Adversarial EXEmples: A Survey and Experimental Evaluation of Practical Attacks on Machine Learning for Windows Malware Detection
arXiv:2008.07125 · doi:10.1145/3473039
Abstract
Recent work has shown that adversarial Windows malware samples - referred to as adversarial EXEmples in this paper - can bypass machine learning-based detection relying on static code analysis by perturbing relatively few input bytes. To preserve malicious functionality, previous attacks either add bytes to existing non-functional areas of the file, potentially limiting their effectiveness, or require running computationally-demanding validation steps to discard malware variants that do not correctly execute in sandbox environments. In this work, we overcome these limitations by developing a unifying framework that does not only encompass and generalize previous attacks against machine-learning models, but also includes three novel attacks based on practical, functionality-preserving manipulations to the Windows Portable Executable (PE) file format. These attacks, named Full DOS, Extend and Shift, inject the adversarial payload by respectively manipulating the DOS header, extending it, and shifting the content of the first section. Our experimental results show that these attacks outperform existing ones in both white-box and black-box scenarios, achieving a better trade-off in terms of evasion rate and size of the injected payload, while also enabling evasion of models that have been shown to be robust to previous attacks. To facilitate reproducibility of our findings, we open source our framework and all the corresponding attack implementations as part of the secml-malware Python library. We conclude this work by discussing the limitations of current machine learning-based malware detectors, along with potential mitigation strategies based on embedding domain knowledge coming from subject-matter experts directly into the learning process.
References in corpus (5)
- Explaining and Harnessing Adversarial Examples
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Evasion Attacks against Machine Learning at Test Time
- Security Evaluation of Pattern Classifiers under Attack
- DeepSign: Deep Learning for Automatic Malware Signature Generation and Classification
Cited by in corpus (18)
- Adversarial Attacks against Windows PE Malware Detection: A Survey of the State-of-the-Art
- Fusing Feature Engineering and Deep Learning: A Case Study for Malware Classification
- Nebula: Self-Attention for Dynamic Malware Analysis
- PAD: Towards Principled Adversarial Malware Detection Against Evasion Attacks
- Stealing and Evading Malware Classifiers and Antivirus at Low False Positive Conditions
- A Comparison of Adversarial Learning Techniques for Malware Detection
- A Robust Defense against Adversarial Attacks on Deep Learning-based Malware Detectors via (De)Randomized Smoothing
- Assessing the Impact of Packing on Machine Learning-Based Malware Detection and Classification Systems
- Machine Learning for Windows Malware Detection and Classification: Methods, Challenges and Ongoing Research
- The Power of MEME: Adversarial Malware Creation with Model-Based Reinforcement Learning
- How to Train your Antivirus: RL-based Hardening through the Problem-Space
- SLIFER: Investigating Performance and Robustness of Malware Detection Pipelines
- Towards a Practical Defense against Adversarial Attacks on Deep Learning-based Malware Detectors via Randomized Smoothing
- EGAN: Evolutional GAN for Ransomware Evasion
- Updating Windows Malware Detectors: Balancing Robustness and Regression against Adversarial EXEmples
- Certified Adversarial Robustness of Machine Learning-based Malware Detectors via (De)Randomized Smoothing
- Effectiveness of Adversarial Benign and Malware Examples in Evasion and Poisoning Attacks
- Demystifying the Role of Rule-based Detection in AI Systems for Windows Malware Detection