Generic Black-Box End-to-End Attack Against State of the Art API Call Based Malware Classifiers
arXiv:1707.05970
Abstract
In this paper, we present a black-box attack against API call based machine learning malware classifiers, focusing on generating adversarial sequences combining API calls and static features (e.g., printable strings) that will be misclassified by the classifier without affecting the malware functionality. We show that this attack is effective against many classifiers due to the transferability principle between RNN variants, feed forward DNNs, and traditional machine learning classifiers such as SVM. We also implement GADGET, a software framework to convert any malware binary to a binary undetected by malware classifiers, using the proposed attack, without access to the malware source code.
Accepted as a conference paper at RAID 2018
References in corpus (9)
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- On the Properties of Neural Machine Translation: Encoder-Decoder Approaches
- Delving into Transferable Adversarial Examples and Black-box Attacks
- Stealing Machine Learning Models via Prediction APIs
- Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN
- On the (Statistical) Detection of Adversarial Examples
- Black-Box Attacks against RNN based Malware Detection Algorithms
- Ensemble Methods as a Defense to Adversarial Perturbations Against Deep Neural Networks
- DeepAPT: Nation-State APT Attribution Using End-to-End Deep Neural Networks
Cited by in corpus (9)
- Early Stage Malware Prediction Using Recurrent Neural Networks
- Adversarial Attacks on Deep Learning Models in Natural Language Processing: A Survey
- Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
- Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey
- FortuneTeller: Predicting Microarchitectural Attacks via Unsupervised Deep Learning
- MULDEF: Multi-model-based Defense Against Adversarial Examples for Neural Networks
- Android HIV: A Study of Repackaging Malware for Evading Machine-Learning Detection
- Adversarial Examples on Object Recognition: A Comprehensive Survey
- Information Laundering for Model Privacy