Adversarial Deep Ensemble: Evasion Attacks and Defenses for Malware Detection

被引:75
|
作者
Li, Deqiang [1 ]
Li, Qianmu [1 ]
机构
[1] Nanjing Univ Sci & Technol, Sch Comp Sci & Engn, Nanjing 210094, Peoples R China
关键词
Adversarial Machine Learning; Deep Neural Networks; Ensemble; Adversarial Malware Detection;
D O I
10.1109/TIFS.2020.3003571
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Malware remains a big threat to cyber security, calling for machine learning based malware detection. While promising, such detectors are known to be vulnerable to evasion attacks. Ensemble learning typically facilitates countermeasures, while attackers can leverage this technique to improve attack effectiveness as well. This motivates us to investigate which kind of robustness the ensemble defense or effectiveness the ensemble attack can achieve, particularly when they combat with each other. We thus propose a new attack approach, named mixture of attacks, by rendering attackers capable of multiple generative methods and multiple manipulation sets, to perturb a malware example without ruining its malicious functionality. This naturally leads to a new instantiation of adversarial training, which is further geared to enhancing the ensemble of deep neural networks. We evaluate defenses using Android malware detectors against 26 different attacks upon two practical datasets. Experimental results show that the new adversarial training significantly enhances the robustness of deep neural networks against a wide range of attacks, ensemble methods promote the robustness when base classifiers are robust enough, and yet ensemble attacks can evade the enhanced malware detectors effectively, even notably downgrading the VirusTotal service.
引用
收藏
页码:3886 / 3900
页数:15
相关论文
共 50 条
  • [31] Robust Android Malware Detection against Adversarial Example Attacks
    Li, Heng
    Zhou, Shiyao
    Yuan, Wei
    Luo, Xiapu
    Gao, Cuiying
    Chen, Shuiyan
    [J]. PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021), 2021, : 3603 - 3612
  • [32] Adversarial Malware Binaries: Evading Deep Learning for Malware Detection in Executables
    Kolosnjaji, Bojan
    Demontis, Ambra
    Biggio, Battista
    Maiorca, Davide
    Giacinto, Giorgio
    Eckert, Claudia
    Roli, Fabio
    [J]. 2018 26TH EUROPEAN SIGNAL PROCESSING CONFERENCE (EUSIPCO), 2018, : 533 - 537
  • [33] Generative Ensemble Learning for Mitigating Adversarial Malware Detection in IoT
    Ahmed, Usman
    Lin, Jerry Chun-Wei
    Srivastava, Gautam
    [J]. 2021 IEEE 29TH INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP 2021), 2021,
  • [34] Investigating the practicality of adversarial evasion attacks on network intrusion detection
    Merzouk, Mohamed Amine
    Cuppens, Frederic
    Boulahia-Cuppens, Nora
    Yaich, Reda
    [J]. ANNALS OF TELECOMMUNICATIONS, 2022, 77 (11-12) : 763 - 775
  • [35] Investigating the practicality of adversarial evasion attacks on network intrusion detection
    Mohamed Amine Merzouk
    Frédéric Cuppens
    Nora Boulahia-Cuppens
    Reda Yaich
    [J]. Annals of Telecommunications, 2022, 77 : 763 - 775
  • [36] Deep learning adversarial attacks and defenses on license plate recognition system
    Vizcarra, Conrado
    Alhamed, Shadan
    Algosaibi, Abdulelah
    Alnaeem, Mohammed
    Aldalbahi, Adel
    Aljaafari, Nura
    Sawalmeh, Ahmad
    Nazzal, Mahmoud
    Khreishah, Abdallah
    Alhumam, Abdulaziz
    Anan, Muhammad
    [J]. CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2024, 27 (08): : 11627 - 11644
  • [37] How Deep Learning Sees the World: A Survey on Adversarial Attacks & Defenses
    Costa, Joana C.
    Roxo, Tiago
    Proenca, Hugo
    Inacio, Pedro Ricardo Morais
    [J]. IEEE ACCESS, 2024, 12 : 61113 - 61136
  • [38] On Effectiveness of Adversarial Examples and Defenses for Malware Classification
    Podschwadt, Robert
    Takabi, Hassan
    [J]. SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM, PT II, 2019, 305 : 380 - 393
  • [39] Black-Box Adversarial Attacks Against Deep Learning Based Malware Binaries Detection with GAN
    Yuan, Junkun
    Zhou, Shaofang
    Lin, Lanfen
    Wang, Feng
    Cui, Jia
    [J]. ECAI 2020: 24TH EUROPEAN CONFERENCE ON ARTIFICIAL INTELLIGENCE, 2020, 325 : 2536 - 2542
  • [40] Unveiling vulnerabilities in deep learning-based malware detection: Differential privacy driven adversarial attacks
    Taheri, Rahim
    Shojafar, Mohammad
    Arabikhan, Farzad
    Gegov, Alexander
    [J]. COMPUTERS & SECURITY, 2024, 146