The Robust Malware Detection Challenge and Greedy Random Accelerated Multi-Bit Search
Name
3411508.3421374.pdf
Size
1.19 MB
Format
Adobe PDF
Checksum (MD5)
cf73dbf22ab6f871a9454e0c991e5908
Author(s) • • • • •
Verwer, Sicco
Nadeem, Azqa
Hammerschmidt, Christian
Bliek, Laurens
Al-Dujaili, Abdullah
O'Reilly, Una-May
Date Issued
November 13, 2020
Publisher
ACM|13th ACM Workshop on Artificial Intelligence and Security
Citation
Verwer, Sicco, Nadeem, Azqa, Hammerschmidt, Christian, Bliek, Laurens, Al-Dujaili, Abdullah et al. 2020. "The Robust Malware Detection Challenge and Greedy Random Accelerated Multi-Bit Search."
Version
Final published version
Abstract
Training classifiers that are robust against adversarially modified examples is becoming increasingly important in practice. In the field of malware detection, adversaries modify malicious binary files to seem benign while preserving their malicious behavior. We report on the results of a recently held robust malware detection challenge. There were two tracks in which teams could participate: the attack track asked for adversarially modified malware samples and the defend track asked for trained neural network classifiers that are robust to such modifications. The teams were unaware of the attacks/defenses they had to detect/evade. Although only 9 teams participated, this unique setting allowed us to make several interesting observations.
We also present the challenge winner: GRAMS, a family of novel techniques to train adversarially robust networks that preserve the intended (malicious) functionality and yield high-quality adversarial samples. These samples are used to iteratively train a robust classifier. We show that our techniques, based on discrete optimization techniques, beat purely gradient-based methods. GRAMS obtained first place in both the attack and defend tracks of the competition.
Description
AISec’20, November 13, 2020, Virtual Event, USA
MIT Department
Massachusetts Institute of Technology. Computer Science and Artificial Intelligence Laboratory
Terms of Use
Article is made available in accordance with the publisher's policy and may be subject to US copyright law. Please refer to the publisher's site for terms of use.
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1145/3411508.3421374