Generating Adversarial Malware Examples Against Multiple Machine Learning Detectors
Anyuan Sang, Zhipeng Wang, Li Yang, Lu Zhou, Junbo Jia, Huipeng Yang · IEEE Transactions on Industrial Informatics · 2025
Malware poses a significant threat to network and information system security, particularly in industrial Internet of Things (IIoT) environments, where embedded systems and edge devices often rely on general-purpose operating systems. Although machine learning (ML) techniques have advanced malware detection, they remain vulnerable to adversarial attacks. Current research primarily focuses on adversarial examples targeting single ML detectors, but the widespread use of ensemble learning necessitates generating adversarial examples that can simultaneously evade multiple detectors. To address this challenge, we propose GanGenetic, a novel framework that combines generative adversarial networks (GANs) with genetic algorithms (GAs) to generate adversarial malware examples targeting import address table features in portable executable files. GanGenetic generates examples with minimal perturbations while simultaneously evaluating the robustness of multiple ML detectors. The framework first generates initial examples using GANs, then optimizes them through a GA to maximize evasion and minimize noise. Experiments on the VirusShare and Ember datasets show that GanGenetic can evade detection by seven ML models (including AdaBoost, Gradient Boosting Decision Trees, logistic regression, multilayer perceptron, random forest, support vector machine, and MalConv) with an average attack success rate exceeding 96%. In addition, in real-world tests, the framework successfully evaded detection while preserving malware functionality.