OFEI: A Semi-black-box Android Adversarial Sample Attack Framework Against DLaaS

OFEI: A Semi-black-box Android Adversarial Sample Attack Framework Against DLaaS
复制标题

OFEI:针对 DLaaS 的半黑盒 Android 对抗样本攻击框架

DOI:
10.1109/tc.2023.3236872
复制
发表时间:
2021-05
影响因子:
3.7
通讯作者:
Xi Zheng
Xi Zheng
中科院分区:
计算机科学2区
文献类型:
--
作者:
Guangquan Xu;GuoHua Xin;Litao Jiao;Jian Liu;Shaoying Liu;Meiqi Feng;Xi Zheng

文献摘要

参考文献

被引文献

相似文献

随着Android设备的日益普及,Android恶意软件正严重威胁着用户的安全。虽然这种威胁可以通过深度学习即服务(DLaaS)来检测,但作为DLaaS最薄弱部分的深度神经网络通常会被攻击者精心制作的对抗性样本所欺骗。在本文中,我们提出了一种新的半黑盒攻击框架,称为one-feature-each-iteration(OFEI),用于制作Android对抗样本。该框架修改尽可能少的特征,并且需要更少的分类器信息来欺骗分类器。我们进行了一个对照实验,以评估我们的OFEI框架,通过比较它与基准方法JSMF,GenAttack和逐点攻击。实验结果表明,我们的OFEI有较高的错误分类率为98.25%。此外,OFEI还可以扩展图像领域的传统白盒攻击方法,如快速梯度符号法(FGSM)和DeepFool,为Android制作对抗性样本。最后,为了增强DLaaS的安全性,我们利用贝叶斯神经网络的两个不确定性来构造组合不确定性,并将其用于检测对抗样本,达到了99.28%的高检测率。
With the growing popularity of Android devices, Android malware is seriously threatening the safety of users. Although such threats can be detected by deep learning as a service (DLaaS), deep neural networks as the weakest part of DLaaS are often deceived by the adversarial samples elaborated by attackers. In this paper, we propose a new semi-black-box attack framework called one-feature-each-iteration (OFEI) to craft Android adversarial samples. This framework modifies as few features as possible and requires less classifier information to fool the classifier. We conduct a controlled experiment to evaluate our OFEI framework by comparing it with the benchmark methods JSMF, GenAttack and pointwise attack. The experimental results show that our OFEI has a higher misclassification rate of 98.25%. Furthermore, OFEI can extend the traditional whitebox attack methods in the image field, such as fast gradient sign method (FGSM) and DeepFool, to craft adversarial samples for Android. Finally, to enhance the security of DLaaS, we use two uncertainties of the Bayesian neural network to construct the combined uncertainty, which is used to detect adversarial samples and achieves a high detection rate of 99.28%.
DOI: 10.1007/978-1-4612-0745-0
发表时间: 1995
期刊: --
影响因子: --
作者:
Radford M. Neal
通讯作者: Radford M. Neal
DOI: 10.1109/tcyb.2019.2931957
发表时间: 2021-03
影响因子: 11.8
作者:
Gongyu Zhou;Guangquan Xu;Jianye Hao;Shizhan Chen;Junfeng xu;Xi Zheng
通讯作者: Xi Zheng
DOI: --
发表时间: 2016-06
期刊: ArXiv
影响因子: --
作者:
Kathrin Grosse;Nicolas Papernot;Praveen Manoharan;M. Backes;P. Mcdaniel
通讯作者: Kathrin Grosse;Nicolas Papernot;Praveen Manoharan;M. Backes;P. Mcdaniel
DOI: 10.1007/s11265-006-0002-0
发表时间: 2007-01-01
期刊: JOURNAL OF VLSI SIGNAL PROCESSING SYSTEMS FOR SIGNAL IMAGE AND VIDEO TECHNOLOGY
影响因子: --
作者:
Qiu, Meikang;Xue, Chun;Shao, Zili
通讯作者: Shao, Zili
DOI: 10.14569/ijacsa.2014.050427
发表时间: 2017-03
影响因子: 0.9
作者:
Safaa Salam Hatem;M. Wafy;M. El-khouly
通讯作者: Safaa Salam Hatem;M. Wafy;M. El-khouly