提出新防御框架,在保持高检测率的同时将计算开销降至1.76倍。
Efficient Adversarial Malware Defense via Trust-Based Raw Override and Confidence-Adaptive Bit-Depth Reduction
- 基于置信度自适应选择防御措施,动态优化安全与效率平衡。
- 在EMBER v2数据集上实现91%准确率,攻击成功率降至31-37%。
- 适合需高吞吐、低延迟的生产级恶意软件检测系统使用。
在大数据环境下部署鲁棒的恶意软件检测系统,需兼顾安全性与计算效率。尽管近期对抗防御方法显著提升了鲁棒性,但通常带来4至22倍的计算开销,对日处理百万样本的生产系统构成挑战。本文提出结合信任-原始覆盖(TRO)与置信度自适应位深压缩(CABDR)的新框架,显式优化对抗鲁棒性与计算效率的权衡。该方法利用自适应置信度机制选择性应用防御措施,在80万样本的EMBER v2数据集上实现1.76倍计算开销(较当前最优平滑防御提升2.3倍)。实验表明,该框架在保持91%干净准确率的同时,将多种攻击类型的攻击成功率降至31%-37%,尤其对基于优化的攻击(如C&W)降低48.8%。系统吞吐量达每秒126万样本(基于预提取的EMBER特征,无运行时特征提取),在72种生产配置下验证,具有统计显著性(5次独立运行,95%置信区间,p<0.01)。结果表明,生产环境中实现实用对抗鲁棒性需显式优化效率-鲁棒性权衡,为组织提供无需高昂基础设施成本的可行路径。
原文摘要 · Abstract (English)
The deployment of robust malware detection systems in big data environments requires careful consideration of both security effectiveness and computational efficiency. While recent advances in adversarial defenses have demonstrated strong robustness improvements, they often introduce computational overhead ranging from 4x to 22x, which presents significant challenges for production systems processing millions of samples daily. In this work, we propose a novel framework that combines Trust-Raw Override (TRO) with Confidence-Adaptive Bit-Depth Reduction (CABDR) to explicitly optimize the trade-off between adversarial robustness and computational efficiency. Our approach leverages adaptive confidence-based mechanisms to selectively apply defensive measures, achieving 1.76x computational overhead - a 2.3x improvement over state-of-the-art smoothing defenses. Through comprehensive evaluation on the EMBER v2 dataset comprising 800K samples, we demonstrate that our framework maintains 91 percent clean accuracy while reducing attack success rates to 31-37 percent across multiple attack types, with particularly strong performance against optimization-based attacks such as C and W (48.8 percent reduction). The framework achieves throughput of up to 1.26 million samples per second (measured on pre-extracted EMBER features with no runtime feature extraction), validated across 72 production configurations with statistical significance (5 independent runs, 95 percent confidence intervals, p less than 0.01). Our results suggest that practical adversarial robustness in production environments requires explicit optimization of the efficiency-robustness trade-off, providing a viable path for organizations to deploy robust defenses without prohibitive infrastructure costs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。