课题基金 / 基金详情

Making malware classification more robust to adversarial attacks

Making malware classification more robust to adversarial attacks
使恶意软件分类对对抗性攻击更加稳健
批准号:
2320321
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2019
资助国家:
英国
项目状态:
已结题
起止时间:
2019 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Abstract:Modern malware classification uses various techniques to gauge whether a particular example is malicious or benign. Recent advances in AI have paved the way for machine learning models (such as artificial neural networks) to play a substantial role in malware classification. However, it is now well-known that such models are susceptible to adversarial examples. An adversarial example is an example which is designed to intentionally deceive the classifier so that it misclassifies it. Various techniques have been discussed and presented to make classifiers more resilient against such attacks, but most work has been carried out in the image recognition domain (as opposed to malware classification) and these techniques are not optimal. Resilience in malware classification is absolutely vital and thus we aim to devise techniques to counter the effects of adversarial examples in this domain.---There are various techniques which we wish to research such as a system based on hybrid models, a regulatory system or perhaps even machine learning-based approaches to counter adversarial examples are especially novel. As a result of the lack of work in this area, I am currently in a deep literature review phase to gauge what has been done in this area since it is mostly unexplored for this domain.A proposed research methodology is below:1. Extensive literature review specific to areas in research objective as well as existing works.2. Experimental evaluation of these existing defences and other more novel techniques to understand the current state from a practical point of view.3. Identification of problems within existing techniques and where opportunities for enhancement lie.4. Development of techniques to be able to counter erroneous misclassification of adversarial examples.5. Evaluation and analysis of the developed techniques and comparison with existing techniques.6. Discussion of results and report on results through final thesis.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金