RAMP is proposed, an attack enhancement method that uses a genetic algorithm to optimize reversed adversarial perturbations under black-box access and then injects them through functionality-preserving binary manipulations, which substantially improves attack effectiveness over trigger-only baselines.
Abstract
Deep learning-based malware detectors are commonly updated by fine-tuning on newly collected samples, but this practical update pipeline also creates an attack surface for training-time backdoor attacks. In realistic crowdsourced data collection, however, strict label vetting typically restricts attackers to the clean-label setting, in which poisoned samples must retain benign labels and functionality, making effective backdoor injection substantially harder. We present a new attack perspective based on feature-space manipulation: instead of relying solely on stronger trigger designs or selecting benign samples that are naturally similar to malware, we deliberately construct benign programs whose representations shift toward the malware region before trigger injection, thereby creating stronger feature-label conflicts during training. Based on this insight, we propose RAMP, an attack enhancement method that uses a genetic algorithm to optimize reversed adversarial perturbations under black-box access and then injects them through functionality-preserving binary manipulations. Extensive experiments show that RAMP substantially improves attack effectiveness over trigger-only baselines, with especially pronounced gains at low poisoning ratios, while maintaining accuracy on clean data. Moreover, RAMP can be combined with advanced trigger designs.
Gradient-seeded Reinforcement Learning And Stealthy Pruning (GRASP), a three-stage framework that tackles challenges of adversarial attacks on machine learning-based malware detectors, and out-performs baselines, achieving higher attack success with fewer queries and smaller file-size inflation.
Yu-Tong Liu, Jian-Ting Ning, Qi Feng et al.· Proceedings of the Thirty-Fi...· 1 citation
A systematic framework to enhance adversarial robustness is proposed, validated on the Malimg dataset and supersedes previous approaches by 13.15% in terms of the evasion rate and 37.34% in terms of retraining success.
Muhammad Arham Tariq, Allah Bux Sargano, Z. Habib et al.· International Journal of Inf...· 0 citations
Problem-space evasion attacks have exposed critical weaknesses in machine learning-based malware detectors; yet, their evaluation remains fragmented across models, datasets, and attack methodologies, often neglecting domain-specific requirements such as executability and functionality preservation. We address this gap...
Mashal Zainab, Salijona Dyrmishi, Hamid Bostani et al.· 0 citations
This work introduces BadCLIP, a novel backdoor attack that leverages prompt learning to effectively inject malicious behaviors into CLIP models even in data-scarce scenarios and achieves high attack success rates while maintaining comparable accuracy on clean images.
Kuo-Feng Gao, Jiawang Bai, Shaobo Min et al.· IEEE Transactions on Pattern...· 0 citations
This work presents Replicant, a deep reinforcement learning framework that learns the realistic task of evasion under a strict label-only black-box threat model and demonstrates that learning the task of evasion not only results in stronger attack performance but provides a better signal for hardening malware detectors...
Shae McFadden, Ilias Tsingenopoulos, Mario D'Onghia et al.· 0 citations
Malicious software is one of the most significant challenges in computer security. Continuous efforts to detect malicious software have evolved significantly since the advent of computing. With the rise of artificial intelligence, novel detection methodologies have emerged. This study investigates the application of...
Kirollos Magdy Luka, Tamer Abdelkader, K. Naik· Engineering Research Express· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.