arrow
返回

Unveiling vulnerabilities in deep learning-based malware detection: Differential privacy driven adversarial attacks

delete2024-11-01
delete3
PRE
AI
R
Rahim Taheri *
M
Mohammad Shojafar
F
Farzad Arabikhan
A
Alexander Gegov
DOI:10.1016/j.cose.2024.104035delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The exponential increase of Android malware creates a severe threat, motivating the development of machine learning and especially deep learning-based classifiers to detect and mitigate malicious applications. However, these classifiers are susceptible to adversarial attacks that manipulate input data to deceive the classifier and compromise performance. This paper investigates the vulnerability of deep learning-based Android malware classifiers against two adversarial attacks: Data Poisoning with Noise Injection (DP-NI) and Gradient-based Data Poisoning (GDP). In these attacks, we explore the utilization of differential privacy techniques by attackers aiming to compromise the effectiveness of deep learning based Android malware classifiers. We propose and evaluate a novel defense mechanism, Differential Privacy-Based Noise Clipping (DP-NC), designed to enhance the robustness of Android malware classifiers against these adversarial attacks. By leveraging deep neural networks and adversarial training techniques, DP-NC demonstrates remarkable efficacy in mitigating the impact of both DP-NI and GDP attacks. Through extensive experimentation on three diverse Android datasets (Drebin, Contagio, and Genome), we evaluate the performance of DP-NC against proposed adversarial attacks. Our results show that DP-NC significantly reduces the false-positive rate and improves classification accuracy across all datasets and attack scenarios. For instance, our findings on the Drebin dataset reveal a significant decrease in accuracy to 51% and 30% after applying DP-NI and GDP techniques, respectively. However, upon applying the DP-NC defense mechanism, the accuracy in both cases improved to approximately 70%. Furthermore, employing DP-NC defense against DP-NI and GDP attacks leads to a notable reduction in false positive rates by 45.46% and 7.67%, respectively. Similar results have been obtained in two other datasets, Contagio and Genome. These results underscore the effectiveness of DP-NC in enhancing the robustness of deep learning-based Android malware classifiers against adversarial attacks.
Keyword:
Adversarial attacks
Android malware detection
Deep learning
Differential privacy
Gradient perturbation

期刊

C
Computers and Security
IF:
5.4
论文数:
4.6K
被引数:
1.4W

机构

U
University of Portsmouth
学者数:
5.1K
论文数: 5.5K
被引数: 9.2K
U
University of Surrey
学者数:
1.2W
论文数: 1.3W
被引数: 22
引用论文

引用论文

err分享
err收藏
Federated synthetic data generation with differential privacy具有差分隐私的联合合成数据生成
err2022-01-01
err25
PREAI
errXin, Bangzhou; Geng, Yangyang; Hu, Teng; Chen, Sheng; Yang, Wei; Wang, Shaowei; Huang, Liusheng
err分享
err收藏
Preserving data privacy in machine learning systems
err2024-02-01
err20
errOAAI
errEl Mestari, Soumia Zohra; Lenzini, Gabriele; Demirci, Huseyin
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
学者 查看更多内容