arrow
Return

Interpretable Defense Against Structural Adversarial Attacks on Android Malware Detection

delete2025-01-01
delete0
PRE
AI
W
Wenying Wei
K
Kaifa Zhao
H
Hao Zhou
J
Jianfeng Li
W
Wu, Shuohan
M
Ming Fan
X
Xiapu Luo *
T
Ting Wang
K
Kai Zhou
刘烃 cover
刘烃 (Ting Liu)
Y
Yuzhe Tang
DOI:10.1109/TIFS.2025.3639962delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Android, being one of the most widely used mobile systems, is facing pressing threats from malware. Despite the effectiveness of Android malware detection (AMD) systems, they are still vulnerable to state-of-the-art adversarial attacks. Existing defense methods require the knowledge of target adversaries, such as attack algorithms or obfuscation strategies, which is impractical in real-world scenarios. Additionally, these approaches may adversely affect the performance of the detection model and fail to defend against problem-space attacks, which not only deceive the detection models but also generate executable adversarial software. To address this research gap, we propose a novel interpretable Android guard system, named IADGuard, to help AMD defend against attacks. IADGuard first designs a novel graph explainable method, AGExplainer, to identify suspicious functions and invocations in adversarial malware. With the guidance of AGExplainer, IADGuard develops a rectifier to reverse adversarial modifications on apps' function invocation relations, which facilitates the detection of adversarial malware by victim AMD. It is noteworthy that IADGuard requires zero knowledge of adversarial models and victim models, thereby preserves the performance of victim AMD. We validate IADGuard over three state-of-the-art problem space attacks that modify apps' function invocation relations to deceive victim AMD. Experimental results show that IADGuard achieves over 90.5% defense success rate, i.e., helps victim AMD identify adversarial malware. Furthermore, AGExplainer surpasses representative interpreters in identifying essential modifications, helps IADGuard reduce false positives to 1.5%, and improves the detection efficiency by up to 10.4 times.
Keywords:
Malware
Training
Robustness
Feature extraction
Predictive models
Perturbation methods
Computational modeling
Adaptation models
Software algorithms
Rectifiers
Interpretable defense
adversarial attack
Android malware detection

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

H
hong kong polytechnic university
Scholars:
3.0W
Papers: 4.1W
Citations: 921
X
xi'an jiaotong university
Scholars:
9.1W
Papers: 6.6W
Citations: 75
S
Syracuse University
Scholars:
5.4K
Papers: 5.2K
Citations: 8.3K
researcher View more organizations