Pith. sign in

REVIEW 2 cited by

Adversarial Attacks against Windows PE Malware Detection: A Survey of the State-of-the-Art

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2112.12310 v5 pith:SNUNIBEV submitted 2021-12-23 cs.CR cs.AI

classification cs.CRcs.AI
keywords malwareadversarialwindowsattacksdetectionbeendefensesfile
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Malware has been one of the most damaging threats to computers that span across multiple operating systems and various file formats. To defend against ever-increasing and ever-evolving malware, tremendous efforts have been made to propose a variety of malware detection that attempt to effectively and efficiently detect malware so as to mitigate possible damages as early as possible. Recent studies have shown that, on the one hand, existing ML and DL techniques enable superior solutions in detecting newly emerging and previously unseen malware. However, on the other hand, ML and DL models are inherently vulnerable to adversarial attacks in the form of adversarial examples. In this paper, we focus on malware with the file format of portable executable (PE) in the family of Windows operating systems, namely Windows PE malware, as a representative case to study the adversarial attack methods in such adversarial settings. To be specific, we start by first outlining the general learning framework of Windows PE malware detection based on ML/DL and subsequently highlighting three unique challenges of performing adversarial attacks in the context of Windows PE malware. Then, we conduct a comprehensive and systematic review to categorize the state-of-the-art adversarial attacks against PE malware detection, as well as corresponding defenses to increase the robustness of Windows PE malware detection. Finally, we conclude the paper by first presenting other related attacks against Windows PE malware detection beyond the adversarial attacks and then shedding light on future research directions and opportunities. In addition, a curated resource list of adversarial attacks and defenses for Windows PE malware detection is also available at https://github.com/ryderling/adversarial-attacks-and-defenses-for-windows-pe-malware-detection.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Certifiably robust malware detectors by design

    cs.CR 2025-08 reject novelty 4.0 of 10

    A new architecture joins a linear layer forced positive on attack perturbation vectors with a monotonic classifier, but the paper's theoretical characterization of robust detectors is mathematically trivial and does n...

  2. Mal-D2GAN: Double-Detector based GAN for Malware Generation

    cs.CR 2025-05 reject novelty 4.0 of 10

    Mal-D2GAN, a GAN with two detectors and a least-squares loss, produced adversarial malware that lowered the true positive rate of eight classifiers to near zero on a 20,000-sample dataset.

Pith tools