RAFM: On designing a robustness assessment framework to evaluate the hardness of malware detectors against adversarial attack

Avantika Gaur, Snigdh Chamoli, Priyanka Negi, Preeti Mishra · 2025

Artificial intelligence (AI)-driven intrusion detection systems (IDS) are crucial in modern technological environments such as virtual domains for identifying complex attack patterns. Although these machine learning (ML) based security models are highly effective, they remain vulnerable to adversarial attacks that target the ML model and exploit its sensitivity by carrying out small perturbations in the input sample. The proposed framework, RAFM, is designed to evaluate the robustness of deep learning-based and gradient-boosting decision tree-based IDS models. It generates adversarial samples through functionality-preserving byte-level manipulations, such as DOS header modifications and shifting techniques, designed to evade detection while maintaining malware functionality. The framework highlights vulnerabilities in these systems by testing against diverse malware families. It offers valuable insights for developing a more resilient AI-based intrusion detection solution for securing virtual machines (VMs) from adversarial attacks.

Read the paper · More papers on PaperTik