Can you See me? On the Visibility of NOPs against Android Malware Detectors

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Soi, Diego, Maiorca, Davide, Giacinto, Giorgio, Berger, Harel
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917556862844928
author Soi, Diego
Maiorca, Davide
Giacinto, Giorgio
Berger, Harel
author_facet Soi, Diego
Maiorca, Davide
Giacinto, Giorgio
Berger, Harel
contents Android malware still represents the most significant threat to mobile systems. While Machine Learning systems are increasingly used to identify these threats, past studies have revealed that attackers can bypass these detection mechanisms by making subtle changes to Android applications, such as adding specific API calls. These modifications are often referred to as No OPerations (NOP), which ideally should not alter the semantics of the program. However, many NOPs can be spotted and eliminated by refining the app analysis process. This paper proposes a visibility metric that assesses the difficulty in spotting NOPs and similar non-operational codes. We tested our metric on a state-of-the-art, opcode-based deep learning system for Android malware detection. We implemented attacks on the feature and problem spaces and calculated their visibility according to our metric. The attained results show an intriguing trade-off between evasion efficacy and detectability: our metric can be valuable to ensure the real effectiveness of an adversarial attack, also serving as a useful aid to develop better defenses.
format Preprint
id arxiv_https___arxiv_org_abs_2312_17356
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Can you See me? On the Visibility of NOPs against Android Malware Detectors
Soi, Diego
Maiorca, Davide
Giacinto, Giorgio
Berger, Harel
Cryptography and Security
Android malware still represents the most significant threat to mobile systems. While Machine Learning systems are increasingly used to identify these threats, past studies have revealed that attackers can bypass these detection mechanisms by making subtle changes to Android applications, such as adding specific API calls. These modifications are often referred to as No OPerations (NOP), which ideally should not alter the semantics of the program. However, many NOPs can be spotted and eliminated by refining the app analysis process. This paper proposes a visibility metric that assesses the difficulty in spotting NOPs and similar non-operational codes. We tested our metric on a state-of-the-art, opcode-based deep learning system for Android malware detection. We implemented attacks on the feature and problem spaces and calculated their visibility according to our metric. The attained results show an intriguing trade-off between evasion efficacy and detectability: our metric can be valuable to ensure the real effectiveness of an adversarial attack, also serving as a useful aid to develop better defenses.
title Can you See me? On the Visibility of NOPs against Android Malware Detectors
topic Cryptography and Security
url https://arxiv.org/abs/2312.17356