arXiv:2501.13782cs.CRcs.AI2025-01被引 5

提出可防御真实恶意软件攻击的安卓恶意代码检测防护框架。

Defending against Adversarial Malware Attacks on ML-based Android Malware Detection Systems

  • 设计可插拔框架ADD,应对真实恶意软件生成的对抗攻击。
  • 在多种主流检测系统中验证,有效抵御前沿问题空间攻击。
  • 适用于提升真实杀毒软件的抗攻击能力,实用性强。

安卓恶意软件持续威胁用户隐私与数据安全。为应对该问题,研究者提出了基于机器学习的安卓恶意软件检测(ML-based AMD)系统。然而,对抗性安卓恶意软件攻击会破坏这些系统的检测完整性,引发严重担忧。现有防御方法仅能应对特征空间攻击(仅生成对抗特征向量),无法防护更真实的、从问题空间生成对抗性恶意软件的攻击,这一问题仍待解决。本文提出ADD框架,作为可插拔模块,增强基于机器学习的安卓恶意软件检测系统对问题空间攻击的鲁棒性。我们在多种主流的ML-based AMD系统上进行了广泛评估,结果表明ADD能有效抵御当前最先进的问题空间对抗性安卓恶意软件攻击。此外,该框架在真实杀毒软件中也展现出显著的防御效果。

原文摘要 · Abstract (English)

Android malware presents a persistent threat to users' privacy and data integrity. To combat this, researchers have proposed machine learning-based (ML-based) Android malware detection (AMD) systems. However, adversarial Android malware attacks compromise the detection integrity of the ML-based AMD systems, raising significant concerns. Existing defenses against adversarial Android malware provide protections against feature space attacks which generate adversarial feature vectors only, leaving protection against realistic threats from problem space attacks which generate real adversarial malware an open problem. In this paper, we address this gap by proposing ADD, a practical adversarial Android malware defense framework designed as a plug-in to enhance the adversarial robustness of the ML-based AMD systems against problem space attacks. Our extensive evaluation across various ML-based AMD systems demonstrates that ADD is effective against state-of-the-art problem space adversarial Android malware attacks. Additionally, ADD shows the defense effectiveness in enhancing the adversarial robustness of real-world antivirus solutions.

恶意软件检测对抗攻击安卓安全防御框架

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。