Adversarial Attacks against Windows PE Malware Detection: A Survey of the State-of-the-Art
Ling, Xiang, Wu, Lingfei, Zhang, Jiangyu, Qu, Zhenqing, Deng, Wei, Chen, Xiang, Wu, Chunming, Ji, Shouling, Luo, Tianyue, Wu, Jingzheng, Wu, Yanjun
–arXiv.org Artificial Intelligence
The malware has been being one of the most damaging threats to computers that span across multiple operating systems and various file formats. To defend against the ever-increasing and ever-evolving threats of malware, tremendous efforts have been made to propose a variety of malware detection methods that attempt to effectively and efficiently detect malware. Recent studies have shown that, on the one hand, existing ML and DL enable the superior detection of newly emerging and previously unseen malware. However, on the other hand, ML and DL models are inherently vulnerable to adversarial attacks in the form of adversarial examples, which are maliciously generated by slightly and carefully perturbing the legitimate inputs to confuse the targeted models. Basically, adversarial attacks are initially extensively studied in the domain of computer vision, and some quickly expanded to other domains, including NLP, speech recognition and even malware detection. In this paper, we focus on malware with the file format of portable executable (PE) in the family of Windows operating systems, namely Windows PE malware, as a representative case to study the adversarial attack methods in such adversarial settings. To be specific, we start by first outlining the general learning framework of Windows PE malware detection based on ML/DL and subsequently highlighting three unique challenges of performing adversarial attacks in the context of PE malware. We then conduct a comprehensive and systematic review to categorize the state-of-the-art adversarial attacks against PE malware detection, as well as corresponding defenses to increase the robustness of PE malware detection. We conclude the paper by first presenting other related attacks against Windows PE malware detection beyond the adversarial attacks and then shedding light on future research directions and opportunities.
arXiv.org Artificial Intelligence
Dec-22-2021
- Country:
- Asia
- China
- Beijing > Beijing (0.04)
- Hong Kong (0.04)
- Hubei Province > Wuhan (0.04)
- Shandong Province > Qingdao (0.04)
- India > Karnataka
- Bengaluru (0.04)
- Japan > Kyūshū & Okinawa
- Okinawa (0.04)
- Macao (0.04)
- Middle East
- Taiwan > Taiwan Province
- Taipei (0.04)
- China
- Europe
- Austria > Vienna (0.14)
- France > Île-de-France
- Greece > Attica
- Athens (0.04)
- Italy
- Calabria > Catanzaro Province
- Catanzaro (0.04)
- Veneto > Venice (0.04)
- Calabria > Catanzaro Province
- Spain
- United Kingdom
- England
- Cambridgeshire > Cambridge (0.04)
- Greater London > London (0.04)
- Scotland > City of Glasgow
- Glasgow (0.04)
- England
- North America
- Canada
- Alberta > Census Division No. 15
- Improvement District No. 9 > Banff (0.04)
- British Columbia > Metro Vancouver Regional District
- Vancouver (0.04)
- New Brunswick > York County
- Fredericton (0.04)
- Ontario > Toronto (0.04)
- Quebec > Montreal (0.04)
- Alberta > Census Division No. 15
- Puerto Rico > Fajardo
- Fajardo (0.04)
- United States
- Pennsylvania > Allegheny County
- Pittsburgh (0.04)
- New York > New York County
- New York City (0.04)
- California
- Alameda County > Oakland (0.04)
- Los Angeles County > Long Beach (0.04)
- San Diego County > San Diego (0.04)
- San Francisco County > San Francisco (0.14)
- Santa Clara County
- San Jose (0.04)
- Santa Clara (0.04)
- District of Columbia > Washington (0.14)
- Illinois > Cook County
- Chicago (0.04)
- Massachusetts > Middlesex County
- Cambridge (0.04)
- Oregon > Multnomah County
- Portland (0.14)
- Louisiana > Orleans Parish
- New Orleans (0.04)
- Arizona > Maricopa County
- Phoenix (0.04)
- Scottsdale (0.04)
- Tempe (0.04)
- Colorado > Denver County
- Denver (0.04)
- Texas > Dallas County
- Dallas (0.04)
- Nevada > Clark County
- Las Vegas (0.04)
- Florida
- Miami-Dade County > Miami (0.04)
- Orange County > Orlando (0.04)
- Palm Beach County > Boca Raton (0.04)
- Pennsylvania > Allegheny County
- Canada
- Oceania
- Australia
- New South Wales > Sydney (0.04)
- Victoria > Melbourne (0.04)
- New Zealand (0.04)
- Australia
- South America > Chile
- Asia
- Genre:
- Overview (1.00)
- Research Report (1.00)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology:
- Information Technology
- Artificial Intelligence
- Machine Learning
- Neural Networks > Deep Learning (1.00)
- Reinforcement Learning (0.93)
- Statistical Learning (1.00)
- Natural Language (1.00)
- Representation & Reasoning (1.00)
- Machine Learning
- Data Science > Data Mining (1.00)
- Security & Privacy (1.00)
- Artificial Intelligence
- Information Technology