3.8 Proceedings Paper

Securing Malware Cognitive Systems against Adversarial Attacks

Publisher

IEEE
DOI: 10.1109/ICCC.2019.00014

Keywords

cognitive; machine learning; malware; adversary

Funding

  1. National Science Foundation CAREER award [1350766, 1618706, 1717774]
  2. Direct For Computer & Info Scie & Enginr
  3. Division Of Computer and Network Systems [1350766] Funding Source: National Science Foundation
  4. Division Of Computer and Network Systems
  5. Direct For Computer & Info Scie & Enginr [1717774] Funding Source: National Science Foundation

Ask authors/readers for more resources

The cognitive systems along with the machine learning techniques have provided significant improvements for many applications. However, recent adversarial attacks, such as data poisoning, evasion attacks, and exploratory attacks, have shown to be able to either cause the machine learning methods to misbehave, or leak sensitive model parameters. In this work, we have devised a prototype of a malware cognitive system, called DEEPARMOUR, which performs robust malware classification against adversarial attacks. At the heart of our method is a voting system with three different machine learning malware classifiers: random forest, multi-layer perceptron, and structure2vec. In addition, DEEPARMOUR applies several adversarial countermeasures, such as feature reconstruction and adversarial retraining to strengthen the robustness. We tested DEEPARMOUR on a malware execution trace dataset, which has 12,536 malware in five categories. We are able to achieve 0.989 accuracy with 10-fold cross validation. Further, to demonstrate the ability of combating adversarial attacks, we have performed a white-box evasion attack on the dataset and showed how our system is resilient to such attacks. Particularly, DEEPARMOUR is able to achieve 0.675 accuracy for the generated adversarial attacks which are unknown to the model. After retraining with only 10% adversarial samples, DEEPARMOUR is able to achieve 0.839 accuracy.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

3.8
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available