Skip to main navigation Skip to search Skip to main content

On the robustness of malware detectors to adversarial samples

Muhammad Salman*, Benjamin Zi Hao Zhao, Hassan Jameel Asghar, Muhammad Ikram, Sidharth Kaushik, Mohamed Ali Kaafar

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference proceeding contributionpeer-review

Abstract

Adversarial examples add imperceptible alterations to inputs with the objective to induce misclassification in machine learning models. They have been demonstrated to pose significant challenges in domains like image classification, with results showing that an adversarially perturbed image to evade detection against one classifier is most likely transferable to other classifiers. Adversarial examples have also been studied in malware analysis. Unlike images, program binaries cannot be arbitrarily perturbed without rendering them non-functional. Due to the difficulty of crafting adversarial program binaries, there is no consensus on the transferability of adversarially perturbed programs to different detectors. In this work, we explore the robustness of malware detectors against adversarially perturbed malware. We investigate the transferability of adversarial attacks developed against one detector, against other machine learning-based malware detectors with different feature space, and code similarity techniques, specifically, locality sensitive hashingbased detectors. Our analysis reveals that adversarial program binaries crafted for one detector are generally less effective against others. We also evaluate an ensemble of detectors and show that they can potentially mitigate the impact of adversarial program binaries. Finally, we demonstrate that substantial program changes made to evade detection may result in the transformation technique being identified, implying that the adversary must make minimal changes to the program binary.
Original languageEnglish
Title of host publicationComputer Security. ESORICS 2024 International Workshops
Subtitle of host publicationSECAI, DisA, CPS4CIP, and SecAssure, Bydgoszcz, Poland, September 16-20, 2024, revised selected papers, part II
EditorsJoaquin Garcia-Alfaro, Harsha Kalutarage, Naoto Yanai, Rafał Kozik, Paweł Ksieniewicz, Michał Woźniak, Habtamu Abie, Silvio Ranise, Luca Verderame, Enrico Cambiaso, Rita Ugarelli, Isabel Praça, Basel Katt, Sandeep Pirbhulal, Ankur Shukla, Ankur Shukla, Michał Choraś
Place of PublicationCham
PublisherSpringer, Springer Nature
Pages149-170
Number of pages22
ISBN (Electronic)9783031823626
ISBN (Print)9783031823619
DOIs
Publication statusPublished - 2025
EventInternational Workshops which were held in conjunction with 29th European Symposium on Research in Computer Security, ESORICS 2024 - Bydgoszcz, Poland
Duration: 16 Sept 202420 Sept 2024
https://sites.google.com/view/secai2024

Publication series

NameLecture Notes in Computer Science
PublisherCham
Volume15264
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Workshop

WorkshopInternational Workshops which were held in conjunction with 29th European Symposium on Research in Computer Security, ESORICS 2024
Country/TerritoryPoland
CityBydgoszcz
Period16/09/2420/09/24
Internet address

Fingerprint

Dive into the research topics of 'On the robustness of malware detectors to adversarial samples'. Together they form a unique fingerprint.

Cite this