The Power of MEME: Adversarial Malware Creation with Model-Based Reinforcement Learning

08/31/2023
by   Maria Rigaki, et al.
0

Due to the proliferation of malware, defenders are increasingly turning to automation and machine learning as part of the malware detection tool-chain. However, machine learning models are susceptible to adversarial attacks, requiring the testing of model and product robustness. Meanwhile, attackers also seek to automate malware generation and evasion of antivirus systems, and defenders try to gain insight into their methods. This work proposes a new algorithm that combines Malware Evasion and Model Extraction (MEME) attacks. MEME uses model-based reinforcement learning to adversarially modify Windows executable binary samples while simultaneously training a surrogate model with a high agreement with the target model to evade. To evaluate this method, we compare it with two state-of-the-art attacks in adversarial malware creation, using three well-known published models and one antivirus product as targets. Results show that MEME outperforms the state-of-the-art methods in terms of evasion capabilities in almost all cases, producing evasive malware with an evasion rate in the range of 32-73 prediction label agreement with the respective target models between 97-99 The surrogate could be used to fine-tune and improve the evasion rate in the future.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/19/2023

A Comparison of Adversarial Learning Techniques for Malware Detection

Machine learning has proven to be a useful tool for automated malware de...
research
04/13/2022

Stealing Malware Classifiers and AVs at Low False Positive Conditions

Model stealing attacks have been successfully used in many machine learn...
research
05/22/2023

FGAM:Fast Adversarial Malware Generation Method Based on Gradient Sign

Malware detection models based on deep learning have been widely used, b...
research
06/23/2023

Creating Valid Adversarial Examples of Malware

Machine learning is becoming increasingly popular as a go-to approach fo...
research
11/28/2021

MALIGN: Adversarially Robust Malware Family Detection using Sequence Alignment

We propose MALIGN, a novel malware family detection approach inspired by...
research
10/16/2020

DOOM: A Novel Adversarial-DRL-Based Op-Code Level Metamorphic Malware Obfuscator for the Enhancement of IDS

We designed and developed DOOM (Adversarial-DRL based Opcode level Obfus...
research
01/20/2022

RoboMal: Malware Detection for Robot Network Systems

Robot systems are increasingly integrating into numerous avenues of mode...

Please sign up or login with your details

Forgot password? Click here to reset