Skip to main navigation Skip to search Skip to main content

ComBat: A Contextual Combinatorial Bandit Approach for Targeted Deception Attacks on Malware Classification System

  • Jianjin Zhao
  • , Qi Li*
  • , Zhiwei Cui
  • , Bowen Sun
  • , Jianyang Ding
  • , Hongliang Zhu
  • , Meng Shen
  • *Corresponding author for this work
  • Jiangsu Police Institute
  • Beijing University of Posts and Telecommunications
  • Jiangnan University
  • Beijing Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

Adversarial malware generation techniques play a crucial role in evaluating the performance and robustness of antivirus products, which is essential for developing more resilient security mechanisms to counter the increasing threat of adversarial attacks. While most existing studies have focused on non-targeted attacks aimed at evading malware detection, targeted attacks in the context of malware family classification remain a significant challenge due to the complexity of multi-class classification tasks. In this paper, we propose ComBat, a contextual combinatorial multi-armed bandit framework for targeted malware deception. ComBat models functionality-preserving action-content pairs as base arms, and encodes both malware features and adversarial intentions as contextual information to guide action selection. By jointly selecting multiple actions as a super arm in each round, ComBat enables efficient and adaptive targeted deception while alleviating the combinatorial inefficiency of sequential RL-based attacks. Both theoretical analysis and experimental results show that ComBat achieves sublinear regret over time and delivers robust performance in malware deception tasks. Additionally, ComBat demonstrates the ability to deceive commercial antivirus engines from VirusTotal into targeted misclassification to some extent.

Original languageEnglish
JournalIEEE Transactions on Reliability
DOIs
Publication statusAccepted/In press - 2026
Externally publishedYes

Keywords

  • Adversarial Sample
  • Deception Attack
  • Malware Classification

Fingerprint

Dive into the research topics of 'ComBat: A Contextual Combinatorial Bandit Approach for Targeted Deception Attacks on Malware Classification System'. Together they form a unique fingerprint.

Cite this