Pith. sign in

REVIEW 2 cited by

Burning the Adversarial Bridges: Robust Windows Malware Detection Against Binary-level Mutations

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2310.03285 v1 pith:IC3GNZMX submitted 2023-10-05 cs.LG cs.CR

classification cs.LGcs.CR
keywords malwaredetectioninformationsoftwareadversarialschemeattackattacks
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Toward robust malware detection, we explore the attack surface of existing malware detection systems. We conduct root-cause analyses of the practical binary-level black-box adversarial malware examples. Additionally, we uncover the sensitivity of volatile features within the detection engines and exhibit their exploitability. Highlighting volatile information channels within the software, we introduce three software pre-processing steps to eliminate the attack surface, namely, padding removal, software stripping, and inter-section information resetting. Further, to counter the emerging section injection attacks, we propose a graph-based section-dependent information extraction scheme for software representation. The proposed scheme leverages aggregated information within various sections in the software to enable robust malware detection and mitigate adversarial settings. Our experimental results show that traditional malware detection models are ineffective against adversarial threats. However, the attack surface can be largely reduced by eliminating the volatile information. Therefore, we propose simple-yet-effective methods to mitigate the impacts of binary manipulation attacks. Overall, our graph-based malware detection scheme can accurately detect malware with an area under the curve score of 88.32\% and a score of 88.19% under a combination of binary manipulation attacks, exhibiting the efficiency of our proposed scheme.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Empirical Evaluation of Concept Drift in ML-Based Android Malware Detection

    cs.CR 2025-07 conditional novelty 5.0 of 10

    Concept drift consistently lowers Android malware detection accuracy across nine machine learning and deep learning algorithms and two large language models, on two datasets.

  2. Adversarial Vulnerability Under Temporal Concept Drift: A Longitudinal Study of Android Malware Detection

    cs.CR 2026-05 unverdicted novelty 4.0 of 10

    Longitudinal evaluation over yearly Android app slices shows temporal drift reduces adversarial robustness of malware detectors, with expanding-window retraining providing partial mitigation but not full recovery.

Pith tools