🤖 AI Summary
This study addresses the vulnerability of machine learning–based malware detection systems to adversarial attacks by constructing the first large-scale, real-world adversarial malware dataset with fine-grained labels at both family and type levels, comprising 77,943 PE adversarial samples generated using diverse techniques. Leveraging EMBER feature extraction, VirusTotal metadata analysis, and model retraining experiments, the work quantitatively evaluates the effectiveness of both evasion and poisoning attacks. Results demonstrate that adversarial samples achieve evasion rates of 98.35% (at the family level) and 92.20% (at the type level) against EMBER-based detectors. Moreover, injecting merely 0.5% poisoning samples during retraining elevates the evasion rate from 26.1% to 92.8%, starkly exposing critical robustness deficiencies in current models.
📝 Abstract
We present a dataset of adversarial malware samples derived from the public RawMal-TF collection of real-world malware binaries. Using a suite of adversarial malware generators, we construct two sets of adversarial PE files: 44,347 family-labelled samples and 33,596 type-labelled samples, achieving evasion rates of 98.35 % and 92.20 % against the EMBER classifier, respectively. Each adversarial binary is accompanied by detailed metadata, including EMBER scores and VirusTotal classifications. We further demonstrate the susceptibility of malware classification pipelines to data poisoning attacks through a series of training experiments. Injecting fully mislabelled adversarial samples representing only 0.5 % of the training data in the family-labelled dataset increases the evasion rate against the re-trained classifier from 26.1 % to 92.8 %. The dataset is publicly released to facilitate future research on adversarial malware, poisoning attacks, and the robustness of machine-learning-based malware detection systems.