Improving Adversarial Attacks Against Executable Raw Byte Classifiers

Justin Burr, Shengjie Xu · 2021

Machine learning models serve as a powerful new technique for detecting malware. However, they are extremely vulnerable to attacks using adversarial examples. Machine learning models that classify Windows Portable Executable (PE) files are challenging to attack using this method due to the difficulty of manipulating executable file formats without compromising their functionality. In this paper, our objective is to propose and develop advanced attacks against models such as MalConv, which forgo feature engineering in favor of ingesting the entire executable file as a raw byte sequence. We will attempt to discover attack methods that are much more sophisticated and difficult to detect than current methods that simply append large amounts of specially-crafted byte sequences to the end of the PE file.

Read the paper · More papers on PaperTik