Lune

DAC2023Top-tier venue

MPass: Bypassing Learning-based Static Malware Detectors

Jialai Wang, Wenjie Qu, Yi Rong, Han Qiu, Qi Li, Zongpeng Li, Chao Zhang

2023Year
4Citations
3Top-tier citations

Abstract

Machine learning (ML) based static malware detectors are widely deployed, but vulnerable to adversarial attacks. Unlike images or texts, tiny modifications to malware samples would significantly compromise their functionality. Consequently, existing attacks against images or texts will be significantly restricted when being deployed on malware detectors. In this work, we propose a hard-label black-box attack MPass against ML-based detectors. MPass employs a problemspace explainability method to locate critical positions of malware, applies adversarial modifications to such positions, and utilizes a runtime recovery technique to preserve the functionality. Experiments show MPass outperforms existing solutions and bypasses both state-of-the-art offline models and commercial ML-based antivirus products.

1 Due to the high runtime overhead of dynamic analysis, ML-based dynamic malware detectors are only deployed in lab environments for high-value suspicious sample analysis. Static detectors are widely deployed in practice and thus become adversaries' targets.

2 Malware developers may reuse binary components and get caught by AVs. Thus, adversarial attacks should target binaries.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext 1ce34b13-d861-48e4-ba3c-2b977d4cead2

Cited by top-tier papers3

Ask how each one uses it

Builds on8

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines