arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

打破黑箱:真实世界杀毒系统的字节级边界推断

Breaking the Black Box: Byte-Level Boundary Inference of Real-World Antivirus Systems

Jieshuai Yang, Zhi Wang, Yan Jia, Zhenhua Wu, Jianfei Tang, Chenbin Su, Jingwei Ye, Jianwen Tian, Wanpeng Li

arXiv 2609.31012首次发表:更新:

发表机构

Nankai University; Singapore Management University; University of Liverpool(南开大学; 新加坡管理大学; 利物浦大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出AVHunter,首个在黑箱条件下推断真实杀毒软件字节级决策边界的框架,通过构建大规模数据集并训练模型,实现85.07%的边界预测召回率,揭示杀毒知识泄漏新形式。

AI 中文摘要

现有理解真实世界杀毒软件检测逻辑的方法仅从黑箱查询中推断二元的恶意/良性判定,对决定杀毒检测的细粒度关键区域提供的洞察有限。本文提出AVHunter,这是第一个在黑箱威胁模型下推断真实世界杀毒产品字节级决策关键区域的框架。AVHunter通过系统探测11个真实世界杀毒产品,构建了首个大规模字节级杀毒边界数据集(BABD),揭示现代杀毒检测主要与少量紧凑的决策关键字节区域相关。利用BABD,AVHunter训练了针对特定杀毒的模型,这些模型不仅能复现二元的杀毒判定,还能定位这些判定背后的决策关键字节区域,平均边界预测召回率达到85.07%,同时与目标杀毒保持97.43%的检测一致性。我们进一步通过边界引导的恶意软件规避、对良性可执行文件的误报诱导,以及一项为期七个月的纵向研究验证了预测区域捕获了真实的杀毒决策知识,该研究表明随着杀毒产品的演进,推断区域大体保持稳定。总体而言,AVHunter超越了传统的二元标签杀毒建模,实现了细粒度的边界区域定位,并揭示了杀毒知识泄漏的一种新形式,对恶意软件分析、杀毒安全和边界感知防御具有重要意义。

英文摘要

Existing approaches for understanding the detection logic of real-world antivirus (AV) software infer only binary malware/benign decisions from black-box queries, providing limited insight into the fine-grained decision-critical regions that govern AV detection. In this paper, we present \textbf{AVHunter}, the first framework for inferring byte-level decision-critical regions of real-world AV products under a black-box threat model. AVHunter constructs the first large-scale Byte-Level AV Boundary Dataset (BABD) by systematically probing 11 real-world AV products, revealing that modern AV detections are largely associated with a small number of compact decision-critical byte regions. Leveraging BABD, AVHunter trains AV-specific models that not only reproduce binary AV decisions, but also localize the decision-critical byte regions underlying these decisions, achieving an average boundary prediction recall of 85.07% while maintaining 97.43% detection agreement with the target AVs. We further validate that the predicted regions capture genuine AV decision knowledge through boundary-guided malware evasion, false-positive induction on benign executables, and a seven-month longitudinal study demonstrating that the inferred regions remain largely stable as AV products evolve. Overall, AVHunter moves beyond conventional binary-label AV modeling by enabling fine-grained boundary-region localization and revealing a new form of AV knowledge leakage with important implications for malware analysis, AV security, and boundary-aware defenses.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑