arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.27422cs.CR

RAMP:逆转对抗扰动以强化针对恶意软件检测器的干净标签后门攻击

RAMP: Reversing Adversarial Perturbations to Strengthen Clean-Label Backdoor Attacks against Malware Detectors

Jinwen Xin, Dongni Zhang, Chenyang Wang, Jianming Fu, Ming Tang, Guojun Peng

首次发表
浏览论文内容

中文总结 AI 辅助

RAMP通过遗传算法优化逆转对抗扰动,在干净标签设置下增强后门攻击,显著提升低投毒比例下的攻击效果并保持干净数据准确性。

中文摘要 AI 辅助

基于深度学习的恶意软件检测器通常通过对新收集的样本进行微调来更新,但这种实际的更新流程也为训练时后门攻击创造了攻击面。然而,在现实的众包数据收集中,严格的标签审查通常将攻击者限制在干净标签设置中,即中毒样本必须保留良性标签和功能,这使得有效的后门注入变得相当困难。我们提出了一种基于特征空间操纵的新攻击视角:不是仅仅依赖更强的触发器设计或选择天然与恶意软件相似的良性样本,而是故意构造良性程序,使其表示在触发器注入之前向恶意软件区域偏移,从而在训练期间产生更强的特征-标签冲突。基于这一见解,我们提出了RAMP,一种攻击增强方法,它使用遗传算法在黑盒访问下优化逆转的对抗扰动,然后通过保持功能的二进制操纵注入这些扰动。大量实验表明,RAMP在仅触发器的基线上显著提高了攻击有效性,尤其是在低投毒比例下效果更为显著,同时保持了对干净数据的准确性。此外,RAMP可以与先进的触发器设计相结合。

英文摘要

Deep learning-based malware detectors are commonly updated by fine-tuning on newly collected samples, but this practical update pipeline also creates an attack surface for training-time backdoor attacks. In realistic crowdsourced data collection, however, strict label vetting typically restricts attackers to the clean-label setting, in which poisoned samples must retain benign labels and functionality, making effective backdoor injection substantially harder. We present a new attack perspective based on feature-space manipulation: instead of relying solely on stronger trigger designs or selecting benign samples that are naturally similar to malware, we deliberately construct benign programs whose representations shift toward the malware region before trigger injection, thereby creating stronger feature-label conflicts during training. Based on this insight, we propose RAMP, an attack enhancement method that uses a genetic algorithm to optimize reversed adversarial perturbations under black-box access and then injects them through functionality-preserving binary manipulations. Extensive experiments show that RAMP substantially improves attack effectiveness over trigger-only baselines, with especially pronounced gains at low poisoning ratios, while maintaining accuracy on clean data. Moreover, RAMP can be combined with advanced trigger designs.

发表机构

  • School of Cyber Science and Engineering, Wuhan University(武汉大学网络安全学院)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑