On the effectiveness of adversarial samples against ensemble learning-based windows PE malware detectors

被引:0
|
作者
To, Trong-Nghia [1 ,2 ]
Kim, Danh Le [1 ,2 ]
Hien, Do Thi Thu [1 ,2 ]
Khoa, Nghi Hoang [1 ,2 ]
Hoang, Hien Do [1 ,2 ]
Duy, Phan The [1 ,2 ]
Pham, Van-Hau [1 ,2 ]
机构
[1] Univ Informat Technol, Ho Chi Minh City, Vietnam
[2] Vietnam Natl Univ, Ho Chi Minh City, Vietnam
关键词
Evasion attack; Adversarial attack; Generative adversarial networks; Reinforcement learning; Ensemble learning; Explainable artificial intelligence;
D O I
10.1007/s10207-024-00969-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The cybersecurity landscape is witnessing an increasing prevalence of threats and malicious programs, posing formidable challenges to conventional detection techniques. Although machine learning (ML) and deep learning (DL) have demonstrated effectiveness in malware detection, their susceptibility to adversarial attacks has led to a growing research trend. This study aims to provide a general framework that uses Reinforcement Learning and Explainable Artificial Intelligence (XAI) to generate and evaluate mutant Windows malware within the problem space. We concentrate on the three primary problems that arise while performing adversarial attacks on Windows Portable Executable malware, including format preservation, executability preservation, and maliciousness preservation. Additionally, we present an innovative approach called SHAPex to evaluate and clarify the impact of input feature predictions on malware detection predictions. This approach aims to optimize the application of results to future research efforts through three key questions pertaining to the predictive capacity of the ML/DL model. Experimental findings reveal that 100% of the selected mutation samples maintain their format integrity. Additionally, our system ensures the preservation of executable functionality in malware variants, yielding consistent and promising results. We have also encapsulated the analytical outcomes regarding the impact of input features on malware detectors' prediction decisions within a specialized framework based on three research questions, emphasizing the predictive capacity of ML/DL models.
引用
收藏
页数:30
相关论文
共 50 条
  • [21] SecureDroid: Enhancing Security of Machine Learning-based Detection against Adversarial Android Malware Attacks
    Chen, Lingwei
    Hou, Shifu
    Ye, Yanfang
    33RD ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2017), 2017, : 362 - 372
  • [22] AdVulCode: Generating Adversarial Vulnerable Code against Deep Learning-Based Vulnerability Detectors
    Yu, Xueqi
    Li, Zhen
    Huang, Xiang
    Zhao, Shasha
    ELECTRONICS, 2023, 12 (04)
  • [23] A Wolf in Sheep's Clothing: Query-Free Evasion Attacks Against Machine Learning-Based Malware Detectors with Generative Adversarial Networks
    Gibcrt, Daniel
    Planes, Jordi
    Lc, Quan
    Zizzo, Giulio
    2023 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS, EUROS&PW, 2023, : 415 - 426
  • [24] Certified Robustness of Static Deep Learning-based Malware Detectors against Patch and Append Attacks
    Gibert, Daniel
    Zizzo, Giulio
    Le, Quan
    PROCEEDINGS OF THE 16TH ACM WORKSHOP ON ARTIFICIAL INTELLIGENCE AND SECURITY, AISEC 2023, 2023, : 173 - 184
  • [25] An Adversarial Reinforcement Learning Framework for Robust Machine Learning-based Malware Detection
    Ebrahimi, Mohammadreza
    Li, Weifeng
    Chai, Yidong
    Pacheco, Jason
    Chen, Hsinchun
    2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS, ICDMW, 2022, : 567 - 576
  • [26] A Comprehensive Study on Learning-Based PE Malware Family Classification Methods
    Ma, Yixuan
    Liu, Shuang
    Jiang, Jiajun
    Chen, Guanhong
    Li, Keqiu
    PROCEEDINGS OF THE 29TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE '21), 2021, : 1314 - 1325
  • [27] ELAMD: An ensemble learning framework for adversarial malware defense
    Chen, Jiaqi
    Yuan, Chong
    Li, Jiashuo
    Tian, Donghai
    Ma, Rui
    Jia, Xiaoqi
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2023, 75
  • [28] Slowing Down the Aging of Learning-Based Malware Detectors With API Knowledge
    Zhang, Xiaohan
    Zhang, Mi
    Zhang, Yuan
    Zhong, Ming
    Zhang, Xin
    Cao, Yinzhi
    Yang, Min
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (02) : 902 - 916
  • [29] Vulnerability Evaluation of Android Malware Detectors against Adversarial Examples
    Ijas, A. H.
    Vinod, P.
    Zemmari, Akka
    Harikrishnan
    Poulose, Godvin
    Jose, Don
    Mercaldo, Francesco
    Martinelli, Fabio
    Santone, Antonella
    KNOWLEDGE-BASED AND INTELLIGENT INFORMATION & ENGINEERING SYSTEMS (KSE 2021), 2021, 192 : 3320 - 3331
  • [30] Adversarial Attack with Genetic Algorithm against IoT Malware Detectors
    Yuan, Peng
    Wang, Shanshan
    Zhao, Chuan
    Wang, Wenyue
    Bai, Daokuan
    Peng, Lizhi
    Chen, Zhenxiang
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 1413 - 1418