Pith. sign in

REVIEW 1 cited by

Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1702.05983 v1 pith:U2Z7D42M submitted 2017-02-20 cs.LG cs.CR

Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN

classification cs.LG cs.CR
keywords malwareadversarialblack-boxdetectionexamplesmalganlearningmachine
verification ladder T0 review T1 audit T2 compute T3 formal T4 reserved
0 comments
read the original abstract

Machine learning has been used to detect new malware in recent years, while malware authors have strong motivation to attack such algorithms. Malware authors usually have no access to the detailed structures and parameters of the machine learning models used by malware detection systems, and therefore they can only perform black-box attacks. This paper proposes a generative adversarial network (GAN) based algorithm named MalGAN to generate adversarial malware examples, which are able to bypass black-box machine learning based detection models. MalGAN uses a substitute detector to fit the black-box malware detection system. A generative network is trained to minimize the generated adversarial examples' malicious probabilities predicted by the substitute detector. The superiority of MalGAN over traditional gradient based adversarial example generation algorithms is that MalGAN is able to decrease the detection rate to nearly zero and make the retraining based defensive method against adversarial examples hard to work.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. Binary Iterative Method for Non-targeted Adversarial Attack

    cs.LG 2026-07 reject novelty 2.0

    Halving the BIM step size each iteration (BinIM) yields stronger non-targeted ImageNet attacks than FGSM/BIM/VAM on three classifiers, with unsupported claims that this finds local minima.