Research on KNN Algorithm in Malicious PDF Files Classification under Adversarial Environment
Kunming Li, Yijun Gu, Peijing Zhang, Wang An, Wenzheng Li · 2019
Traditional machine learning classifiers are usually based on the same distribution of training and testing sets, and only pay attention to the accuracy of the classifier, when attackers change the data distribution, the usability of the model is reduced. A method on how to improve the robustness of the KNN classifier is proposed. Firstly, the gradient descent attack method is used to attack the KNN algorithm. Secondly, add the adversarial samples generated by the gradient descent attack to the training set to train a new KNN classifier. Finally, compare the robustness of the improved classifier and the initial classifier by simulating different attack strengths. The experimental results show that adding the adversarial samples to the KNN classifier can effectively improve the performance of the classifier against the evasion attacks.