Towards Adversarially Superior Malware Detection Models: An Adversary Aware Proactive Approach using Adversarial Attacks and Defenses

被引:6
|
作者
Rathore, Hemant [1 ]
Samavedhi, Adithya [1 ]
Sahay, Sanjay K. [1 ]
Sewak, Mohit [2 ]
机构
[1] BITS Pilani, Dept CS & IS, Goa Campus, Pilani, Rajasthan, India
[2] Microsoft R&D, Secur & Compliance Res, Pilani, Rajasthan, India
关键词
Adversarial Robustness; Malware Detection; Machine Learning; Static Analysis;
D O I
10.1007/s10796-022-10331-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The android ecosystem (smartphones, tablets, etc.) has grown manifold in the last decade. However, the exponential surge of android malware is threatening the ecosystem. Literature suggests that android malware can be detected using machine and deep learning classifiers; however, these detection models might be vulnerable to adversarial attacks. This work investigates the adversarial robustness of twenty-four diverse malware detection models developed using two features and twelve learning algorithms across four categories (machine learning, bagging classifiers, boosting classifiers, and neural network). We stepped into the adversary's shoes and proposed two false-negative evasion attacks, namely GradAA and GreedAA, to expose vulnerabilities in the above detection models. The evasion attack agents transform malware applications into adversarial malware applications by adding minimum noise (maximum five perturbations) while maintaining the modified applications' structural, syntactic, and behavioral integrity. These adversarial malware applications force misclassifications and are predicted as benign by the detection models. The evasion attacks achieved an average fooling rate of 83.34% (GradAA) and 99.21% (GreedAA) which reduced the average accuracy from 90.35% to 55.22% (GradAA) and 48.29% (GreedAA) in twenty-four detection models. We also proposed two defense strategies, namely Adversarial Retraining and Correlation Distillation Retraining as countermeasures to protect detection models from adversarial attacks. The defense strategies slightly improved the detection accuracy but drastically enhanced the adversarial robustness of detection models. Finally, investigating the robustness of malware detection models against adversarial attacks is an essential step before their real-world deployment and can help in developing adversarially superior detection models.
引用
收藏
页码:567 / 587
页数:21
相关论文
共 33 条
  • [1] Towards Adversarially Superior Malware Detection Models: An Adversary Aware Proactive Approach using Adversarial Attacks and Defenses
    Hemant Rathore
    Adithya Samavedhi
    Sanjay K. Sahay
    Mohit Sewak
    Information Systems Frontiers, 2023, 25 : 567 - 587
  • [2] Robust Malware Detection Models: Learning from Adversarial Attacks and Defenses
    Rathore, Hemant
    Samavedhi, Adithya
    Sahay, Sanjay K.
    Sewak, Mohit
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2021, 37
  • [3] Adversarial Deep Ensemble: Evasion Attacks and Defenses for Malware Detection
    Li, Deqiang
    Li, Qianmu
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 3886 - 3900
  • [4] Automated poisoning attacks and defenses in malware detection systems: An adversarial machine learning approach
    Chen, Sen
    Xue, Minhui
    Fan, Lingling
    Hao, Shuang
    Xu, Lihua
    Zhu, Haojin
    Li, Bo
    COMPUTERS & SECURITY, 2018, 73 : 326 - 344
  • [5] Towards Robust Android Malware Detection Models using Adversarial Learning
    Rathore, Hemant
    2021 IEEE INTERNATIONAL CONFERENCE ON PERVASIVE COMPUTING AND COMMUNICATIONS WORKSHOPS AND OTHER AFFILIATED EVENTS (PERCOM WORKSHOPS), 2021, : 424 - 425
  • [6] PAD: Towards Principled Adversarial Malware Detection Against Evasion Attacks
    Li, Deqiang
    Cui, Shicheng
    Li, Yun
    Xu, Jia
    Xiao, Fu
    Xu, Shouhuai
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (02) : 920 - 936
  • [7] Defending malware detection models against evasion based adversarial attacks
    Rathore, Hemant
    Sasan, Animesh
    Sahay, Sanjay K.
    Sewak, Mohit
    PATTERN RECOGNITION LETTERS, 2022, 164 : 119 - 125
  • [8] Adversarial superiority in android malware detection: Lessons from reinforcement learning based evasion attacks and defenses
    Rathore, Hemant
    Nandanwar, Adarsh
    Sahay, Sanjay K.
    Sewak, Mohit
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2023, 44
  • [9] Adversarial superiority in android malware detection: Lessons from reinforcement learning based evasion attacks and defenses
    Rathore, Hemant
    Nandanwar, Adarsh
    Sahay, Sanjay K.
    Sewak, Mohit
    FORENSIC SCIENCE INTERNATIONAL-DIGITAL INVESTIGATION, 2023, 44
  • [10] Adversarial Attacks and Defenses for Wireless Signal Classifiers using CDI-aware GANs
    Sinha, Sujata
    Soysal, Alkan
    ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2024, : 2095 - 2100