课题基金 / 基金详情

Making malware classification more robust to adversarial attacks

Making malware classification more robust to adversarial attacks
使恶意软件分类对对抗性攻击更加稳健
批准号:
2320321
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2019
资助国家:
英国
项目状态:
已结题
起止时间:
2019 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
摘要:现代恶意软件分类使用各种技术来衡量特定示例是恶意的还是良性的。人工智能的最新进展为机器学习模型(如人工神经网络)在恶意软件分类中发挥重要作用铺平了道路。然而,现在众所周知,这样的模型容易受到对抗性例子的影响。对抗性示例是故意欺骗分类器使其错误分类的示例。已经讨论并提出了各种技术,以使分类器对此类攻击更具弹性,但大多数工作都是在图像识别领域进行的(与恶意软件分类相反),这些技术并不是最佳的。恶意软件分类的弹性绝对是至关重要的,因此我们的目标是设计技术来对抗该领域中对抗性示例的影响。我们希望研究的各种技术,如基于混合模型的系统、监管系统,甚至是基于机器学习的方法来对抗对抗的例子,都是特别新颖的。由于在这一领域缺乏工作,我目前正处于深入的文献回顾阶段,以评估在这一领域所做的工作,因为这一领域大多未被探索。建议的研究方法如下:广泛的文献综述,具体到研究目标的领域以及现有的工作。实验评估这些现有的防御和其他更新颖的技术,从实用的角度了解当前的状态。识别现有技术中的问题和改进的机会所在。技术的发展,以防止对抗性例子的错误分类。对已开发的技术进行评价和分析,并与现有技术进行比较。通过结业论文讨论结果并报告结果。
英文摘要
Abstract:Modern malware classification uses various techniques to gauge whether a particular example is malicious or benign. Recent advances in AI have paved the way for machine learning models (such as artificial neural networks) to play a substantial role in malware classification. However, it is now well-known that such models are susceptible to adversarial examples. An adversarial example is an example which is designed to intentionally deceive the classifier so that it misclassifies it. Various techniques have been discussed and presented to make classifiers more resilient against such attacks, but most work has been carried out in the image recognition domain (as opposed to malware classification) and these techniques are not optimal. Resilience in malware classification is absolutely vital and thus we aim to devise techniques to counter the effects of adversarial examples in this domain.---There are various techniques which we wish to research such as a system based on hybrid models, a regulatory system or perhaps even machine learning-based approaches to counter adversarial examples are especially novel. As a result of the lack of work in this area, I am currently in a deep literature review phase to gauge what has been done in this area since it is mostly unexplored for this domain.A proposed research methodology is below:1. Extensive literature review specific to areas in research objective as well as existing works.2. Experimental evaluation of these existing defences and other more novel techniques to understand the current state from a practical point of view.3. Identification of problems within existing techniques and where opportunities for enhancement lie.4. Development of techniques to be able to counter erroneous misclassification of adversarial examples.5. Evaluation and analysis of the developed techniques and comparison with existing techniques.6. Discussion of results and report on results through final thesis.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金