arrow
Return

An Adversarial Attack on ML-Based IoT Malware Detection Using Binary Diversification Techniques

delete2024-01-01
delete0
delete
OA
AI
M
Maina Bernard Mwangi *
S
Shin‐Ming Cheng
DOI:10.1109/ACCESS.2024.3513713delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The integration of machine learning (ML) has revolutionized malware detection, enabling accurate identification of subtle distinctions between malware and benignware. As the threat landscape continually evolves and new malware strains emerge, conventional signature-based detectors are becoming increasingly inadequate, leading to a growing reliance on ML-based detectors. However, ML-based detection systems are particularly vulnerable to adversarial attacks, where subtle alterations to input samples can deceive detectors into misclassifying malware as benignware, highlighting the need for robustness studies, as such misclassifications can lead to significant damage. To this end, we stage a black-box attack on IoT malware detection systems, specifically targeting structure-based detectors, which are predominant due to their ability to detect malware across diverse CPU architectures in IoT environments. Our strategy employs semantic-preserving binary diversification techniques, including function inlining, branch function insertion, control flow graph flattening, and basic block merging and reordering, to modify malware binaries and evade detection. We train a multi-structural substitute detector (based on a combination of control flow graph and function call graph features) on a large-scale dataset of IoT ELF binaries, achieving detection rates of up to 98.24%. Using explainable AI (XAI), we transfer the attack to four structural target detectors, achieving evasion rates of up to 100% on certain detectors, with an average binary size increase of just 8.35%. The modified samples evade detection by a state-of-the-art adversarial detector and several commercial antivirus engines, highlighting the persistent challenge of defending against adversarial threats and emphasizing the need for enhanced and multi-faceted defense mechanisms.
Keywords:
Adversarial attack
binary diversification
Internet of Things (IoT) malware detection
machine learning
Adversarial attack
binary diversification
Internet of Things (IoT) malware detection
machine learning

Journal

IEEE Access cover
IEEE Access
IF:
3.6
Papers:
9.8W
Citations:
29.4W

Organization

N
national taiwan university of science & technology
Scholars:
8.8K
Papers: 8.7K
Citations: 9
Cited Papers

Cited Papers

errShare
errSave
errShare
errSave
IoT malware classification based on reinterpreted function-call graphs
err2023-02-01
err8
PREAI
errWu, Chia-Yi; Ban, Tao; Cheng, Shin-Ming; Takahashi, Takeshi; Inoue, Daisuke
errShare
errSave
Adversarial Examples for CNN-Based Malware Detectors
err2019-01-01
err49
errOAAI
errChen, Bingcai; Ren, Zhongru; Yu, Chao; Hussain, Iftikhar; Liu, Jintao
errShare
errSave
Evading Anti-Malware Engines With Deep Reinforcement Learning
err2019-01-01
err75
errOAAI
errFang, Zhiyang; Wang, Junfeng; Li, Boya; Wu, Siqi; Zhou, Yingjie; Huang, Haiying
errShare
errSave
Generating Effective Software Obfuscation Sequences With Reinforcement Learning
err2022-05-01
err3
PREAI
errWang, Huaijin; Wang, Shuai; Xu, Dongpeng; Zhang, Xiangyu; Liu, Xiao
errShare
errSave
researcher View more