Automated poisoning attacks and defenses in malware detection systems: An adversarial machine learning approach. Issue 73 (March 2018)
- Record Type:
- Journal Article
- Title:
- Automated poisoning attacks and defenses in malware detection systems: An adversarial machine learning approach. Issue 73 (March 2018)
- Main Title:
- Automated poisoning attacks and defenses in malware detection systems: An adversarial machine learning approach
- Authors:
- Chen, Sen
Xue, Minhui
Fan, Lingling
Hao, Shuang
Xu, Lihua
Zhu, Haojin
Li, Bo - Abstract:
- Abstract: The evolution of mobile malware poses a serious threat to smartphone security. Today, sophisticated attackers can adapt by maximally sabotaging machine-learning classifiers via polluting training data, rendering most recent machine learning-based malware detection tools (such as Drebin, Droid APIMiner, and Ma Ma Droid ) ineffective. In this paper, we explore the feasibility of constructing crafted malware samples; examine how machine-learning classifiers can be misled under three different threat models; then conclude that injecting carefully crafted data into training data can significantly reduce detection accuracy. To tackle the problem, we propose Kuafu Det, a two-phase learning enhancing approach that learns mobile malware by adversarial detection. Kuafu Det includes an offline training phase that selects and extracts features from the training set, and an online detection phase that utilizes the classifier trained by the first phase. To further address the adversarial environment, these two phases are intertwined through a self-adaptive learning scheme, wherein an automated camouflage detector is introduced to filter the suspicious false negatives and feed them back into the training phase. We finally show that Kuafu Det can significantly reduce false negatives and boost the detection accuracy by at least 15%. Experiments on more than 250, 000 mobile applications demonstrate that Kuafu Det is scalable and can be highly effective as a standalone system.
- Is Part Of:
- Computers & security. Issue 73(2018)
- Journal:
- Computers & security
- Issue:
- Issue 73(2018)
- Issue Display:
- Volume 73, Issue 73 (2018)
- Year:
- 2018
- Volume:
- 73
- Issue:
- 73
- Issue Sort Value:
- 2018-0073-0073-0000
- Page Start:
- 326
- Page End:
- 344
- Publication Date:
- 2018-03
- Subjects:
- Malware detection -- Adversarial machine learning -- Poisoning attacks -- Manipulation -- KuafuDet
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2017.11.007 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 5763.xml