Arms Race in Adversarial Malware Detection: A Survey
arXiv:2005.11671 · doi:10.1145/3484491
Abstract
Malicious software (malware) is a major cyber threat that has to be tackled with Machine Learning (ML) techniques because millions of new malware examples are injected into cyberspace on a daily basis. However, ML is vulnerable to attacks known as adversarial examples. In this paper, we survey and systematize the field of Adversarial Malware Detection (AMD) through the lens of a unified conceptual framework of assumptions, attacks, defenses, and security properties. This not only leads us to map attacks and defenses to partial order structures, but also allows us to clearly describe the attack-defense arms race in the AMD context. We draw a number of insights, including: knowing the defender's feature set is critical to the success of transfer attacks; the effectiveness of practical evasion attacks largely depends on the attacker's freedom in conducting manipulations in the problem space; knowing the attacker's manipulation set is critical to the defender's success; the effectiveness of adversarial training depends on the defender's capability in identifying the most powerful attack. We also discuss a number of future research directions.
35 pages, 5 figures
References in corpus (10)
- Evasion Attacks against Machine Learning at Test Time
- Poisoning Attacks against Support Vector Machines
- Security Evaluation of Pattern Classifiers under Attack
- Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN
- Adversarial Feature Selection against Evasion Attacks
- Learning to Evade Static PE Machine Learning Malware Models via Reinforcement Learning
- Adversarial Deep Ensemble: Evasion Attacks and Defenses for Malware Detection
- Adversarial EXEmples: A Survey and Experimental Evaluation of Practical Attacks on Machine Learning for Windows Malware Detection
- Robustness of classifiers: from adversarial to random noise
- A Framework for Enhancing Deep Neural Networks Against Adversarial Malware