Pith. sign in

REVIEW 1 cited by

Black-Box Attacks against RNN based Malware Detection Algorithms

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1705.08131 v1 pith:7YSYLYUL submitted 2017-05-23 cs.LG cs.CR

classification cs.LGcs.CR
keywords detectionmalwarealgorithmsadversarialexamplessequentialattacksdetect
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Recent researches have shown that machine learning based malware detection algorithms are very vulnerable under the attacks of adversarial examples. These works mainly focused on the detection algorithms which use features with fixed dimension, while some researchers have begun to use recurrent neural networks (RNN) to detect malware based on sequential API features. This paper proposes a novel algorithm to generate sequential adversarial examples, which are used to attack a RNN based malware detection system. It is usually hard for malicious attackers to know the exact structures and weights of the victim RNN. A substitute RNN is trained to approximate the victim RNN. Then we propose a generative RNN to output sequential adversarial examples from the original sequential malware inputs. Experimental results showed that RNN based malware detection algorithms fail to detect most of the generated malicious adversarial examples, which means the proposed model is able to effectively bypass the detection algorithms.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Tarallo: Evading Behavioral Malware Detectors in the Problem Space

    cs.CR 2025-06 conditional novelty 7.0 of 10

    Tarallo evades RNN-based behavioral malware detectors by injecting API calls selected with a new position-sensitive gradient attack, reaching up to 99% evasion in feature and problem space tests.

Pith tools