StratDef: Strategic defense against adversarial attacks in ML-based malware detection

被引:2
作者
Rashid, Aqib [1 ]
Such, Jose [1 ]
机构
[1] Kings Coll London, Dept Informat, London WC2R 2LS, England
关键词
Adversarial machine learning; Adversarial examples; Malware detection; Machine learning security; Deep learning;
D O I
10.1016/j.cose.2023.103459
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the years, most research towards defenses against adversarial attacks on machine learning models has been in the image recognition domain. The ML-based malware detection domain has received less attention despite its importance. Moreover, most work exploring these defenses has focused on several methods but with no strategy when applying them. In this paper, we introduce StratDef, which is a strategic defense system based on a moving target defense approach. We overcome challenges related to the systematic construction, selection, and strategic use of models to maximize adversarial robustness. StratDef dynamically and strategically chooses the best models to increase the uncertainty for the attacker while minimizing critical aspects in the adversarial ML domain, like attack transferability. We provide the first comprehensive evaluation of defenses against adversarial attacks on machine learning for malware detection, where our threat model explores different levels of threat, attacker knowledge, capabilities, and attack intensities. We show that StratDef performs better than other defenses even when facing the peak adversarial threat. We also show that, of the existing defenses, only a few adversariallytrained models provide substantially better protection than just using vanilla models but are still outperformed by StratDef.
引用
收藏
页数:18
相关论文
共 50 条
  • [1] MalProtect: Stateful Defense Against Adversarial Query Attacks in ML-Based Malware Detection
    Rashid, Aqib
    Such, Jose
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 4361 - 4376
  • [2] Securing ML-based Android Malware Detectors: A Defensive Feature Selection Approach against Backdoor Attacks
    Marek, Bartlomiej
    Pieniazek, Kacper
    Ratajczak, Filip
    Adamczyk, Wojciech
    Bok, Bartosz
    Krzyszton, Mateusz
    2024 IEEE 24TH INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND INTERNET COMPUTING WORKSHOPS, CCGRIDW 2024, 2024, : 128 - 135
  • [3] A novel method for malware detection on ML-based visualization technique
    Liu, Xinbo
    Lin, Yaping
    Li, He
    Zhang, Jiliang
    COMPUTERS & SECURITY, 2020, 89
  • [4] Defending ML-Based Feedback Loop System Against Malicious Adversarial Inference Attacks
    Vahakainu, Petri
    Lehto, Martti
    Kariluoto, Antti
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2021), 2021, : 382 - 390
  • [5] Defend against adversarial attacks in malware detection through attack space management
    Liu, Liang
    Kuang, Xinyu
    Liu, Lin
    Zhang, Lei
    COMPUTERS & SECURITY, 2024, 141
  • [6] Effective ML-Based Android Malware Detection and Categorization
    Alhogail, Areej
    Alharbi, Rawan Abdulaziz
    ELECTRONICS, 2025, 14 (08):
  • [7] Adversarial attacks against Windows PE malware detection: A survey of the state-of-the-art
    Ling, Xiang
    Wu, Lingfei
    Zhang, Jiangyu
    Qu, Zhenqing
    Deng, Wei
    Chen, Xiang
    Qian, Yaguan
    Wu, Chunming
    Ji, Shouling
    Luo, Tianyue
    Wu, Jingzheng
    Wu, Yanjun
    COMPUTERS & SECURITY, 2023, 128
  • [8] Certifying Accuracy, Privacy, and Robustness of ML-Based Malware Detection
    Bena N.
    Anisetti M.
    Gianini G.
    Ardagna C.A.
    SN Computer Science, 5 (6)
  • [9] Adversarial Attacks Against Image-Based Malware Detection Using Autoencoders
    Carey, Alycia N.
    Mai, Huy
    Zhan, Justin
    Mehmood, Asif
    PATTERN RECOGNITION AND TRACKING XXXII, 2021, 11735
  • [10] Enhancing Robustness of Malware Detection Model Against White Box Adversarial Attacks
    Singhal, Riya
    Soni, Meet
    Bhatt, Shruti
    Khorasiya, Manav
    Jinwala, Devesh C.
    DISTRIBUTED COMPUTING AND INTELLIGENT TECHNOLOGY, ICDCIT 2023, 2023, 13776 : 181 - 196