anti-evasion analysis

Designs and implements methods, tools, and evaluation frameworks to detect, counter, and measure evasion tactics used by adversarial code or suspicious artifacts to avoid analysis and detection. This work includes building anti-evasion techniques such as hardened sandboxes and stealthy instrumentation, active probing and behavioral normalization, and test suites that trigger hidden behaviors and quantify the robustness of analysis pipelines.

anti-evasionanalysis

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.13
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$224K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the limitations of existing adversarial simulation tools, which rely on agent-based instrumentation of target systems, often leaving anomalous artifacts and failing to faithfully replicate human attacker behavior—particularly in critical phases of the cyber kill chain such as initial access and interactive operations. To overcome these shortcomings, the authors propose and implement an open-source attack scripting language coupled with an agentless execution engine that closely emulates real-world attacker tactics. This approach enables high-fidelity, interactive simulation of complete kill chain stages, including initial access, privilege escalation, and lateral movement. Experimental results demonstrate that system logs generated by this method exhibit significantly greater behavioral similarity to those produced by actual human-driven attacks, thereby enhancing the realism and effectiveness of security testing and intrusion detection research.

adversary emulationattack automationcyber attack scenarios

Secure Development of a Hooking-Based Deception Framework Against Keylogging Techniques

Aug 06, 2025
MS
Md Sajidul Islam Sajid
🏛️ Towson University

Advanced keyloggers commonly evade conventional defenses via anti-hooking techniques. To address this, we propose an active deception framework that intercepts input APIs through an enhanced API hooking layer and injects dynamically generated, realistic decoy keystrokes at runtime to mislead attackers. Our approach innovatively integrates anti-hooking behavior detection with a self-healing mechanism to ensure robust, persistent hooking under adversarial interference. Furthermore, it employs lightweight injection and stealthy obfuscation strategies to achieve minimal overhead—rendering the defense imperceptible to users—while maximizing deception success rates. Evaluated against a custom-built “super keylogger” and 50 real-world keylogger samples, our framework demonstrates strong resilience against diverse evasion attempts, significantly enhancing robustness against sophisticated anti-detection techniques.

Counter keyloggers with decoy keystrokes via API hookingEnsure deception continuity against evasion strategiesOvercome anti-hooking techniques in advanced keyloggers

In black-box settings, it is challenging to discern whether a large language model’s refusal to respond stems from external safety guardrails or its intrinsic alignment mechanisms, thereby limiting the effectiveness of adversarial attacks. This work proposes the first black-box guardrail reconnaissance method that requires no internal model knowledge. By integrating HTTP metadata, lexical features, and temporal behavioral signals—combined with statistical significance testing and a classification model—the approach accurately detects the presence of guardrails and identifies their interception categories. Experimental results demonstrate that the method achieves 100% accuracy in detecting guardrail presence, exhibits highly statistically significant discrimination between benign and malicious interactions (q < 0.001), and attains an average F1 score of 98% on unseen prompts for guardrail interception classification.

AI securitybehavioral monitoringblack-box adversarial emulation

To address the challenge posed by widespread adoption of Techniques Against Dynamic Analysis (TADA) in malware—which undermines sandboxing efficacy and impedes manual reverse engineering—this paper proposes the first large language model (LLM)-based method for automatic TADA code localization. Our approach integrates semantic understanding and behavioral reasoning without relying on static symbols or runtime traces. It leverages fine-tuned CodeLlama, a novel disassembled instruction sequence encoding scheme, multi-granularity contextual prompting, and cross-sample transfer learning to precisely identify stealthy detection logic. Evaluated on a public dataset, our method achieves an 87.80% localization accuracy and successfully identifies real-world TADA snippets in four prevalent malware families (e.g., Emotet and QakBot), with an average localization error of fewer than three instructions. This significantly enhances dynamic analysis robustness and accelerates reverse-engineering workflows.

Assisting reverse engineers in debugging malware efficientlyIdentifying anti-dynamic analysis techniques in malware codeReducing false negatives in malware sandbox detection

This work addresses the lack of transparency in autonomous penetration testing agents when verifying vulnerabilities under deceptive responses, where conflicting evidence handling and decision logic are difficult to trace. To this end, the paper introduces ATOBench, an evaluation framework that enables the first observable verification chain by injecting registered response transformations at runtime, aligning original and transformed test snippets, and reconstructing source links to track actions, evidence recovery, termination decisions, and report justification. The framework formalizes three frozen observation contracts—exploit proof, resource ownership, and reusable artifacts—to structurally assess evidence processing. Evaluation across 450 test snippets on five model pipelines reveals that high activity levels can obscure verification chain breaks, while successful recovery hinges on the discovery and retention of critical evidence, demonstrating ATOBench’s effectiveness in exposing agent verification behavior under untrusted observations.

agent evaluationautonomous penetration testingdeceptive responses

Latest Papers

What's happening recently
View more

This work addresses the vulnerability of existing deception-based defenses, which rely on static decoys that advanced autonomous penetration agents can readily identify and bypass. To overcome this limitation, the authors propose a trajectory-adaptive deception system that dynamically generates context-aware decoy artifacts based on the agent’s behavioral trajectory. By integrating a validation mechanism with incremental fusion techniques, the system constructs a factually consistent and coherently evolving deceptive environment. Evaluated across 15 CVE-Bench applications and three attack models, the system effectively delays and misdirects attacks: it absorbs 46.8% of tool invocations, traps 55.9% of subsequent actions within the deceptive environment, and leads 90.0% of attack reports to rely on fabricated evidence. Critically, none of the 45 attack–vulnerability pairings succeeded in compromising the real target.

attack trajectoryautonomous penetration agentsdeception defense

Traditional penetration testing struggles to evaluate security risks in AI systems arising from violations of behavioral objectives without breaching underlying infrastructure. This work proposes the first formal definition of AI penetration testing, reframing it as an objective-driven behavioral security assessment. The approach involves identifying operational objectives, mapping AI-driven behaviors, analyzing adversarial attack surfaces—such as prompt injection, data poisoning, and sensor manipulation—establishing criteria for behavioral failure, and conducting scenario-based red-teaming exercises. By integrating threat modeling, behavior mapping, and evidentiary chain construction, the framework demonstrates its efficacy and novelty in a case study involving an AI-powered Security Operations Center assistant, successfully uncovering attack pathways that violate system objectives through behavioral manipulation alone, without requiring infrastructure compromise.

adversarial influenceAI-enabled systemsbehavioral objective violation

This study addresses the inability of traditional honeypots to counter the dynamic attack strategies employed by autonomous penetration testing agents. We propose the first closed-loop dynamic deception framework tailored for autonomous agents, integrating sentinel endpoint detection, application-layer stateful deception, and behavior-guided attack escalation techniques. This architecture enables continuous entrapment, controlled disclosure, and forensic evidence collection regarding agent behaviors. Experimental evaluations demonstrate that the proposed system reduces the attack success rate against genuine targets by 79.2% and successfully extracts attacker API keys in 18.8% of execution instances. These findings establish a novel paradigm for defending against AI agent-driven threats.

adaptive defenseautonomous penetration testing agentshoneypot

This study addresses the lack of effective methods for evaluating the security of skill packages employed by large language model (LLM) agents, as existing static analysis approaches struggle to comprehensively identify potential malicious behaviors. To bridge this gap, the work proposes a five-dimensional static analysis framework that holistically scores skill packages based on pattern density, statistical anomalies, data-flow taint propagation, import irregularities, and semantic mismatches between declared capabilities and actual implementation. The authors also introduce SkillMD-138K, the first adversarial evaluation dataset specifically designed for agent skills. Experimental results demonstrate strong overall detection performance with an AUC of 0.93 and an F1 score of 73.4%, achieving a 93% detection rate for data exfiltration and steganographic payloads. However, the study reveals fundamental blind spots in static analysis regarding host compromise and prompt injection attacks, offering critical insights for developing layered defense strategies.

adversarial evaluationAgent Skillsmalicious detection

Hot Scholars

AA

Alessandro Abate

Professor of Verification and Control, University of Oxford, UK
Formal VerificationControl TheoryStochastic Hybrid SystemsCyber-Physical Systems
QY

Qingqing Ye

Assistant Professor, The Hong Kong Polytechnic University
data privacy and securityadversarial machine learning
DA

Darsh Asher

Ph.D Student, NC State University
Microarchitectural SeculrityMachine Learning Security
RG

Roderich Groß

Resilient Cyber-Physical Systems, Technical University of Darmstadt
roboticsmulti-robot systemsswarm roboticsmodular robotics
ZL

Zi Liang

Hong Kong Polytechnic University
Natural Language ProcessingAI Security