arXiv:2605.23623cs.CRcs.AI2026-05

研究十年间安卓恶意软件检测模型在时间漂移下的抗攻击能力变化

Adversarial Vulnerability Under Temporal Concept Drift: A Longitudinal Study of Android Malware Detection

  • 按年份分组数据,模拟真实部署场景评估模型鲁棒性
  • 训练测试间隔越长,准确率下降,攻击成功率上升,尤其静态特征下FGSM攻击更有效
  • 持续更新可缓解但无法消除鲁棒性退化,需考虑时间漂移的评估框架

我们对超过十年的安卓应用进行了纵向、漂移感知的对抗鲁棒性评估,采用从模拟器和真实设备执行中提取的静态与动态特征表示。数据按年度划分,评估三种模拟真实学习场景的部署协议:(1) 同年训练与测试,(2) 跨年部署且不更新模型,(3) 基于累积历史数据的扩展窗口再训练。在多种分类器上,使用FGSM和SPSA生成对抗样本,受限于可行性。测量干净准确率、对抗准确率(AA)、攻击成功率达(ASR),并引入时序关联指标——RobustDrop、ΔASR和对抗放大因子(AAF),量化分布偏移与鲁棒性退化的关系。结果显示,在所考察的基于迁移的特征空间设置中,时间间隔越大,对抗鲁棒性越弱。随着训练-测试时间差增加,干净准确率与对抗准确率均下降,攻击成功率呈现配置依赖性上升,尤其在静态特征和FGSM扰动下更为明显。扩展窗口再训练可缓解但无法消除持续分布演化带来的鲁棒性损失。这些发现表明,在评估长期智能检测系统鲁棒性时必须考虑时间漂移,并强调在持续演化的对抗环境中需建立漂移感知的鲁棒性评估框架。

原文摘要 · Abstract (English)

We present a longitudinal, drift-aware evaluation of adversarial robustness across more than a decade of Android applications using static and dynamic feature representations extracted from emulator and real-device executions. The dataset is organized into yearly slices and evaluated under three deployment protocols that emulate realistic learning scenarios: (1) same-year training and testing, (2) cross-year deployment without model updates, and (3) expanding-window retraining with cumulative historical data. Across multiple classifier families, adversarial examples are generated using FGSM and SPSA under feasibility constraints. We measure clean performance, Adversarial Accuracy (AA), Attack Success Rate (ASR), and introduce temporal linkage metrics -- RobustDrop, $Δ$ASR, and Adversarial Amplification Factor (AAF) -- to quantify the relationship between distribution shift and robustness degradation.nResults show that temporal separation is associated with reduced adversarial robustness under the evaluated transfer-based feature-space setting. As the train-test gap increases, clean accuracy and adversarial accuracy decline, while attack success exhibits configuration-dependent increases, particularly under FGSM perturbations and static features. Expanding-window retraining mitigates, but does not eliminate, robustness loss under continued distributional evolution. These findings indicate that temporal drift should be considered when assessing the long-term robustness of intelligent detection systems under evolving data distributions and highlight the need for drift-aware robustness assessment frameworks in long-lived adversarial environments.

对抗样本时间漂移恶意软件检测鲁棒性评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。