Adversarially Robust and Interpretable Magecart Malware Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pereira, Pedro, Gouveia, José, Vitorino, João, Maia, Eva, Praça, Isabel
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911251688325120
author Pereira, Pedro
Gouveia, José
Vitorino, João
Maia, Eva
Praça, Isabel
author_facet Pereira, Pedro
Gouveia, José
Vitorino, João
Maia, Eva
Praça, Isabel
contents Magecart skimming attacks have emerged as a significant threat to client-side security and user trust in online payment systems. This paper addresses the challenge of achieving robust and explainable detection of Magecart attacks through a comparative study of various Machine Learning (ML) models with a real-world dataset. Tree-based, linear, and kernel-based models were applied, further enhanced through hyperparameter tuning and feature selection, to distinguish between benign and malicious scripts. Such models are supported by a Behavior Deterministic Finite Automaton (DFA) which captures structural behavior patterns in scripts, helping to analyze and classify client-side script execution logs. To ensure robustness against adversarial evasion attacks, the ML models were adversarially trained and evaluated using attacks from the Adversarial Robustness Toolbox and the Adaptative Perturbation Pattern Method. In addition, concise explanations of ML model decisions are provided, supporting transparency and user trust. Experimental validation demonstrated high detection performance and interpretable reasoning, demonstrating that traditional ML models can be effective in real-world web security contexts.
format Preprint
id arxiv_https___arxiv_org_abs_2511_04440
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adversarially Robust and Interpretable Magecart Malware Detection
Pereira, Pedro
Gouveia, José
Vitorino, João
Maia, Eva
Praça, Isabel
Cryptography and Security
Magecart skimming attacks have emerged as a significant threat to client-side security and user trust in online payment systems. This paper addresses the challenge of achieving robust and explainable detection of Magecart attacks through a comparative study of various Machine Learning (ML) models with a real-world dataset. Tree-based, linear, and kernel-based models were applied, further enhanced through hyperparameter tuning and feature selection, to distinguish between benign and malicious scripts. Such models are supported by a Behavior Deterministic Finite Automaton (DFA) which captures structural behavior patterns in scripts, helping to analyze and classify client-side script execution logs. To ensure robustness against adversarial evasion attacks, the ML models were adversarially trained and evaluated using attacks from the Adversarial Robustness Toolbox and the Adaptative Perturbation Pattern Method. In addition, concise explanations of ML model decisions are provided, supporting transparency and user trust. Experimental validation demonstrated high detection performance and interpretable reasoning, demonstrating that traditional ML models can be effective in real-world web security contexts.
title Adversarially Robust and Interpretable Magecart Malware Detection
topic Cryptography and Security
url https://arxiv.org/abs/2511.04440