Font Size: a A A

Research On Black-box Attack For ML-based Android Malware Detection

Posted on:2023-04-03Degree:MasterType:Thesis
Country:ChinaCandidate:J ZhangFull Text:PDF
GTID:2568306614989129Subject:Cyberspace security
Abstract/Summary:
Android is currently the most popular mobile operating system.After years of development,there are a large number of Android applications.At the same time,the number of Android malware is also increasing rapidly.To effectively detect malware,machine learning has been widely used in Android malware detection.The research results of this paper mainly focus on the following two aspects of machine learning-based Android malware detection system:·API call and permission are the most widely used detection features in Android malware detection.We compare and evaluate the performance of these two detection features in malware detection and also provide ideas for the construction of substitute models for the following work.·Android malware detection based on machine learning also faces sample attacks.At present,there are many gray-box and white-box attacks.However,the more practical threat model-black box adversary attack has not been well verified and evaluated.This paper fills this research gap and proposes a black-box anti-attack method,ShadowDroid,to attack the Android malware detection platform based on machine learning.Shadowdroid attempts to build a substitute model of the target malware detection system.The construction method of the substitute model will refer to our previous work.Using this substitute model,we can identify and modify the critical features of malware to generate adversarial samples.Using this method.we conducted attack experiments.We tried to attack nine Android malware detection platforms based on machine learning and successfully attacked five platforms.
Keywords/Search Tags:Android malware detection, Adversarial example attack, substitute model
Related items