Black-box Attacks Against Neural Binary Function Detection

Black-box Attacks Against Neural Binary Function Detection
复制标题

DOI:
10.1145/3607199.3607200
复制
发表时间:
2022-08
期刊:
Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses
影响因子:
--
通讯作者:
Josh Bundt;Michael Davinroy;Ioannis Agadakos;Alina Oprea;W. Robertson
Josh Bundt;Michael Davinroy;Ioannis Agadakos;Alina Oprea;W. Robertson
中科院分区:
其他
文献类型:
--
作者:
Josh Bundt;Michael Davinroy;Ioannis Agadakos;Alina Oprea;W. Robertson

文献摘要

相似文献

基于深度神经网络(DNN)的二进制分析,或神经二进制分析(NBAs),近年来已成为热门研究课题。DNN在推动自然语言和图像处理领域的性能和准确性方面取得了巨大成功。因此,DNN非常有希望解决由于有损编译过程导致的缺乏完整信息而难以解决的二进制分析问题。尽管有这样的承诺,但考虑到二元分析经常在敌对的环境下运行,目前尚不清楚重新利用最初为其他问题领域开发的嵌入和模型架构的流行策略是否合理。在本文中,我们经验性地证明了神经功能边界检测的现有技术容易受到无意和故意的对抗性攻击。我们从当前一代NBAs是建立在嵌入和模型架构旨在解决语法问题的见解。我们设计了一个简单的,可重复的,可扩展的黑盒方法,探索空间的无意攻击-指令序列,可以发出的常见的编译器工具链和配置-利用这种语法设计的重点。然后,我们表明,这些无意中的错误分类可以被攻击者利用,作为一个高效的黑盒对抗性示例生成过程的基础。我们针对两种最先进的神经功能边界检测器:XDA和DeepDi来评估这种方法。最后,我们对评估数据进行了分析,并对未来的研究如何避免遭受类似的攻击提出了建议。
Binary analyses based on deep neural networks (DNNs), or neural binary analyses (NBAs), have become a hotly researched topic in recent years. DNNs have been wildly successful at pushing the performance and accuracy envelopes in the natural language and image processing domains. Thus, DNNs are highly promising for solving binary analysis problems that are hard due to a lack of complete information resulting from the lossy compilation process. Despite this promise, it is unclear that the prevailing strategy of repurposing embeddings and model architectures originally developed for other problem domains is sound given the adversarial contexts under which binary analysis often operates. In this paper, we empirically demonstrate that the current state of the art in neural function boundary detection is vulnerable to both inadvertent and deliberate adversarial attacks. We proceed from the insight that current generation NBAs are built upon embeddings and model architectures intended to solve syntactic problems. We devise a simple, reproducible, and scalable black-box methodology for exploring the space of inadvertent attacks – instruction sequences that could be emitted by common compiler toolchains and configurations – that exploits this syntactic design focus. We then show that these inadvertent misclassifications can be exploited by an attacker, serving as the basis for a highly effective black-box adversarial example generation process. We evaluate this methodology against two state-of-the-art neural function boundary detectors: XDA and DeepDi. We conclude with an analysis of the evaluation data and recommendations for how future research might avoid succumbing to similar attacks.