arrow
返回

MalPatch: Evading DNN-Based Malware Detection With Adversarial Patches

delete2024-01-01
delete6
PRE
AI
D
Dazhi Zhan
Y
Yexin Duan
Y
Yue Hu
W
Weili Li
S
Shize Guo
Z
Zhisong Pan *
DOI:10.1109/TIFS.2023.3333567delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Static analysis is a crucial protection layer that enables modern antivirus systems to address the rampant proliferation of malware. These systems are increasingly relying on deep neural networks (DNNs) to automatically extract reliable features and achieve outstanding detection accuracy. Since DNNs are known to be vulnerable to adversarial examples, several studies have proposed practical evasion attacks to generate adversarial perturbations that can evade malware detectors. These attacks, however, require specific designs for the given input sample, prohibiting them from large-scale deployment. Therefore, it is more practical to generate sample-agnostic perturbations that do not involve recalculations regardless of the input malware sample. To this end, we leverage an adversarial patch attack, which is a special type of adversarial attack that dose not know the sample being modified during the attack construction process. In particular, we propose a new adversarial attack against malware detection systems called MalPatch. It locates the nonfunctional part of malware for adversarial patch injection to protect its executability while generating adversarial examples based on different strategies. The generated patch can be injected into any malware sample, fooling the detector into classifying it as benign. Experimental results demonstrate that MalPatch is effective under different attack settings. In the white-box setting, MalPatch achieves 69%-78% success rates against DNN detectors based on raw byte features and 47%-96% success rates against four grayscale detectors based on image features. In the black-box setting, the success rates of MalPatch against the same models reach 54%-74% and 27%-42%, respectively. We conclude by discussing several of its potential countermeasures and the generality of our approach.
Keyword:
Malware
Perturbation methods
Detectors
Feature extraction
Static analysis
Payloads
Operating systems
Malware detection
deep neural network
adversarial example
evasion attack
adversarial patch

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.2K
被引数:
2.3W

机构

A
Army Engineering University of PLA
学者数:
5.0K
论文数: 3.7K
被引数: 5
N
national university of defense technology - china
学者数:
1.8W
论文数: 1.4W
被引数: 9
引用论文

引用论文

Adversarial Examples for CNN-Based Malware Detectors
err2019-01-01
err49
errOAAI
errChen, Bingcai; Ren, Zhongru; Yu, Chao; Hussain, Iftikhar; Liu, Jintao
err分享
err收藏
Malware Visualization for Fine-Grained Classification
err2018-01-01
err92
errOAAI
errFu, Jianwen; Xue, Jingfeng; Wang, Yong; Liu, Zhenyan; Shan, Chun
err分享
err收藏
The rise & fall of New Left urbanism
err2009-04-01
err0
errOAAI
errChristopher Klemek
err分享
err收藏
Thermal reactions of benzosilacyclobutenes with alcohols
err1985-01-01
err0
PREAI
errKang Kyung-Tae; Seo Hee-Chan; Kim Kwang-Nam
err分享
err收藏
Mixed-metal cluster carbides and a mixed-metal ketenylidene with nucleophilic carbide sites
err2002-05-01
err0
PREAI
errJoseph W. Kolis; Elizabeth M. Holt; Joseph A. Hriljac; Duward F. Shriver
err分享
err收藏
Germline MLH1, MSH2 and MSH6 variants in Brazilian patients with colorectal cancer and clinical features suggestive of Lynch Syndrome
err2018-03-25
err0
errOAAI
errNayê Balzan Schneider; Tatiane Pastor; André Escremim de Paula; Maria Isabel Achatz; Ândrea Ribeiro dos Santos; Fernanda Sales Luiz Vianna; Clévia Rosset; Manuela Pinheiro; Patricia Ashton‐Prolla; Miguel Ângelo Martins Moreira; Edenir Inêz Palmero
err分享
err收藏
Different responses in metallothionein gene expression and antioxidative enzyme activity lead to more ROS accumulation in rice exposed to Tl(III) than to Tl(I)
err2020-11-01
err0
PREAI
errYan Yao; Moyun Wang; Ping Zhang; Xiaolan Wang; Xuexia Huang; Wei Liu; Zhenchun Wang; Ruiqi Yang
err分享
err收藏
学者 查看更多内容