REVIEW 4 cited by
Adversarial Perturbations Against Deep Neural Networks for Malware Classification
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
Deep neural networks, like many other machine learning models, have recently been shown to lack robustness against adversarially crafted inputs. These inputs are derived from regular inputs by minor yet carefully selected perturbations that deceive machine learning models into desired misclassifications. Existing work in this emerging field was largely specific to the domain of image classification, since the high-entropy of images can be conveniently manipulated without changing the images' overall visual appearance. Yet, it remains unclear how such attacks translate to more security-sensitive applications such as malware detection - which may pose significant challenges in sample generation and arguably grave consequences for failure. In this paper, we show how to construct highly-effective adversarial sample crafting attacks for neural networks used as malware classifiers. The application domain of malware classification introduces additional constraints in the adversarial sample crafting problem when compared to the computer vision domain: (i) continuous, differentiable input domains are replaced by discrete, often binary inputs; and (ii) the loose condition of leaving visual appearance unchanged is replaced by requiring equivalent functional behavior. We demonstrate the feasibility of these attacks on many different instances of malware classifiers that we trained using the DREBIN Android malware data set. We furthermore evaluate to which extent potential defensive mechanisms against adversarial crafting can be leveraged to the setting of malware classification. While feature reduction did not prove to have a positive impact, distillation and re-training on adversarially crafted samples show promising results.
Forward citations
Cited by 4 Pith papers
-
Adversarial Filtering Based Evasion and Backdoor Attacks to EEG-Based Brain-Computer Interfaces
A universal adversarial filter applied to EEG can degrade BCI classifiers to chance accuracy, and the same filter can be used as a backdoor trigger.
-
advPattern: Physical-World Attacks on Deep Person Re-Identification via Adversarially Transformable Patterns
An adversarial clothing pattern, optimized to separate an individual's features across camera views, can reduce rank-1 matching from 87.9% to 27.1% and enable impersonation at 47.1% rank-1 in physical-world tests.
-
ADAPT: A Pseudo-labeling Approach to Combat Concept Drift in Malware Detection
A pseudo-labeling method with class-specific adaptive thresholds, label-consistent augmentation, and mixup reduces concept-drift performance loss in malware classifiers across five datasets.
-
Comprehensive Survey on Adversarial Examples in Cybersecurity: Impacts, Challenges, and Mitigation Strategies
A review summarizing adversarial example attacks and defenses in cybersecurity, with duplicated references and no new experimental results.
Discussion (0). Continue with ORCID to comment.