Adversarial Retraining and White-Box Attacks for Robust Malware Detection

Hajar Ouazza, Fadoua Khennou, Abderrahim Abdellaoui · 2025

This paper investigates the vulnerability of deep learning models to adversarial attacks in malware detection and evaluates adversarial retraining as a defense mechanism. We assess DNN, Wide&DNN, CNN, and CNN&GRU&Att models under clean conditions, adversarial attacks (FGSM, PGD, BIM), and retraining. Results show a sharp performance drop under attacks, with Wide&DNN and CNN&GRU&Att exhibiting greater resilience. Adversarial retraining significantly enhances robustness, often restoring or improving pre-attack performance. Analysis of accuracy, precision, recall, Fl-score, and AUC underscores the need for strong defense strategies and complex architectures.

Read the paper · More papers on PaperTik