Return
Adversarial ELF Malware Detection Method Using Model Interpretation
DOI:10.1109/TII.2022.3192901.png)
Abstract
En 中文
Recent research shows that executable and linkable format (ELF) malware detection models based on deep learning are vulnerable to adversarial attacks. The most commonly used method in previous work is adversarial training to defend adversarial examples. Nevertheless, it is inefficient and only effective for specific adversarial attacks. Given that the perturbation byte insertion positions of existing adversarial malware generation methods are relatively fixed, we propose a new method to detect adversarial ELF malware. Using model interpretation techniques, we analyze the decision-making basis of the malware detection model and extract the features of adversarial examples. We further use anomaly detection techniques to identify adversarial examples. As an add-on module of the malware detection model, the proposed method does not require modifying the original model and does not need to retrain the model. Evaluating results show that the method can effectively defend the adversarial attacks against the malware detection model.
Keywords:
Malware
Analytical models
Deep learning
Ground penetrating radar
Geophysical measurement techniques
Training
Feature extraction
Artificial neural networks
computer security
invasive software
smart devices
Journal
IF:
9.9
Papers:
8.6K
Citations:
6.0W
Organization
Cited Papers
Understanding adversarial training: Increasing local stability of supervised models through robust optimization
NEUROCOMPUTING
IF6.5

