StratDef: Strategic defense against adversarial attacks in ML-based malware detection

被引:1
|
作者
Rashid, Aqib [1 ]
Such, Jose [1 ]
机构
[1] Kings Coll London, Dept Informat, London WC2R 2LS, England
关键词
Adversarial machine learning; Adversarial examples; Malware detection; Machine learning security; Deep learning;
D O I
10.1016/j.cose.2023.103459
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the years, most research towards defenses against adversarial attacks on machine learning models has been in the image recognition domain. The ML-based malware detection domain has received less attention despite its importance. Moreover, most work exploring these defenses has focused on several methods but with no strategy when applying them. In this paper, we introduce StratDef, which is a strategic defense system based on a moving target defense approach. We overcome challenges related to the systematic construction, selection, and strategic use of models to maximize adversarial robustness. StratDef dynamically and strategically chooses the best models to increase the uncertainty for the attacker while minimizing critical aspects in the adversarial ML domain, like attack transferability. We provide the first comprehensive evaluation of defenses against adversarial attacks on machine learning for malware detection, where our threat model explores different levels of threat, attacker knowledge, capabilities, and attack intensities. We show that StratDef performs better than other defenses even when facing the peak adversarial threat. We also show that, of the existing defenses, only a few adversariallytrained models provide substantially better protection than just using vanilla models but are still outperformed by StratDef.
引用
收藏
页数:18
相关论文
共 50 条
  • [41] AdvRefactor: A Resampling-Based Defense Against Adversarial Attacks
    Jiang, Jianguo
    Li, Boquan
    Yu, Min
    Liu, Chao
    Sun, Jianguo
    Huang, Weiqing
    Lv, Zhiqiang
    ADVANCES IN MULTIMEDIA INFORMATION PROCESSING - PCM 2018, PT II, 2018, 11165 : 815 - 825
  • [42] ROLDEF: RObust Layered DEFense for Intrusion Detection Against Adversarial Attacks
    Gungor, Onat
    Rosing, Tajana
    Alcsanli, Bans
    2024 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION, DATE, 2024,
  • [43] Eluding ML-based Adblockers With Actionable Adversarial Examples
    Zhu, Shitong
    Wang, Zhongjie
    Chen, Xun
    Li, Shasha
    Man, Keyu
    Iqbal, Umar
    Qian, Zhiyun
    Chan, Kevin S.
    Krishnamurthy, Srikanth V.
    Shafiq, Zubair
    Hao, Yu
    Li, Guoren
    Zhang, Zheng
    Zou, Xiaochen
    37TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2021, 2021, : 541 - 553
  • [44] Effectiveness of machine learning based android malware detectors against adversarial attacks
    Jyothish, A.
    Mathew, Ashik
    Vinod, P.
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (03): : 2549 - 2569
  • [45] Adversarial attacks against Windows PE malware detection: A survey of the state-of-the-art
    Ling, Xiang
    Wu, Lingfei
    Zhang, Jiangyu
    Qu, Zhenqing
    Deng, Wei
    Chen, Xiang
    Qian, Yaguan
    Wu, Chunming
    Ji, Shouling
    Luo, Tianyue
    Wu, Jingzheng
    Wu, Yanjun
    COMPUTERS & SECURITY, 2023, 128
  • [46] Systemically Evaluating the Robustness of ML-based IoT Malware Detectors
    Abusnaina, Ahmed
    Anwar, Afsah
    Alshamrani, Sultan
    Alabduljabbar, Abdulrahman
    Jang, Rhongho
    Nyang, Daehun
    Mohaisen, David
    51ST ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS - SUPPLEMENTAL VOL (DSN 2021), 2021, : 3 - 4
  • [47] On the Robustness of ML-Based Network Intrusion Detection Systems: An Adversarial and Distribution Shift Perspective
    Wang, Minxiao
    Yang, Ning
    Gunasinghe, Dulaj H.
    Weng, Ning
    COMPUTERS, 2023, 12 (10)
  • [48] Defense against Adversarial Attacks with an Induced Class
    Xu, Zhi
    Wang, Jun
    Pu, Jian
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [49] On the Defense of Spoofing Countermeasures Against Adversarial Attacks
    Nguyen-Vu, Long
    Doan, Thien-Phuc
    Bui, Mai
    Hong, Kihun
    Jung, Souhwan
    IEEE ACCESS, 2023, 11 : 94563 - 94574
  • [50] A Defense Method Against Facial Adversarial Attacks
    Sadu, Chiranjeevi
    Das, Pradip K.
    2021 IEEE REGION 10 CONFERENCE (TENCON 2021), 2021, : 459 - 463