On the effectiveness of adversarial samples against ensemble learning-based windows PE malware detectors

被引:0
|
作者
To, Trong-Nghia [1 ,2 ]
Kim, Danh Le [1 ,2 ]
Hien, Do Thi Thu [1 ,2 ]
Khoa, Nghi Hoang [1 ,2 ]
Hoang, Hien Do [1 ,2 ]
Duy, Phan The [1 ,2 ]
Pham, Van-Hau [1 ,2 ]
机构
[1] Univ Informat Technol, Ho Chi Minh City, Vietnam
[2] Vietnam Natl Univ, Ho Chi Minh City, Vietnam
关键词
Evasion attack; Adversarial attack; Generative adversarial networks; Reinforcement learning; Ensemble learning; Explainable artificial intelligence;
D O I
10.1007/s10207-024-00969-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The cybersecurity landscape is witnessing an increasing prevalence of threats and malicious programs, posing formidable challenges to conventional detection techniques. Although machine learning (ML) and deep learning (DL) have demonstrated effectiveness in malware detection, their susceptibility to adversarial attacks has led to a growing research trend. This study aims to provide a general framework that uses Reinforcement Learning and Explainable Artificial Intelligence (XAI) to generate and evaluate mutant Windows malware within the problem space. We concentrate on the three primary problems that arise while performing adversarial attacks on Windows Portable Executable malware, including format preservation, executability preservation, and maliciousness preservation. Additionally, we present an innovative approach called SHAPex to evaluate and clarify the impact of input feature predictions on malware detection predictions. This approach aims to optimize the application of results to future research efforts through three key questions pertaining to the predictive capacity of the ML/DL model. Experimental findings reveal that 100% of the selected mutation samples maintain their format integrity. Additionally, our system ensures the preservation of executable functionality in malware variants, yielding consistent and promising results. We have also encapsulated the analytical outcomes regarding the impact of input features on malware detectors' prediction decisions within a specialized framework based on three research questions, emphasizing the predictive capacity of ML/DL models.
引用
收藏
页数:30
相关论文
共 50 条
  • [1] Effectiveness of machine learning based android malware detectors against adversarial attacks
    Jyothish, A.
    Mathew, Ashik
    Vinod, P.
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (03): : 2549 - 2569
  • [2] Windows PE Malware Detection Using Ensemble Learning
    Azeez, Nureni Ayofe
    Odufuwa, Oluwanifise Ebunoluwa
    Misra, Sanjay
    Oluranti, Jonathan
    Damasevicius, Robertas
    INFORMATICS-BASEL, 2021, 8 (01):
  • [3] A novel method for improving the robustness of deep learning-based malware detectors against adversarial attacks
    Shaukat, Kamran
    Luo, Suhuai
    Varadharajan, Vijay
    ENGINEERING APPLICATIONS OF ARTIFICIAL INTELLIGENCE, 2022, 116
  • [4] Evaluating Realistic Adversarial Attacks against Machine Learning Models for Windows PE Malware Detection
    Imran, Muhammad
    Appice, Annalisa
    Malerba, Donato
    FUTURE INTERNET, 2024, 16 (05)
  • [5] Towards a Practical Defense Against Adversarial Attacks on Deep Learning-Based Malware Detectors via Randomized Smoothing
    Gibert, Daniel
    Zizzo, Giulio
    Le, Quan
    COMPUTER SECURITY. ESORICS 2023 INTERNATIONAL WORKSHOPS, CPS4CIP, PT II, 2024, 14399 : 683 - 699
  • [6] Adversarial Robustness of Deep Learning-Based Malware Detectors via (De)Randomized Smoothing
    Gibert, Daniel
    Zizzo, Giulio
    Le, Quan
    Planes, Jordi
    IEEE ACCESS, 2024, 12 : 61152 - 61162
  • [7] Adversarial attacks against Windows PE malware detection: A survey of the state-of-the-art
    Ling, Xiang
    Wu, Lingfei
    Zhang, Jiangyu
    Qu, Zhenqing
    Deng, Wei
    Chen, Xiang
    Qian, Yaguan
    Wu, Chunming
    Ji, Shouling
    Luo, Tianyue
    Wu, Jingzheng
    Wu, Yanjun
    COMPUTERS & SECURITY, 2023, 128
  • [8] On the Deterioration of Learning-Based Malware Detectors for Android
    Fu, Xiaoqin
    Cai, Haipeng
    2019 IEEE/ACM 41ST INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS (ICSE-COMPANION 2019), 2019, : 272 - 273
  • [9] An Ensemble Learning-Based Cooperative Defensive Architecture Against Adversarial Attacks
    Liu, Tian
    Song, Yunfei
    Hu, Ming
    Xia, Jun
    Zhang, Jianning
    Chen, Mingsong
    JOURNAL OF CIRCUITS SYSTEMS AND COMPUTERS, 2021, 30 (02)
  • [10] DroidEye: Fortifying Security of Learning-based Classifier against Adversarial Android Malware Attacks
    Chen, Lingwei
    Hou, Shifu
    Ye, Yanfang
    Xu, Shouhuai
    2018 IEEE/ACM INTERNATIONAL CONFERENCE ON ADVANCES IN SOCIAL NETWORKS ANALYSIS AND MINING (ASONAM), 2018, : 782 - 789