Adversarial Co-Evolution of Malware and Detection Models: A Bilevel Optimization Perspective

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Jurečková, Olha, Jureček, Martin, Kozák, Matouš, Lórencz, Róbert
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915955315048448
author Jurečková, Olha
Jureček, Martin
Kozák, Matouš
Lórencz, Róbert
author_facet Jurečková, Olha
Jureček, Martin
Kozák, Matouš
Lórencz, Róbert
contents Machine learning-based malware detectors are increasingly vulnerable to adversarial examples. Traditional defenses, such as one-shot adversarial training, often fail against adaptive attackers who use reinforcement learning to bypass detection. This paper proposes a robust defense framework based on bilevel optimization, explicitly modeling the strategic interaction between a defender and an attacker as an adversarial co-evolutionary process. We evaluate our approach using the MAB-malware framework against three distinct malware families: Mokes, Strab, and DCRat. Our experimental results demonstrate that while standard classifiers and basic adversarial retraining often remain vulnerable, showing evasion rates as high as 90 %, the proposed bilevel optimization approach consistently achieves near-total immunity, reducing evasion rates to 0 - 1.89 %. Furthermore, the iterative framework significantly increases the attacker's query complexity, raising the average cost of successful evasion by up to two orders of magnitude. These findings suggest that modeling the iterative cycle of attack and defense through bilevel optimization is essential for developing resilient malware detection systems capable of withstanding evolving adversarial threats.
format Preprint
id arxiv_https___arxiv_org_abs_2604_22569
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Adversarial Co-Evolution of Malware and Detection Models: A Bilevel Optimization Perspective
Jurečková, Olha
Jureček, Martin
Kozák, Matouš
Lórencz, Róbert
Cryptography and Security
Machine Learning
Machine learning-based malware detectors are increasingly vulnerable to adversarial examples. Traditional defenses, such as one-shot adversarial training, often fail against adaptive attackers who use reinforcement learning to bypass detection. This paper proposes a robust defense framework based on bilevel optimization, explicitly modeling the strategic interaction between a defender and an attacker as an adversarial co-evolutionary process. We evaluate our approach using the MAB-malware framework against three distinct malware families: Mokes, Strab, and DCRat. Our experimental results demonstrate that while standard classifiers and basic adversarial retraining often remain vulnerable, showing evasion rates as high as 90 %, the proposed bilevel optimization approach consistently achieves near-total immunity, reducing evasion rates to 0 - 1.89 %. Furthermore, the iterative framework significantly increases the attacker's query complexity, raising the average cost of successful evasion by up to two orders of magnitude. These findings suggest that modeling the iterative cycle of attack and defense through bilevel optimization is essential for developing resilient malware detection systems capable of withstanding evolving adversarial threats.
title Adversarial Co-Evolution of Malware and Detection Models: A Bilevel Optimization Perspective
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2604.22569