Adversarial Deep Learning for Robust Detection of Binary Encoded Malware
arXiv:1801.02950
Abstract
Malware is constantly adapting in order to avoid detection. Model based malware detectors, such as SVM and neural networks, are vulnerable to so-called adversarial examples which are modest changes to detectable malware that allows the resulting malware to evade detection. Continuous-valued methods that are robust to adversarial examples of images have been developed using saddle-point optimization formulations. We are inspired by them to develop similar methods for the discrete, e.g. binary, domain which characterizes the features of malware. A specific extra challenge of malware is that the adversarial examples must be generated in a way that preserves their malicious functionality. We introduce methods capable of generating functionally preserved adversarial malware examples in the binary domain. Using the saddle-point formulation, we incorporate the adversarial examples into the training of models that are robust to them. We evaluate the effectiveness of the methods and others in the literature on a set of Portable Execution~(PE) files. Comparison prompts our introduction of an online measure computed during training to assess general expectation of robustness.
1ST Deep Learning and Security Workshop (co-located with the 39th IEEE Symposium on Security and Privacy)
Cited by in corpus (14)
- IDSGAN: Generative Adversarial Networks for Attack Generation against Intrusion Detection
- Adversarial Attacks on Deep Learning Models in Natural Language Processing: A Survey
- Malware Classification using Deep Learning based Feature Extraction and Wrapper based Feature Selection Technique
- COPYCAT: Practical Adversarial Attacks on Visualization-Based Malware Detection
- Min-Max Optimization without Gradients: Convergence and Applications to Adversarial ML
- On the Application of Danskin's Theorem to Derivative-Free Minimax Optimization
- Enhancing Robustness of Deep Neural Networks Against Adversarial Malware Samples: Principles, Framework, and AICS'2019 Challenge
- Towards Security Threats of Deep Learning Systems: A Survey
- ATMPA: Attacking Machine Learning-based Malware Visualization Detection Methods via Adversarial Examples
- Semantic-preserving Reinforcement Learning Attack Against Graph Neural Networks for Malware Detection
- Mind the Gap: On Bridging the Semantic Gap between Machine Learning and Information Security
- Generating Adversarial Examples with an Optimized Quality
- An MDL-Based Classifier for Transactional Datasets with Application in Malware Detection
- A Review of Computer Vision Methods in Network Security