We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Mate! Are You Really Aware? An Explainability-Guided Testing Framework for Robustness of Malware Detectors

Abstract: Numerous open-source and commercial malware detectors are available. However, their efficacy is threatened by new adversarial attacks, whereby malware attempts to evade detection, e.g., by performing feature-space manipulation. In this work, we propose an explainability-guided and model-agnostic testing framework for robustness of malware detectors when confronted with adversarial attacks. The framework introduces the concept of Accrued Malicious Magnitude (AMM) to identify which malware features could be manipulated to maximize the likelihood of evading detection. We then use this framework to test several state-of-the-art malware detectors' abilities to detect manipulated malware. We find that (i) commercial antivirus engines are vulnerable to AMM-guided test cases; (ii) the ability of a manipulated malware generated using one detector to evade detection by another detector (i.e., transferability) depends on the overlap of features with large AMM values between the different detectors; and (iii) AMM values effectively measure the fragility of features (i.e., capability of feature-space manipulation to flip the prediction results) and explain the robustness of malware detectors facing evasion attacks. Our findings shed light on the limitations of current malware detectors, as well as how they can be improved.
Comments: Accepted at ESEC/FSE 2023. this https URL
Subjects: Cryptography and Security (cs.CR); Machine Learning (cs.LG)
Cite as: arXiv:2111.10085 [cs.CR]
  (or arXiv:2111.10085v4 [cs.CR] for this version)

Submission history

From: Ruoxi Sun [view email]
[v1] Fri, 19 Nov 2021 08:02:38 GMT (1357kb,D)
[v2] Sun, 16 Jan 2022 08:01:18 GMT (2483kb,D)
[v3] Sun, 15 May 2022 09:53:40 GMT (3178kb,D)
[v4] Mon, 27 Nov 2023 23:25:00 GMT (1884kb,D)

Link back to: arXiv, form interface, contact.