ELAMD: An ensemble learning framework for adversarial malware defense

被引:1
|
作者
Chen, Jiaqi [1 ]
Yuan, Chong [1 ]
Li, Jiashuo [1 ]
Tian, Donghai [1 ]
Ma, Rui [1 ]
Jia, Xiaoqi [2 ]
机构
[1] Beijing Inst Technol, Beijing Key Lab Software Secur Engn Tech, Beijing 100081, Peoples R China
[2] Chinese Acad Sci, Inst Informat Engn, Key Lab Network Assessment Technol, Beijing 100049, Peoples R China
关键词
Ensemble learning; Adversarial defense; Semi-supervised learning; Anomaly detection; Malware detection;
D O I
10.1016/j.jisa.2023.103508
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning-based methods have been widely used in malware detection. However, recent studies show that models based on machine learning (or deep learning) are vulnerable to adversarial attacks. For example, slight perturbation to input can cause the models to produce false detection results with high confidence. Although some research efforts have been made to defend against adversarial attacks, the existing methods suffer from limitations in terms of detection accuracy and labeling cost. To address this problem, we propose an ensemble learning framework for Windows malware adversarial defense that contains two methods. The first one is an adversarial sample detection method to defeat specific adversarial attacks. This method takes malware features into groups and uses ensemble learning to detect the adversarial sample. The second one is an anomaly detection method to defend against agnostic adversarial attacks. This method regards adversarial samples as outliers and utilizes unsupervised and semi-supervised learning to construct anomaly detection models. We use the adversarial defense methods proposed as supplementary modules to the original malware detection models. Experiments show that our methods can improve malware detection model robustness against adversarial attacks. Moreover, comparison experiments indicate that our methods outperform traditional adversarial training by about 11% on detection accuracy.
引用
收藏
页数:14
相关论文
共 50 条
  • [1] Generative Ensemble Learning for Mitigating Adversarial Malware Detection in IoT
    Ahmed, Usman
    Lin, Jerry Chun-Wei
    Srivastava, Gautam
    [J]. 2021 IEEE 29TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP 2021), 2021,
  • [2] MAB-MALWARE: A Reinforcement Learning Framework for Blackbox Generation of Adversarial Malware
    Song, Wei
    Li, Xuezixiang
    Afroz, Sadia
    Garg, Deepali
    Kuznetsov, Dmitry
    Yin, Heng
    [J]. ASIA CCS'22: PROCEEDINGS OF THE 2022 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2022, : 990 - 1003
  • [3] An Effective Ensemble Deep Learning Framework for Malware Detection
    Dinh Viet Sang
    Dang Manh Cuong
    Le Tran Bao Cuong
    [J]. PROCEEDINGS OF THE NINTH INTERNATIONAL SYMPOSIUM ON INFORMATION AND COMMUNICATION TECHNOLOGY (SOICT 2018), 2018, : 192 - 199
  • [4] MFDroid: A Stacking Ensemble Learning Framework for Android Malware Detection
    Wang, Xusheng
    Zhang, Linlin
    Zhao, Kai
    Ding, Xuhui
    Yu, Mingming
    [J]. SENSORS, 2022, 22 (07)
  • [5] EnsGuard: A Novel Acceleration Framework for Adversarial Ensemble Learning
    Wang, Xingbin
    Wang, Yan
    Su, Yulan
    Zhang, Sisi
    Meng, Dan
    Hou, Rui
    [J]. IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2024, 43 (10) : 3088 - 3101
  • [6] An Adversarial Reinforcement Learning Framework for Robust Machine Learning-based Malware Detection
    Ebrahimi, Mohammadreza
    Li, Weifeng
    Chai, Yidong
    Pacheco, Jason
    Chen, Hsinchun
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS, ICDMW, 2022, : 567 - 576
  • [7] FENOC: An Ensemble One-Class Learning Framework for Malware Detection
    Liu, Jiachen
    Song, Jianfeng
    Miao, Qiguang
    Cao, Ying
    [J]. 2013 9TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS), 2013, : 523 - 527
  • [8] Understanding and Improving Ensemble Adversarial Defense
    Deng, Yian
    Mu, Tingting
    [J]. ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [9] Adversarial Machine Learning in Malware Detection: Arms Race between Evasion Attack and Defense
    Chen, Lingwei
    Ye, Yanfang
    Bourlai, Thirimachos
    [J]. 2017 EUROPEAN INTELLIGENCE AND SECURITY INFORMATICS CONFERENCE (EISIC), 2017, : 99 - 106
  • [10] Ensemble dynamic behavior detection method for adversarial malware
    Jing, Chao
    Wu, Yun
    Cui, Chaoyuan
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2022, 130 : 193 - 206