Certifiably robust malware detectors by design

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Gimenez, Pierre-Francois, Sivaprasad, Sarath, Fritz, Mario
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915445909487616
author Gimenez, Pierre-Francois
Sivaprasad, Sarath
Fritz, Mario
author_facet Gimenez, Pierre-Francois
Sivaprasad, Sarath
Fritz, Mario
contents Malware analysis involves analyzing suspicious software to detect malicious payloads. Static malware analysis, which does not require software execution, relies increasingly on machine learning techniques to achieve scalability. Although such techniques obtain very high detection accuracy, they can be easily evaded with adversarial examples where a few modifications of the sample can dupe the detector without modifying the behavior of the software. Unlike other domains, such as computer vision, creating an adversarial example of malware without altering its functionality requires specific transformations. We propose a new model architecture for certifiably robust malware detection by design. In addition, we show that every robust detector can be decomposed into a specific structure, which can be applied to learn empirically robust malware detectors, even on fragile features. Our framework ERDALT is based on this structure. We compare and validate these approaches with machine-learning-based malware detection methods, allowing for robust detection with limited reduction of detection performance.
format Preprint
id arxiv_https___arxiv_org_abs_2508_10038
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Certifiably robust malware detectors by design
Gimenez, Pierre-Francois
Sivaprasad, Sarath
Fritz, Mario
Cryptography and Security
Artificial Intelligence
Malware analysis involves analyzing suspicious software to detect malicious payloads. Static malware analysis, which does not require software execution, relies increasingly on machine learning techniques to achieve scalability. Although such techniques obtain very high detection accuracy, they can be easily evaded with adversarial examples where a few modifications of the sample can dupe the detector without modifying the behavior of the software. Unlike other domains, such as computer vision, creating an adversarial example of malware without altering its functionality requires specific transformations. We propose a new model architecture for certifiably robust malware detection by design. In addition, we show that every robust detector can be decomposed into a specific structure, which can be applied to learn empirically robust malware detectors, even on fragile features. Our framework ERDALT is based on this structure. We compare and validate these approaches with machine-learning-based malware detection methods, allowing for robust detection with limited reduction of detection performance.
title Certifiably robust malware detectors by design
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2508.10038