relies on signature-based approaches, which suffer from limited generalization. To mitigate this issue, machine learning (ML)-based detection methods have been integrated with signature-based methods in recent years. However, ML-based detectors are vulnerable to adversarial attacks, particularly those leveraging Generative Adversarial Networks (GAN) to alter the features of malware while retaining its malicious purpose and bypassing detection. In this paper, we present an innovative defense mechanism called REMEDII (Robust Malware Detection with Iterative Adversarial Training), which improves the robustness of ML-based malware detectors. REMEDII iteratively generates mini-batches of adversarial samples from newly trained instances of GANs and intelligently selects samples with maximum hamming (bit-wise) distance from benign data, ensuring more robust training and mitigating overfitting. Extensive experiments with various ML classifiers (e.g., Convolutional Neural Networks) show that REMEDII achieves over 85% adversarial robustness against GAN-based attacks while maintaining a benign accuracy drop of less than 2%. These results significantly outperform existing defense techniques, which achieve very low adversarial robustness (<2%).

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

REMEDII: Robust Malware Detection with Iterative and Intelligent Adversarial Training

  • Sanchit Gupta,
  • Vireshwar Kumar

摘要

Malware detection traditionally relies on signature-based approaches, which suffer from limited generalization. To mitigate this issue, machine learning (ML)-based detection methods have been integrated with signature-based methods in recent years. However, ML-based detectors are vulnerable to adversarial attacks, particularly those leveraging Generative Adversarial Networks (GAN) to alter the features of malware while retaining its malicious purpose and bypassing detection. In this paper, we present an innovative defense mechanism called REMEDII (Robust Malware Detection with Iterative Adversarial Training), which improves the robustness of ML-based malware detectors. REMEDII iteratively generates mini-batches of adversarial samples from newly trained instances of GANs and intelligently selects samples with maximum hamming (bit-wise) distance from benign data, ensuring more robust training and mitigating overfitting. Extensive experiments with various ML classifiers (e.g., Convolutional Neural Networks) show that REMEDII achieves over 85% adversarial robustness against GAN-based attacks while maintaining a benign accuracy drop of less than 2%. These results significantly outperform existing defense techniques, which achieve very low adversarial robustness (<2%).