• Home
  • Search
  • Evaluating Realistic Adversarial Attacks against Machine Learning Models for Windows PE Malware Detection
  • Cite Icon21
  • https://doi.org/10.3390/fi16050168Copy DOI Icon

Evaluating Realistic Adversarial Attacks against Machine Learning Models for Windows PE Malware Detection

Show More
  • Abstract
  • Highlights & Summary
  • PDF
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

During the last decade, the cybersecurity literature has conferred a high-level role to machine learning as a powerful security paradigm to recognise malicious software in modern anti-malware systems. However, a non-negligible limitation of machine learning methods used to train decision models is that adversarial attacks can easily fool them. Adversarial attacks are attack samples produced by carefully manipulating the samples at the test time to violate the model integrity by causing detection mistakes. In this paper, we analyse the performance of five realistic target-based adversarial attacks, namely Extend, Full DOS, Shift, FGSM padding + slack and GAMMA, against two machine learning models, namely MalConv and LGBM, learned to recognise Windows Portable Executable (PE) malware files. Specifically, MalConv is a Convolutional Neural Network (CNN) model learned from the raw bytes of Windows PE files. LGBM is a Gradient-Boosted Decision Tree model that is learned from features extracted through the static analysis of Windows PE files. Notably, the attack methods and machine learning models considered in this study are state-of-the-art methods broadly used in the machine learning literature for Windows PE malware detection tasks. In addition, we explore the effect of accounting for adversarial attacks on securing machine learning models through the adversarial training strategy. Therefore, the main contributions of this article are as follows: (1) We extend existing machine learning studies that commonly consider small datasets to explore the evasion ability of state-of-the-art Windows PE attack methods by increasing the size of the evaluation dataset. (2) To the best of our knowledge, we are the first to carry out an exploratory study to explain how the considered adversarial attack methods change Windows PE malware to fool an effective decision model. (3) We explore the performance of the adversarial training strategy as a means to secure effective decision models against adversarial Windows PE malware files generated with the considered attack methods. Hence, the study explains how GAMMA can actually be considered the most effective evasion method for the performed comparative analysis. On the other hand, the study shows that the adversarial training strategy can actually help in recognising adversarial PE malware generated with GAMMA by also explaining how it changes model decisions.

Loading PDF

Similar Papers
  • PDF
  • Research Article
  • Citations19

A hybrid CNN and ensemble model for COVID-19 lung infection detection on chest CT scans.

  • Mar 09, 2023
  • PLOS ONE
  • Ahmed A Akl +3
  • Research Article
  • Citations19

Towards robust autonomous driving systems through adversarial test set generation

  • Nov 17, 2022
  • ISA Transactions
  • Devrim Unal +4
  • Research Article

Benchmarking Classical and Deep Learning Models for Ransomware Detection Using Static PE Features

  • Aug 27, 2025
  • Journal of Advanced Research in Applied Sciences and Engineering Technology
  • Shuaib Ahmed Wadho +4
  • Dissertation

Application of reliability and resilience models to machine learning

  • Jan 01, 2023
  • Zakaria Faddi
  • Research Article
  • Citations13

Electroencephalogram-based machine learning models to predict neurologic outcome after cardiac arrest: A systematic review

  • Nov 14, 2023
  • Resuscitation
  • Chao-Chen Chen +6
  • Research Article
  • Citations30

Analyzing and Explaining Black-Box Models for Online Malware Detection

  • Jan 01, 2023
  • IEEE Access
  • Harikha Manthena +3
  • Research Article

Novel Convolution Neural Network for Enhanced Network Attack Pattern Recognition

  • Sep 19, 2025
  • University of Bisha Journal for Basic and Applied Sciences
  • Salahaldeen Duraibi
  • Research Article
  • Citations1

O-125 Application of artificial intelligence using big data to devise and train a machine learning model on over 63,000 human embryos to automate time-lapse embryo annotation

  • Jun 29, 2022
  • Human Reproduction
  • A Campbell +5
  • Abstract

Systematic Review of Machine Learning in Diagnosis of Myeloproliferative Neoplasia

  • Nov 05, 2024
  • Blood
  • Karna Desai +5
  • Research Article
  • Citations2

Unravelling emotions: exploring deep learning approaches for EEG-based emotionrecognition with current challenges and future recommendations.

  • Oct 23, 2025
  • Cognitive neurodynamics
  • Abgeena Abgeena +1
  • Research Article
  • Citations16

Robust Attacks Detection Model for Internet of Flying Things Based on Generative Adversarial Network (GAN) and Adversarial Training

  • Jul 01, 2025
  • IEEE Internet of Things Journal
  • Tarek Gaber +3
  • PDF
  • Research Article
  • Citations40

Machine Learning Models for Blood Glucose Level Prediction in Patients With Diabetes Mellitus: Systematic Review and Network Meta-Analysis.

  • Nov 20, 2023
  • JMIR Medical Informatics
  • Kui Liu +9
  • Research Article

Key Variables in the Reliability of ML Models Exposed to Neutrons, Protons, and Heavy Ions

  • Jan 01, 2025
  • IEEE Transactions on Nuclear Science
  • Bruno Loureiro Coelho +10
  • Research Article
  • Citations2

Capacity Abuse Attack of Deep Learning Models Without Need of Label Encodings

  • Feb 01, 2024
  • IEEE Transactions on Artificial Intelligence
  • Wenjian Luo +5
  • Research Article

Cataract Diseases Prediction Using Deep Learning

  • Jan 01, 2024
  • Frontiers in Health Informatics
  • Jayashri Bagade
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.