PAD: Towards Principled Adversarial Malware Detection Against Evasion Attacks

被引:0
|
作者
Li, Deqiang [1 ]
Cui, Shicheng [2 ]
Li, Yun [1 ]
Xu, Jia [1 ]
Xiao, Fu [1 ]
Xu, Shouhuai [3 ]
机构
[1] Nanjing Univ Posts & Telecommun, Sch Comp Sci, Nanjing 210023, Peoples R China
[2] Nanjing Inst Technol, Sch Comp Engn, Nanjing 211167, Peoples R China
[3] Univ Colorado Colorado Springs, Dept Comp Sci, Colorado Springs, CO 80918 USA
关键词
Adversarial example; deep neural network; evasion attack; malware detection; provable defense; DEFENSES;
D O I
10.1109/TDSC.2023.3265665
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Machine Learning (ML) techniques can facilitate the automation of malicious software (malware for short) detection, but suffer from evasion attacks. Many studies counter such attacks in heuristic manners, lacking theoretical guarantees and defense effectiveness. In this article, we propose a new adversarial training framework, termed Principled Adversarial Malware Detection (PAD), which offers convergence guarantees for robust optimization methods. PAD lays on a learnable convex measurement that quantifies distribution-wise discrete perturbations to protect malware detectors from adversaries, whereby for smooth detectors, adversarial training can be performed with theoretical treatments. To promote defense effectiveness, we propose a new mixture of attacks to instantiate PAD to enhance deep neural network-based measurements and malware detectors. Experimental results on two Android malware datasets demonstrate: (i) the proposed method significantly outperforms the state-of-the-art defenses; (ii) it can harden ML-based malware detection against 27 evasion attacks with detection accuracies greater than 83.45%, at the price of suffering an accuracy decrease smaller than 2.16% in the absence of attacks; (iii) it matches or outperforms many anti-malware scanners in VirusTotal against realistic adversarial malware.
引用
收藏
页码:920 / 936
页数:17
相关论文
共 50 条
  • [41] Black-Box Adversarial Attacks Against Deep Learning Based Malware Binaries Detection with GAN
    Yuan, Junkun
    Zhou, Shaofang
    Lin, Lanfen
    Wang, Feng
    Cui, Jia
    [J]. ECAI 2020: 24TH EUROPEAN CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2020, 325 : 2536 - 2542
  • [42] SecureDroid: Enhancing Security of Machine Learning-based Detection against Adversarial Android Malware Attacks
    Chen, Lingwei
    Hou, Shifu
    Ye, Yanfang
    [J]. 33RD ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2017), 2017, : 362 - 372
  • [43] Evaluating Resilience of Encrypted Traffic Classification against Adversarial Evasion Attacks
    Maarouf, Ramy
    Sattar, Danish
    Matrawy, Ashraf
    [J]. 26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [44] DiffAttack: Evasion Attacks Against Diffusion-Based Adversarial Purification
    Kang, Mintong
    Song, Dawn
    Li, Bo
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [45] EAGLE: Evasion Attacks Guided by Local Explanations Against Android Malware Classification
    Shu, Zhan
    Yan, Guanhua
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 3165 - 3182
  • [46] Robust Malware Detection Models: Learning from Adversarial Attacks and Defenses
    Rathore, Hemant
    Samavedhi, Adithya
    Sahay, Sanjay K.
    Sewak, Mohit
    [J]. FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2021, 37
  • [47] Adversarial-Example Attacks Toward Android Malware Detection System
    Li, Heng
    Zhou, ShiYao
    Yuan, Wei
    Li, Jiahuan
    Leung, Henry
    [J]. IEEE SYSTEMS JOURNAL, 2020, 14 (01): : 653 - 656
  • [48] Towards Adversarially Superior Malware Detection Models: An Adversary Aware Proactive Approach using Adversarial Attacks and Defenses
    Hemant Rathore
    Adithya Samavedhi
    Sanjay K. Sahay
    Mohit Sewak
    [J]. Information Systems Frontiers, 2023, 25 : 567 - 587
  • [49] Towards Adversarially Superior Malware Detection Models: An Adversary Aware Proactive Approach using Adversarial Attacks and Defenses
    Rathore, Hemant
    Samavedhi, Adithya
    Sahay, Sanjay K.
    Sewak, Mohit
    [J]. INFORMATION SYSTEMS FRONTIERS, 2023, 25 (02) : 567 - 587
  • [50] On the robustness of skeleton detection against adversarial attacks
    Bai, Xiuxiu
    Yang, Ming
    Liu, Zhe
    [J]. NEURAL NETWORKS, 2020, 132 : 416 - 427