Evasion Attacks Based on Wasserstein Generative Adversarial Network

Jinlan Zhang, Qiao Yan, Mingde Wang · 2019

Security issues have been accompanied by the development of the artificial intelligence industry. Machine learning has been widely used for fraud detection, spam detection, and malicious file detection, since it has the ability to dig the value of big data. However, for malicious attackers, there is a strong motivation to evade such algorithms. Because attackers do not know the specific parameters of the machine model, they can only carry out a black box attack. This paper proposes a method based on Wasserstein Generative Adversarial Network(WGAN) to generate malicious PDF files which are similar to benign ones and can evade the malicious file detection system. The experimental results show that the adversarial examples generated by our method can evade the PDF classifier-PDFrate of 100%. We also test their performance in different classifiers and the results show that our proposed method can evade the classifiers of different machine learning algorithms such as Support Vector Machine(SVM), Linear Regression, Decision Tree, Random Forest.

Read the paper · More papers on PaperTik