On the Security Risks of ML-based Malware Detection Systems: A Survey
By: Ping He , Yuhao Mao , Changjiang Li and more
Potential Business Impact:
Protects computers from sneaky virus attacks.
Malware presents a persistent threat to user privacy and data integrity. To combat this, machine learning-based (ML-based) malware detection (MD) systems have been developed. However, these systems have increasingly been attacked in recent years, undermining their effectiveness in practice. While the security risks associated with ML-based MD systems have garnered considerable attention, the majority of prior works is limited to adversarial malware examples, lacking a comprehensive analysis of practical security risks. This paper addresses this gap by utilizing the CIA principles to define the scope of security risks. We then deconstruct ML-based MD systems into distinct operational stages, thus developing a stage-based taxonomy. Utilizing this taxonomy, we summarize the technical progress and discuss the gaps in the attack and defense proposals related to the ML-based MD systems within each stage. Subsequently, we conduct two case studies, using both inter-stage and intra-stage analyses according to the stage-based taxonomy to provide new empirical insights. Based on these analyses and insights, we suggest potential future directions from both inter-stage and intra-stage perspectives.
Similar Papers
Security through the Eyes of AI: How Visualization is Shaping Malware Detection
Cryptography and Security
Shows bad computer programs using pictures.
Systems-Theoretic and Data-Driven Security Analysis in ML-enabled Medical Devices
Cryptography and Security
Makes smart medical tools safer from hackers.
Optimized Approaches to Malware Detection: A Study of Machine Learning and Deep Learning Techniques
Cryptography and Security
Finds computer viruses faster and more accurately.