On the effectiveness of adversarial samples against ensemble learning-based windows PE malware detectors

被引:0
|
作者
To, Trong-Nghia [1 ,2 ]
Kim, Danh Le [1 ,2 ]
Hien, Do Thi Thu [1 ,2 ]
Khoa, Nghi Hoang [1 ,2 ]
Hoang, Hien Do [1 ,2 ]
Duy, Phan The [1 ,2 ]
Pham, Van-Hau [1 ,2 ]
机构
[1] Univ Informat Technol, Ho Chi Minh City, Vietnam
[2] Vietnam Natl Univ, Ho Chi Minh City, Vietnam
关键词
Evasion attack; Adversarial attack; Generative adversarial networks; Reinforcement learning; Ensemble learning; Explainable artificial intelligence;
D O I
10.1007/s10207-024-00969-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The cybersecurity landscape is witnessing an increasing prevalence of threats and malicious programs, posing formidable challenges to conventional detection techniques. Although machine learning (ML) and deep learning (DL) have demonstrated effectiveness in malware detection, their susceptibility to adversarial attacks has led to a growing research trend. This study aims to provide a general framework that uses Reinforcement Learning and Explainable Artificial Intelligence (XAI) to generate and evaluate mutant Windows malware within the problem space. We concentrate on the three primary problems that arise while performing adversarial attacks on Windows Portable Executable malware, including format preservation, executability preservation, and maliciousness preservation. Additionally, we present an innovative approach called SHAPex to evaluate and clarify the impact of input feature predictions on malware detection predictions. This approach aims to optimize the application of results to future research efforts through three key questions pertaining to the predictive capacity of the ML/DL model. Experimental findings reveal that 100% of the selected mutation samples maintain their format integrity. Additionally, our system ensures the preservation of executable functionality in malware variants, yielding consistent and promising results. We have also encapsulated the analytical outcomes regarding the impact of input features on malware detectors' prediction decisions within a specialized framework based on three research questions, emphasizing the predictive capacity of ML/DL models.
引用
收藏
页数:30
相关论文
共 50 条
  • [21] Lung Cancer Classification using Reinforcement Learning-based Ensemble Learning
    Luo, Shengping
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (08) : 1112 - 1122
  • [22] Adversarial Machine Learning-Based Anticipation of Threats Against Vehicle-to-Microgrid Services
    Omara, Ahmed
    Kantarci, Burak
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 1844 - 1849
  • [23] Ensemble Deep Learning Classification Method Based on Generative Adversarial Networks
    Shen, Haoyuan
    Lin, Chenglong
    Ma, Yizhong
    Xie, En
    2024 16TH INTERNATIONAL CONFERENCE ON COMPUTER AND AUTOMATION ENGINEERING, ICCAE 2024, 2024, : 46 - 53
  • [24] ELAA: An Ensemble-Learning-Based Adversarial Attack Targeting Image-Classification Model
    Fu, Zhongwang
    Cui, Xiaohui
    ENTROPY, 2023, 25 (02)
  • [25] Adversarial Examples Against Image-based Malware Classification Systems
    Vi, Bao Ngoc
    Nguyen, Huu Noi
    Nguyen, Ngoc Tran
    Tran, Cao Truong
    PROCEEDINGS OF 2019 11TH INTERNATIONAL CONFERENCE ON KNOWLEDGE AND SYSTEMS ENGINEERING (KSE 2019), 2019, : 347 - 351
  • [26] Defending malware detection models against evasion based adversarial attacks
    Rathore, Hemant
    Sasan, Animesh
    Sahay, Sanjay K.
    Sewak, Mohit
    PATTERN RECOGNITION LETTERS, 2022, 164 : 119 - 125
  • [27] Multiview-Ensemble-Learning-Based Robust Graph Convolutional Networks Against Adversarial Attacks
    Wu, Tao
    Luo, Junhui
    Qiao, Shaojie
    Wang, Chao
    Yuan, Lin
    Pu, Xiao
    Xian, Xingping
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (16): : 27700 - 27714
  • [28] Adversarial Attacks and Detection on Reinforcement Learning-Based Interactive Recommender Systems
    Cao, Yuanjiang
    Chen, Xiaocong
    Yao, Lina
    Wang, Xianzhi
    Zhang, Wei Emma
    PROCEEDINGS OF THE 43RD INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL (SIGIR '20), 2020, : 1669 - 1672
  • [29] Generating Adversarial Examples Against Machine Learning-Based Intrusion Detector in Industrial Control Systems
    Chen, Jiming
    Gao, Xiangshan
    Deng, Ruilong
    He, Yang
    Fang, Chongrong
    Cheng, Peng
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (03) : 1810 - 1825
  • [30] Channel-Aware Adversarial Attacks Against Deep Learning-Based Wireless Signal Classifiers
    Kim, Brian
    Sagduyu, Yalin E.
    Davaslioglu, Kemal
    Erpek, Tugba
    Ulukus, Sennur
    IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2022, 21 (06) : 3868 - 3880