Are Malware Detection Models Adversarial Robust Against Evasion Attack?

Hemant Rathore, Adithya Samavedhi, Sanjay K. Sahay, Mohit Sewak · IEEE INFOCOM 2022 - IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS) · 2022

The ever-increasing number of android malware still poses a critical security challenge to the smartphone ecosystem. Literature suggests that machine and deep learning models can detect android malware with high accuracy and low false positivity. However, the result of arms-race in the adversarial setting of these detection models will shape their integration in real-world applications. Therefore, we first constructed four different malware detection models by applying machine and deep learning algorithms. Then, we stepped into the malware developer’s shoes and created an adversarial setting framework to investigate the robustness of the above detection models. We developed an evasion attack (Gradient Modification Attack) to exploit the vulnerabilities and force massive misclassifications in the above detection models. The attack drastically reduces the average accuracy of the above four detection models from 95.13% to $59. 97$%. Later, we also developed a potential defense mechanism (Correlated Distillation Retraining) to mitigate such adversarial attacks. In the end, we conclude that investigation of malware detection models in adversarial settings is essential for improving their robustness and real-world deployment.

Read the paper · More papers on PaperTik