Adversarial Learning Attacks on Graph-based IoT Malware Detection Systems

Adversarial Learning Attacks on Graph-based IoT Malware Detection Systems
复制标题

DOI:
10.1109/icdcs.2019.00130
复制
发表时间:
2019-07
期刊:
2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS)
影响因子:
--
通讯作者:
Ahmed A. Abusnaina;Aminollah Khormali;Hisham Alasmary;Jeman Park;Afsah Anwar;Aziz Mohaisen
Ahmed A. Abusnaina;Aminollah Khormali;Hisham Alasmary;Jeman Park;Afsah Anwar;Aziz Mohaisen
中科院分区:
其他
文献类型:
--
作者:
Ahmed A. Abusnaina;Aminollah Khormali;Hisham Alasmary;Jeman Park;Afsah Anwar;Aziz Mohaisen

文献摘要

被引文献

相似文献

基于控制流图(CFG)特征和深度学习网络的物联网恶意软件检测得到了广泛研究。本研究的主要目的是探究此类模型对抗对抗性学习的鲁棒性。我们设计了两种方法来制作对抗性物联网软件:现成方法以及图嵌入与增强(GEA)方法。在现成的对抗性学习攻击方法中,我们检验了八种不同的对抗性学习方法,以迫使模型误分类。GEA方法旨在通过将良性样本精心嵌入到恶意样本中,来保持生成的对抗样本的功能性和实用性。我们进行了大量实验以评估所提方法的性能,结果表明现成的对抗性攻击方法能够实现100%的误分类率。此外,我们观察到GEA方法能够将所有物联网恶意软件样本误分类为良性。这项工作的研究结果凸显了针对对抗性学习开发更强大检测工具的必要性,包括不易被操纵的特征,不像基于CFG的特征。这项研究的影响相当广泛,因为本研究中所挑战的方法被广泛用于其他使用图的应用中。
IoT malware detection using control flow graph (CFG)-based features and deep learning networks are widely explored. The main goal of this study is to investigate the robustness of such models against adversarial learning. We designed two approaches to craft adversarial IoT software: off-the-shelf methods and Graph Embedding and Augmentation (GEA) method. In the off-the-shelf adversarial learning attack methods, we examine eight different adversarial learning methods to force the model to misclassification. The GEA approach aims to preserve the functionality and practicality of the generated adversarial sample through a careful embedding of a benign sample to a malicious one. Intensive experiments are conducted to evaluate the performance of the proposed method, showing that off-the-shelf adversarial attack methods are able to achieve a misclassification rate of 100%. In addition, we observed that the GEA approach is able to misclassify all IoT malware samples as benign. The findings of this work highlight the essential need for more robust detection tools against adversarial learning, including features that are not easy to manipulate, unlike CFG-based features. The implications of the study are quite broad, since the approach challenged in this work is widely used for other applications using graphs.