On the effectiveness of adversarial samples against ensemble learning-based windows PE malware detectors

被引:0
|
作者
To, Trong-Nghia [1 ,2 ]
Kim, Danh Le [1 ,2 ]
Hien, Do Thi Thu [1 ,2 ]
Khoa, Nghi Hoang [1 ,2 ]
Hoang, Hien Do [1 ,2 ]
Duy, Phan The [1 ,2 ]
Pham, Van-Hau [1 ,2 ]
机构
[1] Univ Informat Technol, Ho Chi Minh City, Vietnam
[2] Vietnam Natl Univ, Ho Chi Minh City, Vietnam
关键词
Evasion attack; Adversarial attack; Generative adversarial networks; Reinforcement learning; Ensemble learning; Explainable artificial intelligence;
D O I
10.1007/s10207-024-00969-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The cybersecurity landscape is witnessing an increasing prevalence of threats and malicious programs, posing formidable challenges to conventional detection techniques. Although machine learning (ML) and deep learning (DL) have demonstrated effectiveness in malware detection, their susceptibility to adversarial attacks has led to a growing research trend. This study aims to provide a general framework that uses Reinforcement Learning and Explainable Artificial Intelligence (XAI) to generate and evaluate mutant Windows malware within the problem space. We concentrate on the three primary problems that arise while performing adversarial attacks on Windows Portable Executable malware, including format preservation, executability preservation, and maliciousness preservation. Additionally, we present an innovative approach called SHAPex to evaluate and clarify the impact of input feature predictions on malware detection predictions. This approach aims to optimize the application of results to future research efforts through three key questions pertaining to the predictive capacity of the ML/DL model. Experimental findings reveal that 100% of the selected mutation samples maintain their format integrity. Additionally, our system ensures the preservation of executable functionality in malware variants, yielding consistent and promising results. We have also encapsulated the analytical outcomes regarding the impact of input features on malware detectors' prediction decisions within a specialized framework based on three research questions, emphasizing the predictive capacity of ML/DL models.
引用
收藏
页数:30
相关论文
共 50 条
  • [31] Generating Adversarial Examples for Static PE Malware Detector Based on Deep Reinforcement Learning
    Chen, Jun
    Jiang, Jingfei
    Li, Rongchun
    Dou, Yong
    5TH ANNUAL INTERNATIONAL CONFERENCE ON INFORMATION SYSTEM AND ARTIFICIAL INTELLIGENCE (ISAI2020), 2020, 1575
  • [32] Feature-Based Adversarial Attacks Against Machine Learnt Mobile Malware Detectors
    Shahpasand, Maryam
    Hamey, Leonard
    Kaafar, Mohamed Ali
    Vatsalan, Dinusha
    2020 30TH INTERNATIONAL TELECOMMUNICATION NETWORKS AND APPLICATIONS CONFERENCE (ITNAC), 2020, : 135 - 142
  • [33] Adversarial Attack on Microarchitectural Events based Malware Detectors
    Dinakarrao, Sai Manoj Pudukotai
    Amberkar, Sairaj
    Bhat, Sahil
    Dhavlle, Abhijitt
    Sayadi, Hossein
    Sasan, Avesta
    Homayoun, Houman
    Rafatirad, Setareh
    PROCEEDINGS OF THE 2019 56TH ACM/EDAC/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2019,
  • [34] Adversarial Examples for CNN-Based Malware Detectors
    Chen, Bingcai
    Ren, Zhongru
    Yu, Chao
    Hussain, Iftikhar
    Liu, Jintao
    IEEE ACCESS, 2019, 7 : 54360 - 54371
  • [35] Adversarial Attacks on Transformers-Based Malware Detectors
    Jakhotiya, Yash
    Patil, Heramb
    Rawlani, Jugal
    Mane, Sunil B.
    arXiv, 2022,
  • [36] Generative Ensemble Learning for Mitigating Adversarial Malware Detection in IoT
    Ahmed, Usman
    Lin, Jerry Chun-Wei
    Srivastava, Gautam
    2021 IEEE 29TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP 2021), 2021,
  • [37] Beyond the Hype: An Evaluation of Commercially Available Machine Learning-based Malware Detectors
    Bridges, Robert A.
    Oesch, Sean
    Iannacone, Michael D.
    Huffer, Kelly M. T.
    Jewell, Brian
    Nichols, Jeff A.
    Weber, Brian
    Verma, Miki E.
    Scofield, Daniel
    Miles, Craig
    Plummer, Thomas
    Daniell, Mark
    Tall, Anne M.
    Beaver, Justin M.
    Smith, Jared M.
    DIGITAL THREATS: RESEARCH AND PRACTICE, 2023, 4 (02):
  • [38] Detection of different windows PE malware using machine learning methods
    Kocak, Aynur
    Sogut, Esra
    Alkan, Mustafa
    Erdem, O. Ayhan
    JOURNAL OF POLYTECHNIC-POLITEKNIK DERGISI, 2023, 26 (03): : 1185 - 1197
  • [39] Evading Deep Learning-Based Malware Detectors via Obfuscation: A Deep Reinforcement Learning Approach
    Etter, Brian
    Hu, James Lee
    Ebrahimi, Mohammadreza
    Li, Weifeng
    Li, Xin
    Chen, Hsinchun
    2023 23RD IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS, ICDMW 2023, 2023, : 1313 - 1321
  • [40] GAN-based Approach to Crafting Adversarial Malware Examples against a Heterogeneous Ensemble Classifier
    Al-Ahmadi, Saad
    Al-Eyead, Saud
    SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY, 2022, : 451 - 460