PAD: Towards Principled Adversarial Malware Detection Against Evasion Attacks
Li, Deqiang, Cui, Shicheng, Li, Yun, Xu, Jia, Xiao, Fu, Xu, Shouhuai
–arXiv.org Artificial Intelligence
Machine Learning (ML) techniques can facilitate the automation of malicious software (malware for short) detection, but suffer from evasion attacks. Many studies counter such attacks in heuristic manners, lacking theoretical guarantees and defense effectiveness. In this paper, we propose a new adversarial training framework, termed Principled Adversarial Malware Detection (PAD), which offers convergence guarantees for robust optimization methods. PAD lays on a learnable convex measurement that quantifies distribution-wise discrete perturbations to protect malware detectors from adversaries, whereby for smooth detectors, adversarial training can be performed with theoretical treatments. To promote defense effectiveness, we propose a new mixture of attacks to instantiate PAD to enhance deep neural network-based measurements and malware detectors. Experimental results on two Android malware datasets demonstrate: (i) the proposed method significantly outperforms the state-of-the-art defenses; (ii) it can harden ML-based malware detection against 27 evasion attacks with detection accuracies greater than 83.45%, at the price of suffering an accuracy decrease smaller than 2.16% in the absence of attacks; (iii) it matches or outperforms many anti-malware scanners in VirusTotal against realistic adversarial malware.
arXiv.org Artificial Intelligence
Apr-6-2023
- Country:
- Oceania > Australia
- New South Wales > Sydney (0.14)
- North America
- United States
- New York > New York County
- New York City (0.04)
- Nevada > Clark County
- Las Vegas (0.04)
- Colorado > El Paso County
- Colorado Springs (0.04)
- California > San Diego County
- San Diego (0.04)
- New York > New York County
- Puerto Rico > San Juan
- San Juan (0.04)
- Canada
- United States
- Europe
- Norway > Eastern Norway
- Oslo (0.04)
- Middle East > Republic of Türkiye
- Istanbul Province > Istanbul (0.04)
- Italy > Liguria
- Genoa (0.04)
- Norway > Eastern Norway
- Asia
- Macao (0.04)
- Japan (0.04)
- Middle East > Republic of Türkiye
- Istanbul Province > Istanbul (0.04)
- China > Jiangsu Province
- Nanjing (0.04)
- Africa > Ethiopia
- Addis Ababa > Addis Ababa (0.04)
- Oceania > Australia
- Genre:
- Research Report > New Finding (0.46)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: