arrow
Return

Android Malware Detection via (Somewhat) Robust Irreversible Feature Transformations

delete2020-01-01
delete23
PRE
AI
Q
Qian Han
V
V. S. Subrahmanian *
Y
Yanhai Xiong
DOI:10.1109/TIFS.2020.2975932delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
As the most widely used OS on earth, Android is heavily targeted by malicious hackers. Though much work has been done on detecting Android malware, hackers are becoming increasingly adept at evading ML classifiers. We develop FARM, a Feature transformation based AndRoid Malware detector. FARM takes well-known features for Android malware detection and introduces three new types of feature transformations that transform these features irreversibly into a new feature domain. We first test FARM on 6 Android classification problems separating goodware and other malware from 3 classes of malware: rooting malware, spyware, and banking trojans. We show that FARM beats standard baselines when no attacks occur. Though we cannot guess all possible attacks that an adversary might use, we propose three realistic attacks on FARM and show that FARM is very robust to these attacks in all classification problems. Additionally, FARM has automatically identified two malware samples which were not previously classified as rooting malware by any of the 61 anti-viruses on VirusTotal. These samples were reported to Google's Android Security Team who subsequently confirmed our findings.
Keywords:
Android
machine learning
feature transformation
malware detection
spyware
Banking Trojans
rooting malware
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

D
Dartmouth College
Scholars:
1.5W
Papers: 1.4W
Citations: 1.8W