Utilizing benign files to obfuscate malware via deep reinforcement learning
Jiyao Gao, Zhiyang Fang · 2022
Recently, many machine learning methods had been proposed to detect malware, and they were proved to have a better performance on polymorphic malware families. However, it has been shown that machine learning methods are vulnerable to mancraft adversarial examples. This paper proposes a deep reinforcement learning framework for generating adversarial malware examples automatically. The proposed method includes extracting bytes from benign executable files, appending them to the end of malware, or inserting them into the binary. The model is evaluated with a state-of-the-art malware classifier (EMBER), resulting in a high evasion rate of 85%.