Evading Classifiers by Morphing in the Dark
arXiv:1705.07535 · doi:10.1145/3133956.3133978
Abstract
Learning-based systems have been shown to be vulnerable to evasion through adversarial data manipulation. These attacks have been studied under assumptions that the adversary has certain knowledge of either the target model internals, its training dataset or at least classification scores it assigns to input samples. In this paper, we investigate a much more constrained and realistic attack scenario wherein the target classifier is minimally exposed to the adversary, revealing on its final classification decision (e.g., reject or accept an input sample). Moreover, the adversary can only manipulate malicious samples using a blackbox morpher. That is, the adversary has to evade the target classifier by morphing malicious samples "in the dark". We present a scoring mechanism that can assign a real-value score which reflects evasion progress to each sample based on the limited information available. Leveraging on such scoring mechanism, we propose an evasion method -- EvadeHC -- and evaluate it against two PDF malware detectors, namely PDFRate and Hidost. The experimental evaluation demonstrates that the proposed evasion attacks are effective, attaining evasion rate on the evaluation dataset. Interestingly, EvadeHC outperforms the known classifier evasion technique that operates based on classification scores output by the classifiers. Although our evaluations are conducted on PDF malware classifier, the proposed approaches are domain-agnostic and is of wider application to other learning-based systems.
Cited by in corpus (10)
- One pixel attack for fooling deep neural networks
- Towards Adversarial Malware Detection: Lessons Learned from PDF-based Attacks
- Malware Makeover: Breaking ML-based Static Analysis by Modifying Executable Bytes
- Constrained Concealment Attacks against Reconstruction-based Anomaly Detectors in Industrial Control Systems
- A Framework for Enhancing Deep Neural Networks Against Adversarial Malware
- Arms Race in Adversarial Malware Detection: A Survey
- Mitigating Adversarial Gray-Box Attacks Against Phishing Detectors
- Wild Networks: Exposure of 5G Network Infrastructures to Adversarial Examples
- Analyzing PDFs like Binaries: Adversarially Robust PDF Malware Analysis via Intermediate Representation and Language Model
- How stealthy is stealthy? Studying the Efficacy of Black-Box Adversarial Attacks in the Real World