Using Explainability Techniques to Assist Android Malware Detection Models in Resisting Adversarial Attacks
Yiming Chen, Yu-Cheng Yan, Qing-Min Yang · 2024
This study explores using Function Call Graphs (FCGs) to generate adversarial examples to improve the robustness of Android malware detection models. With Android holding a market share of up to 70% [1], its applications are frequent targets for attacks. To counter increasingly sophisticated threats, this research employs machine learning and deep learning, using FCGs to create adversarial samples that can evade detection with up to a 95% evasion rate. We focuses on simulated annealing, and explainable AI (XAI) techniques for generating these samples and uses adversarial training to balance accuracy and robustness in detection models. Adversarial training helps models identify such adversary samples, while XAI provides insights into the models’ decision-making processes, enhancing their ability to detect malicious apps. This approach achieves an F1-Score of 94% in standard training and 91% with adversarial training, outperforming simulated annealing (86%) in resisting unknown adversarial samples, with XAI showing an average detection rate of 92%.