Reducing the Surface for Adversarial Attacks in Malware Detectors
Autoři
Rok
2025
Publikováno
Machine Learning, Deep Learning and AI for Cybersecurity. Basel: Springer Nature Switzerland AG, 2025. p. 231-266. ISBN 978-3-031-83156-0.
Typ
Kapitola v knize
Pracoviště
Anotace
Adversarial attacks pose a significant problem in malware detection
because they allow relatively simple modifications to already detected malware to
recreate undetectable malware and cause misclassification in machine learning models, even in black-box scenarios. The goal of this work is to study defensive techniques
and implement a tool that can mitigate the impact of these attacks by preprocessing
samples to minimize the attack surface needed to create adversarial samples. Our
technique has been subjected to rigorous testing against a number of adversarial gen-
erators. The results of this testing have demonstrated the efficacy of our approach,
with a notable reduction in the evasion rate of detection for most generators to zero
percent. This has been achieved without any adverse impact on the detection accuracy
of common malware.