Adversarial attacks pose a significant problem in malware detection because they allow relatively simple modifications to already detected malware to recreate undetectable malware and cause misclassification in machine learning models, even in black-box scenarios. The goal of this work is to study defensive techniques and implement a tool that can mitigate the impact of these attacks by preprocessing samples to minimize the attack surface needed to create adversarial samples. Our technique has been subjected to rigorous testing against a number of adversarial generators. The results of this testing have demonstrated the efficacy of our approach, with a notable reduction in the evasion rate of detection for most generators to zero percent. This has been achieved without any adverse impact on the detection accuracy of common malware.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Reducing the Surface for Adversarial Attacks in Malware Detectors

  • Benjamín Peraus,
  • Martin Jureček

摘要

Adversarial attacks pose a significant problem in malware detection because they allow relatively simple modifications to already detected malware to recreate undetectable malware and cause misclassification in machine learning models, even in black-box scenarios. The goal of this work is to study defensive techniques and implement a tool that can mitigate the impact of these attacks by preprocessing samples to minimize the attack surface needed to create adversarial samples. Our technique has been subjected to rigorous testing against a number of adversarial generators. The results of this testing have demonstrated the efficacy of our approach, with a notable reduction in the evasion rate of detection for most generators to zero percent. This has been achieved without any adverse impact on the detection accuracy of common malware.