摘要
Adversarial malware generation techniques play a crucial role in evaluating the performance and robustness of antivirus products, which is essential for developing more resilient security mechanisms to counter the increasing threat of adversarial attacks. While most existing studies have focused on non-targeted attacks aimed at evading malware detection, targeted attacks in the context of malware family classification remain a significant challenge due to the complexity of multi-class classification tasks. In this paper, we propose ComBat, a contextual combinatorial multi-armed bandit framework for targeted malware deception. ComBat models functionality-preserving action-content pairs as base arms, and encodes both malware features and adversarial intentions as contextual information to guide action selection. By jointly selecting multiple actions as a super arm in each round, ComBat enables efficient and adaptive targeted deception while alleviating the combinatorial inefficiency of sequential RL-based attacks. Both theoretical analysis and experimental results show that ComBat achieves sublinear regret over time and delivers robust performance in malware deception tasks. Additionally, ComBat demonstrates the ability to deceive commercial antivirus engines from VirusTotal into targeted misclassification to some extent.
| 源语言 | 英语 |
|---|---|
| 期刊 | IEEE Transactions on Reliability |
| DOI | |
| 出版状态 | 已接受/待刊 - 2026 |
| 已对外发布 | 是 |
学术指纹
探究 'ComBat: A Contextual Combinatorial Bandit Approach for Targeted Deception Attacks on Malware Classification System' 的科研主题。它们共同构成独一无二的学术指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver