AI 中文总结
PhantomCall是一种黑盒攻击,通过注入虚拟函数扰动Windows PE恶意软件的函数调用图,在保留程序语义的同时规避三类恶意软件检测器,攻击成功率高且速度快,多数变体保留原恶意行为。
AI 中文摘要
此前针对Windows PE恶意软件检测器的对抗攻击主要针对原始字节、PE头或函数内控制流图,未将函数调用图(FCG)作为攻击面,但FCG结构是基于图的恶意软件检测器的重要特征。本文提出PhantomCall,一种黑盒攻击方法,通过在目标调用点注入完全可执行的虚拟函数来扰动Windows PE恶意软件的FCG,在保留程序语义的同时向控制流图(CFG)和FCG添加新节点与边。该方法将结构扰动与分类器引导搜索及可调注入参数相结合,可在三种架构不同的分类器上生效。在2025年收集的Windows恶意软件语料库上,针对MalConv(原始字节CNN)、MalGraph(基于图的GNN)和SAFE+GNN(纯FCG的GNN,在2024年语料库上从头训练),在两个FPR阈值下进行评估,最佳PhantomCall变体在所有配置下达到85%-100%的攻击成功率,在MalGraph上比现有最先进方法高出最多14.78个百分点,在SAFE+GNN上高出95.5个百分点,且在所有目标上平均生成规避变体的速度快2.9倍。对于MalConv和MalGraph,大多数规避仅需单个调用点修改,在基于沙箱的语义测试中,86%-97%的评估规避变体保留了原始恶意行为。
英文摘要
Prior adversarial attacks on Windows PE malware detectors target raw bytes, PE headers, or intra-function control-flow graphs, leaving the function call graph (FCG) unexplored as an attack surface. Yet the FCG structure is an important feature in graph-based malware detectors. We present Phan- tomCall, a black-box attack that perturbs the FCG of Windows PE malware by injecting fully executable dummy functions at targeted call sites, adding new nodes and edges to both the CFG and FCG while preserving program semantics. We pair this structural perturbation with classifier-guided search and tunable injection parameters, effective across three archi- tecturally distinct classifiers. Evaluated on a 2025-collected Windows malware corpus against MalConv (raw-byte CNN), MalGraph (graph-based GNN), and SAFE+GNN (pure FCG GNN trained from scratch on a 2024 corpus) at two FPR thresholds, the best PhantomCall variant achieves 85-100% attack success rate across all configurations, exceeding prior state-of-the-art by up to 14.78 percentage points on MalGraph and 95.5 percentage points on SAFE+GNN, and generating evasive variants up to 2.9x faster on average across all targets. For MalConv and MalGraph, the majority of evasions require only a single call site modification, and 86-97% of evaluated evasive variants preserve the original malicious behavior in sandbox-based semantic testing across all configurations.