IMaler: An Adversarial Attack Framework to Obfuscate Malware Structure Against DGCNN-Based Classifier via Reinforcement Learning
Ya‐Hui Chen, Yunjiang Feng, Zhi Wang, Jianjun Zhao, Chengchun Wang, Qixu Liu · 2023
Inspired by the success of graph neural network in graph data classification, graph neural networks have been widely used in malware classification and they have been proven to be the state-of-the-art malware classification models. However, most of existing adversarial samples generation techniques against machine learning-based malware classification models modify malware samples by inserting dead codes or modifying binaries directly, which is less effective against graph neural network-based malware classification models. In this paper, we propose an adversarial attack framework powered by reinforcement learning to spoof the deep graph convolutional neural network (DGCNN)-based malware classifiers called Intelligent Malware Evader (IMaler). We construct functionality-preserved manipulations based on traditional obfuscation techniques that can modify both node features and structural features of malware. The reinforcement learning agent can make optimal decisions on how to obfuscate malware with functionality-preserved manipulations. We use a large dataset with more than 10,000 samples to evaluate the performance of IMaler and use a random agent attack as a baseline attack. The experiment results show that IMaler can achieve a significantly higher evasion rate (88.26%) than the random agent attack with fewer query times.