On the effectiveness of adversarial samples against ensemble learning-based windows PE malware detectors

被引:0
|
作者
To, Trong-Nghia [1 ,2 ]
Kim, Danh Le [1 ,2 ]
Hien, Do Thi Thu [1 ,2 ]
Khoa, Nghi Hoang [1 ,2 ]
Hoang, Hien Do [1 ,2 ]
Duy, Phan The [1 ,2 ]
Pham, Van-Hau [1 ,2 ]
机构
[1] Univ Informat Technol, Ho Chi Minh City, Vietnam
[2] Vietnam Natl Univ, Ho Chi Minh City, Vietnam
关键词
Evasion attack; Adversarial attack; Generative adversarial networks; Reinforcement learning; Ensemble learning; Explainable artificial intelligence;
D O I
10.1007/s10207-024-00969-y
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The cybersecurity landscape is witnessing an increasing prevalence of threats and malicious programs, posing formidable challenges to conventional detection techniques. Although machine learning (ML) and deep learning (DL) have demonstrated effectiveness in malware detection, their susceptibility to adversarial attacks has led to a growing research trend. This study aims to provide a general framework that uses Reinforcement Learning and Explainable Artificial Intelligence (XAI) to generate and evaluate mutant Windows malware within the problem space. We concentrate on the three primary problems that arise while performing adversarial attacks on Windows Portable Executable malware, including format preservation, executability preservation, and maliciousness preservation. Additionally, we present an innovative approach called SHAPex to evaluate and clarify the impact of input feature predictions on malware detection predictions. This approach aims to optimize the application of results to future research efforts through three key questions pertaining to the predictive capacity of the ML/DL model. Experimental findings reveal that 100% of the selected mutation samples maintain their format integrity. Additionally, our system ensures the preservation of executable functionality in malware variants, yielding consistent and promising results. We have also encapsulated the analytical outcomes regarding the impact of input features on malware detectors' prediction decisions within a specialized framework based on three research questions, emphasizing the predictive capacity of ML/DL models.
引用
收藏
页数:30
相关论文
共 50 条
  • [31] Study of Ensemble Learning-Based Fusion Prognostics
    Sun Jianzhong
    Zuo Hongfu
    Yang Haibin
    Pecht, Michael
    2010 PROGNOSTICS AND SYSTEM HEALTH MANAGEMENT CONFERENCE, 2010, : 82 - +
  • [32] Evaluating Deep Learning-based NIDS in Adversarial Settings
    Mohammadian, Hesamodin
    Lashkari, Arash Habibi
    Ghorbani, Ali A.
    PROCEEDINGS OF THE 8TH INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY (ICISSP), 2021, : 435 - 444
  • [33] Adversarial Attacks Against Image-Based Malware Detection Using Autoencoders
    Carey, Alycia N.
    Mai, Huy
    Zhan, Justin
    Mehmood, Asif
    PATTERN RECOGNITION AND TRACKING XXXII, 2021, 11735
  • [34] ResNet and Transformer Hybrid Malware Classification Model Based on Ensemble Learning
    Li, Kewei
    Liu, Fudong
    PROCEEDINGS OF 2023 7TH INTERNATIONAL CONFERENCE ON ELECTRONIC INFORMATION TECHNOLOGY AND COMPUTER ENGINEERING, EITCE 2023, 2023, : 1269 - 1275
  • [35] IMaler: An Adversarial Attack Framework to Obfuscate Malware Structure against DGCNN-based Classifier via Reinforcement Learning
    Chen, Yanhui
    Feng, Yun
    Wang, Zhi
    Zhao, Jianjun
    Wang, Chengchun
    Liu, Qixu
    ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 790 - 796
  • [36] A Robust Malware Detection Approach for Android System Based on Ensemble Learning
    Li, Wenjia
    Cai, Juecong
    Wang, Zi
    Cheng, Sihua
    UBIQUITOUS SECURITY, 2022, 1557 : 309 - 321
  • [37] Fortifying graph neural networks against adversarial attacks via ensemble learning
    Zhou, Chenyu
    Huang, Wei
    Miao, Xinyuan
    Peng, Yabin
    Kong, Xianglong
    Cao, Yi
    Chen, Xi
    KNOWLEDGE-BASED SYSTEMS, 2025, 309
  • [38] Ensemble learning-based HVDC systems fault diagnosis
    Li Q.
    Chen Q.
    Wu J.
    Peng G.
    Huang X.
    Li Z.
    Yang B.
    Dianli Xitong Baohu yu Kongzhi/Power System Protection and Control, 2023, 51 (16): : 168 - 178
  • [39] MADVEX: Instrumentation-Based Adversarial Attacks on Machine Learning Malware Detection
    Loose, Nils
    Maechtle, Felix
    Pott, Claudius
    Bezsmertnyi, Volodymyr
    Eisenbarth, Thomas
    DETECTION OF INTRUSIONS AND MALWARE, AND VULNERABILITY ASSESSMENT, DIMVA 2023, 2023, 13959 : 69 - 88
  • [40] Ensemble-Based Distributed Learning for Generative Adversarial Networks
    Liu, Chonghe
    Ren, Jinke
    Yu, Guanding
    2022 IEEE 95TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2022-SPRING), 2022,