Fetching the paper…
Reading the bibliography…
Recent work has shown that adversarial Windows malware samples - referred to as adversarial EXEmples in this paper - can bypass machine learning-based detection relying on static code analysis by perturbing relatively few input bytes.
D. Wierstra, T. Schaul, T. Glasmachers, Y. Sun, J. Peters, and J. Schmidhuber · 2008
Earlier work this paper cites.
Adversarial machine learning
L. Huang, A. D. Joseph, B. Nelson, B. Rubinstein, and J. D. Tygar · 2011
Earlier work this paper cites.
Evasion attacks against machine learning at test time
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, and F. Roli · 2013
Earlier work this paper cites.
Security evaluation of pattern classifiers under attack
B. Biggio, G. Fumera, and F. Roli · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
I. J. Goodfellow, J. Shlens, and C. Szegedy · 2014
Earlier work this paper cites.
Intriguing properties of neural networks
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. Goodfellow, and R. Fergus · 2014
Earlier work this paper cites.
Deepsign: Deep learning for automatic malware signature generation and classification
O. E. David and N. S. Netanyahu · 2015
Earlier work this paper cites.
Deep neural network based malware detection using two dimensional binary program features
J. Saxe and K. Berlin · 2015
Earlier work this paper cites.
Dl4md: A deep learning framework for intelligent malware detection
W. Hardy, L. Chen, S. Hou, Y. Ye, and X. Li · 2016
Earlier work this paper cites.
Deep learning for classification of malware system call sequences
B. Kolosnjaji, A. Zarras, G. Webster, and C. Eckert · 2016
Earlier work this paper cites.
Transferability in machine learning: from phenomena to black-box attacks using adversarial samples
N. Papernot, P. McDaniel, and I. Goodfellow · 2016
Earlier work this paper cites.
Evading machine learning malware detection
H. S. Anderson, A. Kharkar, B. Filar, and P. Roth · 2017
Earlier work this paper cites.
Towards evaluating the robustness of neural networks
N. Carlini and D. Wagner · 2017
Earlier work this paper cites.
Zoo: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models
P.-Y. Chen, H. Zhang, Y. Sharma, J. Yi, and C.-J. Hsieh · 2017
Cited alongside, same era.
Self-normalizing neural networks
G. Klambauer, T. Unterthiner, A. Mayr, and S. Hochreiter · 2017
Cited alongside, same era.
Practical black-box attacks against machine learning
N. Papernot, P. McDaniel, I. Goodfellow, S. Jha, Z. B. Celik, and A. Swami · 2017
Cited alongside, same era.
Ember: an open dataset for training static pe malware machine learning models
H. S. Anderson and P. Roth · 2018
Cited alongside, same era.
Black-box adversarial attacks with limited queries and information
A. Ilyas, L. Engstrom, A. Athalye, and J. Lin · 2018
Cited alongside, same era.
Adversarially robust malware detection using monotonic classification
Activation analysis of a byte-based deep neural network for malware classification
S. E. Coull and C. Gardner · 2019
Later among the works it cites.
Explaining vulnerabilities of deep learning to adversarial malware binaries
L. Demetrio, B. Biggio, G. Lagorio, F. Roli, and A. Armando · 2019
Later among the works it cites.
Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks
A. Demontis, M. Melis, M. Pintor, M. Jagielski, B. Biggio, A. Oprea, C. Nita-Rotaru, and F. Roli · 2019
Later among the works it cites.
secml: A python library for secure and explainable machine learning, 2019
M. Melis, A. Demontis, M. Pintor, A. Sotgiu, and B. Biggio · 2019
Later among the works it cites.
Optimization-guided binary diversification to mislead neural networks for malware detection
M. Sharif, K. Lucas, L. Bauer, M. K. Reiter, and S. Shintre · 2019
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
I. Incer, M. Theodorides, S. Afroz, and D. Wagner · 2018
Cited alongside, same era.
Adversarial malware binaries: Evading deep learning for malware detection in executables
B. Kolosnjaji, A. Demontis, B. Biggio, D. Maiorca, G. Giacinto, C. Eckert, and F. Roli · 2018
Cited alongside, same era.
Deep convolutional malware classifiers can learn from raw executables and labels only
M. Krčál, O. Švec, M. Bálek, and O. Jašek · 2018
Cited alongside, same era.
Deceiving end-to-end deep learning malware detectors using adversarial examples
F. Kreuk, A. Barak, S. Aviv-Reuven, M. Baruch, B. Pinkas, and J. Keshet · 2018
Cited alongside, same era.
Malware detection by eating a whole exe
E. Raff, J. Barker, J. Sylvester, R. Brandon, B. Catanzaro, and C. K. Nicholas · 2018
Cited alongside, same era.
When does machine learning FAIL? generalized transferability for evasion and poisoning attacks
O. Suciu, R. Marginean, Y. Kaya, H. D. III, and T. Dumitras · 2018
Cited alongside, same era.
Aimed: Evolving malware with genetic programming to evade detection
R. L. Castro, C. Schmitt, and G. Dreo · 2019
Cited alongside, same era.
Exploring adversarial examples in malware detection
O. Suciu, S. E. Coull, and J. Johns · 2019
Later among the works it cites.
From hack to elaborate technique—a survey on binary rewriting
M. Wenzl, G. Merzdovnik, J. Ullrich, and E. Weippl · 2019
Later among the works it cites.
When malware is packin’heat; limits of machine learning classifiers based on static analysis features
H. Aghakhani, F. Gritti, F. Mecca, M. Lindorfer, S. Ortolani, D. Balzarotti, G. Vigna, and C. Kruegel · 2020
Closest in time.
Functionality-preserving black-box optimization of adversarial windows malware, 2020
L. Demetrio, B. Biggio, G. Lagorio, F. Roli, and A. Armando · 2020
Closest in time.
Can domain knowledge alleviate adversarial attacks in multi-label classifiers?, 2020
S. Melacci, G. Ciravegna, A. Sotgiu, A. Demontis, B. Biggio, M. Gori, and F. Roli · 2020
Closest in time.
Intriguing properties of adversarial ml attacks in the problem space
F. Pierazzi, F. Pendlebury, J. Cortellazzi, and L. Cavallaro · 2020
Closest in time.
Automatic generation of adversarial examples for interpreting malware classifiers
W. Song, X. Li, S. Afroz, D. Garg, D. Kuznetsov, and H. Yin · 2020
Closest in time.