Functionality-preserving Black-box Optimization of Adversarial Windows Malware
arXiv:2003.13526 · doi:10.1109/TIFS.2021.3082330
Abstract
Windows malware detectors based on machine learning are vulnerable to adversarial examples, even if the attacker is only given black-box query access to the model. The main drawback of these attacks is that: (i) they are query-inefficient, as they rely on iteratively applying random transformations to the input malware; and (ii) they may also require executing the adversarial malware in a sandbox at each iteration of the optimization process, to ensure that its intrusive functionality is preserved. In this paper, we overcome these issues by presenting a novel family of black-box attacks that are both query-efficient and functionality-preserving, as they rely on the injection of benign content - which will never be executed - either at the end of the malicious file, or within some newly-created sections. Our attacks are formalized as a constrained minimization problem which also enables optimizing the trade-off between the probability of evading detection and the size of the injected payload. We empirically investigate this trade-off on two popular static Windows malware detectors, and show that our black-box attacks can bypass them with only few queries and small payloads, even when they only return the predicted labels. We also evaluate whether our attacks transfer to other commercial antivirus solutions, and surprisingly find that they can evade, on average, more than 12 commercial antivirus engines. We conclude by discussing the limitations of our approach, and its possible future extensions to target malware classifiers based on dynamic analysis.
References in corpus (1)
Cited by in corpus (25)
- Adversarial EXEmples: A Survey and Experimental Evaluation of Practical Attacks on Machine Learning for Windows Malware Detection
- Adversarial Attacks against Windows PE Malware Detection: A Survey of the State-of-the-Art
- Fusing Feature Engineering and Deep Learning: A Case Study for Malware Classification
- EvadeDroid: A Practical Evasion Attack on Machine Learning for Black-box Android Malware Detection
- PAD: Towards Principled Adversarial Malware Detection Against Evasion Attacks
- Creating Valid Adversarial Examples of Malware
- Query-Free Evasion Attacks Against Machine Learning-Based Malware Detectors with Generative Adversarial Networks
- Quo Vadis: Hybrid Machine Learning Meta-Model based on Contextual and Behavioral Malware Representations
- WebAssembly Diversification for Malware Evasion
- ModSec-AdvLearn: Countering Adversarial SQL Injections with Robust Machine Learning
- Stealing and Evading Malware Classifiers and Antivirus at Low False Positive Conditions
- A Comparison of Adversarial Learning Techniques for Malware Detection
- Raze to the Ground: Query-Efficient Adversarial HTML Attacks on Machine-Learning Phishing Webpage Detectors
- A Robust Defense against Adversarial Attacks on Deep Learning-based Malware Detectors via (De)Randomized Smoothing
- Assessing the Impact of Packing on Machine Learning-Based Malware Detection and Classification Systems
- MALIGN: Explainable Static Raw-byte Based Malware Family Classification using Sequence Alignment
- Machine Learning for Windows Malware Detection and Classification: Methods, Challenges and Ongoing Research
- The Power of MEME: Adversarial Malware Creation with Model-Based Reinforcement Learning
- How to Train your Antivirus: RL-based Hardening through the Problem-Space
- SLIFER: Investigating Performance and Robustness of Malware Detection Pipelines
- Towards a Practical Defense against Adversarial Attacks on Deep Learning-based Malware Detectors via Randomized Smoothing
- Updating Windows Malware Detectors: Balancing Robustness and Regression against Adversarial EXEmples
- Certified Adversarial Robustness of Machine Learning-based Malware Detectors via (De)Randomized Smoothing
- Effectiveness of Adversarial Benign and Malware Examples in Evasion and Poisoning Attacks
- Demystifying the Role of Rule-based Detection in AI Systems for Windows Malware Detection