arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Windows 恶意软件检测器作为复合人工智能系统:准确性、效率与对抗鲁棒性之间的权衡

Windows Malware Detector as a Compound AI System: Trade-Offs in Accuracy, Efficiency, and Adversarial Robustness

Andrea Ponte, Luca Demetrio, Luca Oneto, Battista Biggio, Fabio Roli

arXiv 2609.08394首次发表:更新:

发表机构

University of Genova; University of Cagliari(热那亚大学; 卡利亚里大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出一种平衡检测性能、计算效率与对抗鲁棒性的复合人工智能系统评估方法,引入系统级威胁模型,实验表明可缩短训练时间并提升响应能力,同时为从业者提供部署指南。

AI 中文摘要

工业级 Windows 恶意软件检测器通常被描述为由多个异构组件组成的复合人工智能系统,这些组件包括基于规则的机制以及基于机器学习的静态和动态分析。然而,由于工业保密和有限的公开披露,这些系统的内部架构只能被推断,使得对检测准确性、计算成本和对抗鲁棒性的系统评估在很大程度上不可行。相比之下,学术研究提供了可重复和透明的评估方法,但通常孤立地研究单个检测组件。为了弥合学术研究与工业实践之间的差距,并受最先进的工业级 Windows 恶意软件检测架构的启发,我们提出了一种新颖的方法,该方法(i)明确平衡了检测性能、计算需求和鲁棒性之间的权衡,并引入了(ii)系统级威胁模型,该模型捕捉攻击者如何利用不同程度的知识来规避整个复合人工智能系统,而不是孤立的检测器。在真实世界数据上进行的实验表明,复合人工智能系统的训练时间可以缩短,响应能力可以得到提高,同时仅产生轻微的检测性能损失。利用我们的威胁建模,我们展示了知识越来越丰富的攻击者能够制造更有效的对抗样本,揭示系统的优势和弱点,降低其响应能力,并暴露出效率与鲁棒性之间的直接权衡。最后,我们将这些权衡转化为实用建议和部署指南,帮助从业者选择最符合其运营约束的系统。

英文摘要

Industrial Windows malware detectors are commonly described as Compound AI Systems composed of multiple heterogeneous components, including rule-based mechanisms as well as machine-learning-based static and dynamic analyses. However, due to industrial secrecy and limited public disclosure, the internal architectures of these systems can only be inferred, rendering systematic evaluations of detection accuracy, computational costs, and adversarial robustness largely infeasible. In contrast, academic research provides reproducible and transparent evaluation methodologies, but typically investigates individual detection components in isolation. To bridge the gap between academic research and industrial practice, and inspired by state-of-the-art industrial architectures for Windows malware detection, we propose a novel methodology that (i) explicitly balances the trade-off among detection performance, computational requirements, and robustness, and introduces (ii) system-level threat models that capture how attackers exploit different degrees of knowledge to evade the entire Compound AI System rather than isolated detectors. Experiments conducted on real-world data demonstrate that the Compound AI System training time can be reduced and responsiveness improved while incurring only a marginal loss in detection performance. Leveraging our threat modeling, we show that increasingly knowledgeable attackers craft more effective adversarial examples, revealing the system's strengths and weaknesses, degrading its responsiveness, and exposing a direct trade-off between efficiency and robustness. Finally, we translate these trade-offs into take-home messages and deployment guidelines, helping practitioners to select the system that best matches their operational constraints.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑