The Robust Malware Detection Challenge and Greedy Random Accelerated Multi-Bit Search

Sicco Verwer, Azqa Nadeem, Christian Hammerschmidt, Laurens Bliek, Abdullah Al-Dujaili, Una May O'Reilly

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

12 Citations (Scopus)

Abstract

Training classifiers that are robust against adversarially modified examples is becoming increasingly important in practice. In the field of malware detection, adversaries modify malicious binary files to seem benign while preserving their malicious behavior. We report on the results of a recently held robust malware detection challenge. There were two tracks in which teams could participate: The attack track asked for adversarially modified malware samples and the defend track asked for trained neural network classifiers that are robust to such modifications. The teams were unaware of the attacks/defenses they had to detect/evade. Although only 9 teams participated, this unique setting allowed us to make several interesting observations. We also present the challenge winner: GRAMS, a family of novel techniques to train adversarially robust networks that preserve the intended (malicious) functionality and yield high-quality adversarial samples. These samples are used to iteratively train a robust classifier. We show that our techniques, based on discrete optimization techniques, beat purely gradient-based methods. GRAMS obtained first place in both the attack and defend tracks of the competition.

Original languageEnglish
Title of host publicationAISec 2020 - Proceedings of the 13th ACM Workshop on Artificial Intelligence and Security
PublisherAssociation for Computing Machinery, Inc
Pages61-70
Number of pages10
ISBN (Electronic)978-1-4503-8094-2
DOIs
Publication statusPublished - Nov 2020
Externally publishedYes
Event13th ACM Workshop on Artificial Intelligence and Security, AISec 2020 - Virtual, Online, United States
Duration: 13 Nov 202013 Nov 2020

Workshop

Workshop13th ACM Workshop on Artificial Intelligence and Security, AISec 2020
Country/TerritoryUnited States
CityVirtual, Online
Period13/11/2013/11/20

Funding

This work is part of the research programme Real-time data-driven maintenance logistics with project number 628.009.012, which is financed by the Dutch Research Council (NWO).

Keywords

  • adversarial learning
  • adversarial malware
  • discrete optimization
  • neural networks
  • robust malware detection
  • saddle-point optimization

Fingerprint

Dive into the research topics of 'The Robust Malware Detection Challenge and Greedy Random Accelerated Multi-Bit Search'. Together they form a unique fingerprint.

Cite this