Trust Under Siege: Label Spoofing Attacks against Machine Learning for Android Malware Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lan, Tianwei, Demetrio, Luca, Nait-Abdesselam, Farid, Han, Yufei, Aonzo, Simone
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913737906061312
author Lan, Tianwei
Demetrio, Luca
Nait-Abdesselam, Farid
Han, Yufei
Aonzo, Simone
author_facet Lan, Tianwei
Demetrio, Luca
Nait-Abdesselam, Farid
Han, Yufei
Aonzo, Simone
contents Machine learning (ML) malware detectors rely heavily on crowd-sourced AntiVirus (AV) labels, with platforms like VirusTotal serving as a trusted source of malware annotations. But what if attackers could manipulate these labels to classify benign software as malicious? We introduce label spoofing attacks, a new threat that contaminates crowd-sourced datasets by embedding minimal and undetectable malicious patterns into benign samples. These patterns coerce AV engines into misclassifying legitimate files as harmful, enabling poisoning attacks against ML-based malware classifiers trained on those data. We demonstrate this scenario by developing AndroVenom, a methodology for polluting realistic data sources, causing consequent poisoning attacks against ML malware detectors. Experiments show that not only state-of-the-art feature extractors are unable to filter such injection, but also various ML models experience Denial of Service already with 1% poisoned samples. Additionally, attackers can flip decisions of specific unaltered benign samples by modifying only 0.015% of the training data, threatening their reputation and market share and being unable to be stopped by anomaly detectors on training data. We conclude our manuscript by raising the alarm on the trustworthiness of the training process based on AV annotations, requiring further investigation on how to produce proper labels for ML malware detectors.
format Preprint
id arxiv_https___arxiv_org_abs_2503_11841
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Trust Under Siege: Label Spoofing Attacks against Machine Learning for Android Malware Detection
Lan, Tianwei
Demetrio, Luca
Nait-Abdesselam, Farid
Han, Yufei
Aonzo, Simone
Cryptography and Security
Machine Learning
Machine learning (ML) malware detectors rely heavily on crowd-sourced AntiVirus (AV) labels, with platforms like VirusTotal serving as a trusted source of malware annotations. But what if attackers could manipulate these labels to classify benign software as malicious? We introduce label spoofing attacks, a new threat that contaminates crowd-sourced datasets by embedding minimal and undetectable malicious patterns into benign samples. These patterns coerce AV engines into misclassifying legitimate files as harmful, enabling poisoning attacks against ML-based malware classifiers trained on those data. We demonstrate this scenario by developing AndroVenom, a methodology for polluting realistic data sources, causing consequent poisoning attacks against ML malware detectors. Experiments show that not only state-of-the-art feature extractors are unable to filter such injection, but also various ML models experience Denial of Service already with 1% poisoned samples. Additionally, attackers can flip decisions of specific unaltered benign samples by modifying only 0.015% of the training data, threatening their reputation and market share and being unable to be stopped by anomaly detectors on training data. We conclude our manuscript by raising the alarm on the trustworthiness of the training process based on AV annotations, requiring further investigation on how to produce proper labels for ML malware detectors.
title Trust Under Siege: Label Spoofing Attacks against Machine Learning for Android Malware Detection
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2503.11841