通过注入伪装代码,让物联网恶意软件逃避基于功耗的检测。
Evasion of IoT Malware Detection via Dummy Code Injection
- 在Mirai蠕虫扫描阶段插入结构化伪代码,扰乱功耗特征。
- 平均攻击成功率75.2%,在多模型下实现有效规避。
- 适合研究安全防御与对抗性攻击的学者参考。
物联网(IoT)已将数十亿设备连接至全球网络,但其快速扩张也带来了严重安全漏洞,使设备成为如Mirai僵尸网络等恶意软件的目标。功率侧信道分析近年来成为基于设备功耗模式检测恶意活动的有前景技术。然而,此类检测系统在对抗性干扰下的鲁棒性仍缺乏研究。本文提出一种新型对抗策略,针对基于功率侧信道的恶意软件检测。通过在Mirai蠕虫的扫描阶段注入结构化伪代码,动态扰动功耗信号,在不破坏核心功能的前提下规避AI/ML驱动的异常检测。我们系统分析了隐蔽性、执行开销与逃逸效果之间的权衡,使用来自多家手机制造商的定制数据集评估多个先进侧信道分析模型。实验结果表明,该对抗修改实现了平均75.2%的攻击成功率,暴露出功率基入侵检测框架的实际漏洞。
原文摘要 · Abstract (English)
The Internet of Things (IoT) has revolutionized connectivity by linking billions of devices worldwide. However, this rapid expansion has also introduced severe security vulnerabilities, making IoT devices attractive targets for malware such as the Mirai botnet. Power side-channel analysis has recently emerged as a promising technique for detecting malware activity based on device power consumption patterns. However, the resilience of such detection systems under adversarial manipulation remains underexplored. This work presents a novel adversarial strategy against power side-channel-based malware detection. By injecting structured dummy code into the scanning phase of the Mirai botnet, we dynamically perturb power signatures to evade AI/ML-based anomaly detection without disrupting core functionality. Our approach systematically analyzes the trade-offs between stealthiness, execution overhead, and evasion effectiveness across multiple state-of-the-art models for side-channel analysis, using a custom dataset collected from smartphones of diverse manufacturers. Experimental results show that our adversarial modifications achieve an average attack success rate of 75.2\%, revealing practical vulnerabilities in power-based intrusion detection frameworks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。