Adversarial Attacks and Defenses in Malware Detection Classifiers
Teenu S. John, Tony Thomas · Advances in computer and electrical engineering book series · 2019
Machine learning has found its immense application in various cybersecurity domains owing to its automated threat prediction and detection capabilities. Despite its advantages, attackers can utilize the vulnerabilities of machine learning models for degrading its performance. These attacks called adversarial attacks can perturb the features of the data to induce misclassification. Adversarial attacks are highly destructive in the case of malware detection classifiers, causing a harmful virus or trojan to evade the threat detection system. The feature perturbations carried out by an adversary against malware detection classifiers are different from the conventional attack strategies employed by an adversary against computer vision tasks. This chapter discusses various adversarial attacks launched against malware detection classifiers and the existing defensive mechanisms. The authors also discuss the challenges and the research directions that need to be addressed to develop effective defensive mechanisms against these attacks.