Improving Adversarial Robustness in Android Malware Detection by Reducing the Impact of Spurious Correlations

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Bostani, Hamid, Zhao, Zhengyu, Moonsamy, Veelasha
Format: Preprint
Veröffentlicht: 2024
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866913484638257152
author Bostani, Hamid
Zhao, Zhengyu
Moonsamy, Veelasha
author_facet Bostani, Hamid
Zhao, Zhengyu
Moonsamy, Veelasha
contents Machine learning (ML) has demonstrated significant advancements in Android malware detection (AMD); however, the resilience of ML against realistic evasion attacks remains a major obstacle for AMD. One of the primary factors contributing to this challenge is the scarcity of reliable generalizations. Malware classifiers with limited generalizability tend to overfit spurious correlations derived from biased features. Consequently, adversarial examples (AEs), generated by evasion attacks, can modify these features to evade detection. In this study, we propose a domain adaptation technique to improve the generalizability of AMD by aligning the distribution of malware samples and AEs. Specifically, we utilize meaningful feature dependencies, reflecting domain constraints in the feature space, to establish a robust feature space. Training on the proposed robust feature space enables malware classifiers to learn from predefined patterns associated with app functionality rather than from individual features. This approach helps mitigate spurious correlations inherent in the initial feature space. Our experiments conducted on DREBIN, a renowned Android malware detector, demonstrate that our approach surpasses the state-of-the-art defense, Sec-SVM, when facing realistic evasion attacks. In particular, our defense can improve adversarial robustness by up to 55% against realistic evasion attacks compared to Sec-SVM.
format Preprint
id arxiv_https___arxiv_org_abs_2408_16025
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Improving Adversarial Robustness in Android Malware Detection by Reducing the Impact of Spurious Correlations
Bostani, Hamid
Zhao, Zhengyu
Moonsamy, Veelasha
Cryptography and Security
Machine Learning
Software Engineering
Machine learning (ML) has demonstrated significant advancements in Android malware detection (AMD); however, the resilience of ML against realistic evasion attacks remains a major obstacle for AMD. One of the primary factors contributing to this challenge is the scarcity of reliable generalizations. Malware classifiers with limited generalizability tend to overfit spurious correlations derived from biased features. Consequently, adversarial examples (AEs), generated by evasion attacks, can modify these features to evade detection. In this study, we propose a domain adaptation technique to improve the generalizability of AMD by aligning the distribution of malware samples and AEs. Specifically, we utilize meaningful feature dependencies, reflecting domain constraints in the feature space, to establish a robust feature space. Training on the proposed robust feature space enables malware classifiers to learn from predefined patterns associated with app functionality rather than from individual features. This approach helps mitigate spurious correlations inherent in the initial feature space. Our experiments conducted on DREBIN, a renowned Android malware detector, demonstrate that our approach surpasses the state-of-the-art defense, Sec-SVM, when facing realistic evasion attacks. In particular, our defense can improve adversarial robustness by up to 55% against realistic evasion attacks compared to Sec-SVM.
title Improving Adversarial Robustness in Android Malware Detection by Reducing the Impact of Spurious Correlations
topic Cryptography and Security
Machine Learning
Software Engineering
url https://arxiv.org/abs/2408.16025