[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119797-en":3,"doc-seo-119797-105":29,"detail-sidebar-cat-0-en-105":89},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":20,"language":21,"language_code":22,"site_id":23,"html_lang":22,"table_of_contents":24,"faqs":25,"seo_title":26,"seo_description":14,"update_tm":27,"read_time":28},119797,34359740700684,"Finn","https://ap-avatar.wpscdn.com/avatar/1f400023980c374ae676?_k=1777273430885731487",8,"Research & Report","Enhancing Malware Analysis and Detection Using Adversarial Machine Learning Techniques","This presentation outlines a machine-learning driven malware detection framework aimed at improving robustness against zero-day threats and adversarial behavior. It addresses key limitations of existing systems by leveraging memory forensics to handle obfuscated malware and introducing a phase-based workflow. Phase 1 builds and trains a malware classifier from memory snapshots with feature extraction and SMOTE balancing. Phase 2 attacks the model using JSMA while generating a new dataset via VolMemLyzer feature export, and Phase 3 evaluates performance and adversarial example transferability using robustness techniques and metrics.","Enhancing Malware Analysis and Detection  \nUsing Adversarial Machine Learning  \nTechniques  \nTroy Tolman, Md. Mashrur Arifin, Dr. Jyh-haw Yeh  \nBoise State University  \n Introduction   \n• Machine learning-driven malware detection systems have demonstrated potential in identifying zero-day malware.  \n• Existing approaches lack robustness and needs more testing on different types of malware.  \n• AML attacks can help to determine effectiveness and robustness of a detection system.  \nChallenges:  \n• Obfuscated malware can be difficult to catch. Memory forensics is the solution. (VolMemLyzer)  \n• CIC-MalMem-2022 dataset only covers Spyware, Ransomware, and Trojan Horses.  \n• ML based malware detection systems have been tested on Windows, but further research is needed on Linux and MacOs to create unification between the systems.  \nApproach  \nPhase 1:  \nDevelop and train machine learning based Malware Detection Model:  \n• Take memory snapshot and extract features.  \n• Data balancing using SMOTE.  \n• Split data and input into detection system.  \n• Binary output (malicious or benign) .  \nFigure 1: Basic ML based Detection System Workflow  \nReferences  \nPhase 2:  \nAttack the detection model using JSMA  \n• Collect malware binaries to execute on a VM and take memory snapshot.  \n• VolMemLyzer to extract features to CSV file (new dataset) .  \n• Feed CSV files into the detection model.  \n• Record performance for analysis in phase 3.  \nFigure 2: AML Model Workflow  \nPhase 3: (Future Work)  \nAnalyze model performance and Adversarial Example Transferability  \n• Robustifying Techniques  \n- Defensive Distillation  \n- Adversarial Training  \n• AE Transferability  \n- Provides insight into ML models  \nTools  \nResults  \n• Algorithms Tested in Detection Model  \n- Decision Trees, Random Forest, LGBM, XGBoost  \n• Top Performers  \n- XGBoost, Random  \n• Metrics used:  \n- 10-fold cross validation  \n- accuracy  \n- F1 Score  \n- FPR  \n- sensitivity  \n- PPV  \n- Cohen kappa  \n- specificity  \n- MCC  \nForest Figure 3: XGBoost Confusion Matrix  \n\n| Authors | Algorithm | Accuracy (in %) |\n| --- | --- | --- |\n| [1] | RF, DT | 92.01, 99.00 |\n| [2] | LR | 99.97 |\n| [3] | KNN w/ Stacked Ensemble | 97.00 |\n| This study | XGBoost, RF | 99.98, 99.98 |\n\nTable 1: Performance comparison of related works.  \nConclusions  \n• ML based Detection systems are a viable solution to combat zero-day malware, but needs more research.  \n• The new dataset from Phase 2 will help researchers to robustify their models against many forms of malware.  \nFuture work:  \n• Defensive Distillation, Adversarial Training  \n• AE Transferability Problem  \n• Test model on MacOS and Linux  \n12.. AkDehnrr etetaall,, MMaallwawarereAnadetelyctsioisnaunsdinDgonoryUasningalyMsiaschindataei LnebairgingataAelgonvirrimsme. SntymmAppel trSyci 2, 01222(, 1174) ,(22300242)., p. 8604 NSF Cloud Computing and Privacy REU Award Number: 2244596 3. Carrier et al, Detecting obfuscated malware using memory feature engineering. ICISSP, SciTePress (2022), pp. 177-188","cbCaidNLTeANgATl","https://ap.wps.com/l/cbCaidNLTeANgATl","pdf",800395,1,"English","en",105,"# Introduction\n# Challenges\n# Approach\n## Phase 1: Build and train detection model\n## Phase 2: Attack the detection model and build new dataset\n## Phase 3: Future work on performance and transferability\n# Tools and Algorithms Tested\n# Results\n# Conclusions\n# Future work","[{\"question\":\"Why are adversarial machine learning techniques relevant to malware detection in this work?\",\"answer\":\"Adversarial machine learning attacks are used to evaluate how effective and robust a malware detection system is, especially against zero-day malware behavior.\"},{\"question\":\"How does the approach handle obfuscated malware that is hard to detect?\",\"answer\":\"The approach relies on memory forensics, using tools such as VolMemLyzer, to extract features from memory snapshots that better reveal obfuscated malware.\"},{\"question\":\"What is the role of Phase 2 in the overall workflow?\",\"answer\":\"Phase 2 executes malware binaries in a VM, takes memory snapshots, extracts features into a new dataset, and attacks the detection model using JSMA to measure performance for later analysis.\"}]","Enhancing Malware Analysis and Detection Using Adversarial Machine Learning Techniques | PDF",1785726350,3,{"code":4,"msg":30,"data":31},"ok",{"site_id":23,"language":22,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":84,"head_meta":86,"extra_data":88,"updated_unix":27},"enhancing-malware-analysis-and-detection-using-adversarial-machine-learning-techniques","",{"@graph":35,"@context":83},[36,52,66],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,49],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":28},"https://docshare.wps.com/document/research-report/",{"item":50,"name":13,"@type":42,"position":51},"https://docshare.wps.com/document/enhancing-malware-analysis-and-detection-using-adversarial-machine-learning-techniques/119797/",4,{"url":50,"name":13,"@type":53,"author":54,"headline":13,"publisher":56,"fileFormat":59,"inLanguage":22,"description":14,"dateModified":60,"datePublished":60,"encodingFormat":59,"isAccessibleForFree":61,"interactionStatistic":62},"DigitalDocument",{"name":9,"@type":55},"Person",{"url":40,"name":57,"@type":58},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":63,"interactionType":64,"userInteractionCount":4},"InteractionCounter",{"@type":65},"ViewAction",{"@type":67,"mainEntity":68},"FAQPage",[69,75,79],{"name":70,"@type":71,"acceptedAnswer":72},"Why are adversarial machine learning techniques relevant to malware detection in this work?","Question",{"text":73,"@type":74},"Adversarial machine learning attacks are used to evaluate how effective and robust a malware detection system is, especially against zero-day malware behavior.","Answer",{"name":76,"@type":71,"acceptedAnswer":77},"How does the approach handle obfuscated malware that is hard to detect?",{"text":78,"@type":74},"The approach relies on memory forensics, using tools such as VolMemLyzer, to extract features from memory snapshots that better reveal obfuscated malware.",{"name":80,"@type":71,"acceptedAnswer":81},"What is the role of Phase 2 in the overall workflow?",{"text":82,"@type":74},"Phase 2 executes malware binaries in a VM, takes memory snapshots, extracts features into a new dataset, and attacks the detection model using JSMA to measure performance for later analysis.","https://schema.org",{"og:url":50,"og:type":85,"og:title":13,"og:site_name":57,"og:description":14},"article",{"robots":87,"canonical":50},"index,follow",{"doc_id":7,"site_id":23},{"code":4,"msg":5,"data":90},[91,95,99,103,108,113,118,121,126,129,133],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":92,"show_sort_weight":93,"slug":94},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":96,"show_sort_weight":97,"slug":98},"Literature",80,"literature",{"id":51,"doc_module":4,"doc_module_name":45,"category_name":100,"show_sort_weight":101,"slug":102},"Exam",70,"exam",{"id":104,"doc_module":4,"doc_module_name":45,"category_name":105,"show_sort_weight":106,"slug":107},5,"Comic",60,"comic",{"id":109,"doc_module":4,"doc_module_name":45,"category_name":110,"show_sort_weight":111,"slug":112},6,"Technology",50,"technology",{"id":114,"doc_module":4,"doc_module_name":45,"category_name":115,"show_sort_weight":116,"slug":117},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":119,"slug":120},30,"research-report",{"id":122,"doc_module":4,"doc_module_name":45,"category_name":123,"show_sort_weight":124,"slug":125},9,"Religion & Spirituality",20,"religion-spirituality",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":127,"show_sort_weight":124,"slug":128},"World Cup","world-cup",{"id":130,"doc_module":4,"doc_module_name":45,"category_name":131,"show_sort_weight":130,"slug":132},10,"Lifestyle","lifestyle",{"id":134,"doc_module":4,"doc_module_name":45,"category_name":135,"show_sort_weight":104,"slug":136},19,"General","general"]