Do Fear the REAPIR: Adversarial Malware from API Replacement

Luke Kurlandski, Rayan Mosli, Yin Pan, Sirapat Thianphan, Matthew Wright · 2025

As the security industry increasingly uses machine learning in its malware detection pipelines, the threat of carefully crafted adversarial inputs designed to bypass detection has become worrying. A promising approach to malware detection is examining API calls, as they show insights into the program behavior, and nearly all malicious activities require interfacing with the operating system in some way. Researchers have thus examined the threat of adversarial examples against API-call-based malware detectors, with attacks that rely entirely upon the insertion of additional API calls into the malware. While this is effective against malware classifiers, the inserted API calls are non-functional and thus can be removed before detection is attempted, making the attacks fail in the context of a comprehensive malware detection pipeline. In this work, we present REAPIR (Resource-efficient API call Replacements), a framework to generate adversarial malware by replacing existing API calls with other ones with similar functionality instead of inserting inert ones. Since substituted calls perform real functions, they cannot be detected and removed. Using REAPIR, we were able to evade a 97 % accurate classifier 82 % of the time. In addition to being computationally efficient, our attack is also query efficient, being able to evade detection 60 % of time with only ten queries to the target model. Our work highlights the need to develop classifiers robust against this type of adversarial attack.

Read the paper · More papers on PaperTik