αCyber: Enhancing Robustness of Android Malware Detection System against Adversarial Attacks on Heterogeneous Graph based Model

αCyber: Enhancing Robustness of Android Malware Detection System against Adversarial Attacks on Heterogeneous Graph based Model
复制标题

DOI:
10.1145/3357384.3357875
复制
发表时间:
2019-11
期刊:
Proceedings of the 28th ACM International Conference on Information and Knowledge Management
影响因子:
--
通讯作者:
Shifu Hou;Yujie Fan;Yiming Zhang;Yanfang Ye;Jingwei Lei;Wenqiang Wan;Jiabin Wang;Qi Xiong;Fudong Shao
Shifu Hou;Yujie Fan;Yiming Zhang;Yanfang Ye;Jingwei Lei;Wenqiang Wan;Jiabin Wang;Qi Xiong;Fudong Shao
中科院分区:
其他
文献类型:
--
作者:
Shifu Hou;Yujie Fan;Yiming Zhang;Yanfang Ye;Jingwei Lei;Wenqiang Wan;Jiabin Wang;Qi Xiong;Fudong Shao

文献摘要

被引文献

相似文献

Android恶意软件的爆炸性增长和不断增长的社会化需要保护移动用户免受新型威胁的影响。但是,在Android恶意软件检测中,他们的成功也可能激励攻击者击败基于HG的模型,以绕过该检测在本文中,我们在第一次尝试中探索了基于HG的模型的对抗性攻击和/或防御的工作。首先,通过考虑Android恶意软件攻击者的当前功能和知识来有效地对抗对抗性攻击,首先在HG数据上提出一个新颖而实用的对抗攻击模型(称为HG攻击) HG,我们提出了一个依赖而优雅的防御范式(命名为RAD-HGC),以增强基于HG的分类器在Android恶意软件检测中的鲁棒性。我们开发的系统αCyber​​,它整合了我们提出的防御模型RAD-HGC,该模型对对对抗性恶意软件的实际攻击具有对由HG数据进行的实际对抗性恶意软件攻击HG攻击。
The explosive growth and increasing sophistication of Android malware call for new defensive techniques that are capable of protecting mobile users against novel threats. To combat the evolving Android malware attacks, systems of HinDroid and AiDroid have demonstrated the success of heterogeneous graph (HG) based classifiers in Android malware detection; however, their success may also incentivize attackers to defeat HG based models to bypass the detection. By far, there has no work on adversarial attack and/or defense on HG data. In this paper, we explore the robustness of HG based model in Android malware detection at the first attempt. In particular, based on a generic HG based classifier, (1) we first present a novel yet practical adversarial attack model (named HG-Attack) on HG data by considering Android malware attackers' current capabilities and knowledge; (2) to effectively combat the adversarial attacks on HG, we then propose a resilient yet elegant defense paradigm (named Rad-HGC) to enhance robustness of HG based classifier in Android malware detection. Promising experimental results based on the large-scale and real sample collections from Tencent Security Lab demonstrate the effectiveness of our developed system αCyber, which integrates our proposed defense model Rad-HGC that is resilient against practical adversarial malware attacks on the HG data performed by HG-Attack.