Skip to main navigation Skip to search Skip to main content

An Adversarial Reinforcement Learning Framework for Robust Machine Learning-based Malware Detection

  • Mohammadreza (Reza) Ebrahimi*
  • , Weifeng Li
  • , Yidong Chai*
  • , Jason Pacheco
  • , Hsinchun Chen
  • *Corresponding author for this work

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Empowered by the recent development in Ma-chine Learning (ML), signatureless ML-based malware detectors present promising performance in identifying unseen mal ware variants and zero days without requiring expensive dynamic malware analysis. However, it has been recently shown that ML-based malware detectors are vulnerable to adversarial malware attacks, in which an attacker modifies a known malware exe-cutable to trick the malware detector into recognizing the modi-fied variant as benign. Adversarial malware example generation has become an emerging area in adversarial ML that studies creating functionality-preserving adversarial malware variants. Advancements in this area have led to an eternal game between the adversary and defender. While the area has attracted much attention in the security community, a large body of these studies merely focuses on attack methods against ML-based malware detectors. There has been little work on understanding how these adversarial variants can be systematically used by the defender to strengthen the robustness of these detectors and stand ahead of the adversary. Latest efforts have led to emergence of adversarial learning. In this work, we propose a simple wargame approach to empirically conduct the adversarial minimax optimization underlying in the adversarial learning for improving the robustness of ML-based malware detectors. Our proposed approach employs adversarial malware variants generated from a reinforcement learning-based adversarial attack policy in a minimax game alternating between strengthening the attack policy and improving the detectors' robustness. We evaluated the effectiveness of our approach on a testbed with 33.2 GB working malware collected from VirusTotal. Despite the sub-optimal nature of our method, it was able to surprisingly enhance the robustness of three known open-source ML-based malware detectors (LGBM, MalConv, and NonNeg) against the adversarial malware variants by 4, 7, and 11 times, respectively. © 2022 IEEE.
Original languageEnglish
Title of host publicationProceedings - 22nd IEEE International Conference on Data Mining Workshops
EditorsK. Selçuk Candan, Thang N. Dinh, My T. Thai, Takashi Washio
PublisherIEEE
Pages567-576
ISBN (Electronic)9798350346091
ISBN (Print)979-8-3503-4610-7
DOIs
Publication statusPublished - Nov 2022
Externally publishedYes
Event22nd IEEE International Conference on Data Mining (ICDM 2022) - Hilton Orlando, Orlando, United States
Duration: 28 Nov 20221 Dec 2022
https://icdm22.cse.usf.edu/index.html

Publication series

NameIEEE International Conference on Data Mining Workshops, ICDMW
ISSN (Print)2375-9232
ISSN (Electronic)2375-9259

Conference

Conference22nd IEEE International Conference on Data Mining (ICDM 2022)
PlaceUnited States
CityOrlando
Period28/11/221/12/22
Internet address

Funding

We would like to thank VirusTotal for providing us with access to their recent malware samples. This material is based upon work supported by the National Science Foundation (NSF) under Secure and Trustworthy Cyberspace (Grant No. 1936370) and Cybersecurity Scholarship-for-Service (Grant No. 1921485).

Research Keywords

  • adversarial learning
  • adversarial malware variants
  • adversarial minimax game
  • adversarial robustness
  • machine learning-based malware detection

Fingerprint

Dive into the research topics of 'An Adversarial Reinforcement Learning Framework for Robust Machine Learning-based Malware Detection'. Together they form a unique fingerprint.

Cite this