arXiv:2604.22569cs.CRcs.LG2026-04

用双层优化模拟攻防对抗,提升病毒检测系统抗攻击能力

Adversarial Co-Evolution of Malware and Detection Models: A Bilevel Optimization Perspective

  • 将攻防过程建模为双层优化,动态应对自适应攻击者
  • 在三种病毒家族测试中,漏洞率降至0-1.89%,远超传统方法
  • 使攻击者查询成本提高近百倍,适合安全防御研究者参考

基于机器学习的恶意软件检测系统日益面临对抗样本威胁。传统防御方法如一次性对抗训练,难以抵御使用强化学习进行规避的自适应攻击者。本文提出一种基于双层优化的鲁棒防御框架,将防御者与攻击者之间的战略互动建模为对抗共进化过程。我们在MAB-malware框架下,针对Mokes、Strab和DCRat三种不同恶意软件家族进行评估。实验结果表明,标准分类器和基础对抗再训练方法仍高度脆弱,逃避率高达90%;而所提双层优化方法在所有测试中均实现近乎完全免疫,逃避率降至0-1.89%。此外,该迭代框架显著提升了攻击者的查询复杂度,使成功规避的平均成本增加两个数量级。这些发现表明,通过双层优化建模攻防迭代循环,是构建能够抵御持续演进对抗威胁的鲁棒恶意软件检测系统的关键。

原文摘要 · Abstract (English)

Machine learning-based malware detectors are increasingly vulnerable to adversarial examples. Traditional defenses, such as one-shot adversarial training, often fail against adaptive attackers who use reinforcement learning to bypass detection. This paper proposes a robust defense framework based on bilevel optimization, explicitly modeling the strategic interaction between a defender and an attacker as an adversarial co-evolutionary process. We evaluate our approach using the MAB-malware framework against three distinct malware families: Mokes, Strab, and DCRat. Our experimental results demonstrate that while standard classifiers and basic adversarial retraining often remain vulnerable, showing evasion rates as high as 90 %, the proposed bilevel optimization approach consistently achieves near-total immunity, reducing evasion rates to 0 - 1.89 %. Furthermore, the iterative framework significantly increases the attacker's query complexity, raising the average cost of successful evasion by up to two orders of magnitude. These findings suggest that modeling the iterative cycle of attack and defense through bilevel optimization is essential for developing resilient malware detection systems capable of withstanding evolving adversarial threats.

恶意软件检测对抗攻击双层优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。