{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T23:48:42Z","timestamp":1768348122612,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":28,"publisher":"ACM","license":[{"start":{"date-parts":[[2017,8,13]],"date-time":"2017-08-13T00:00:00Z","timestamp":1502582400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2017,8,13]]},"DOI":"10.1145\/3097983.3098158","type":"proceedings-article","created":{"date-parts":[[2017,8,4]],"date-time":"2017-08-04T18:35:54Z","timestamp":1501871754000},"page":"1145-1153","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":111,"title":["Adversary Resistant Deep Neural Networks with an Application to Malware Detection"],"prefix":"10.1145","author":[{"given":"Qinglong","family":"Wang","sequence":"first","affiliation":[{"name":"Pennsylvania State University &amp; McGill University, State College, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenbo","family":"Guo","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, State College, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaixuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, State College, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"suffix":"II","given":"Alexander G.","family":"Ororbia","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, State College, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinyu","family":"Xing","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, State College, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xue","family":"Liu","sequence":"additional","affiliation":[{"name":"McGill University, Montreal, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"C. Lee","family":"Giles","sequence":"additional","affiliation":[{"name":"Pennsylvania State University, State College, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2017,8,13]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"DeepDGA: Adversarially-Tuned Domain Generation and Detection. arXiv:1610.01969 [cs.CR]","author":"Anderson Hyrum","year":"2016","unstructured":"Hyrum Anderson , Jonathan Woodbridge , and Bobby Filar . 2016. DeepDGA: Adversarially-Tuned Domain Generation and Detection. arXiv:1610.01969 [cs.CR] ( 2016 ). Hyrum Anderson, Jonathan Woodbridge, and Bobby Filar. 2016. DeepDGA: Adversarially-Tuned Domain Generation and Detection. arXiv:1610.01969 [cs.CR] (2016)."},{"key":"e_1_3_2_1_2_1","unstructured":"Matt Wolff Andrew Davis. 2015. Deep Learning on Dis- assembly. https:\/\/www.blackhat.com\/docs\/us-15\/materials\/ us-15-Davis-Deep-Learning-On-Disassembly.pdf.  Matt Wolff Andrew Davis. 2015. Deep Learning on Dis- assembly. https:\/\/www.blackhat.com\/docs\/us-15\/materials\/ us-15-Davis-Deep-Learning-On-Disassembly.pdf."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5188-5"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2808769.2808773"},{"key":"e_1_3_2_1_5_1","unstructured":"Ran Bi. 2015. Deep Learning can be easily fooled. http:\/\/www.kdnuggets.com\/ 2015\/01\/deep-learning-can-be-easily-fooled.html.  Ran Bi. 2015. Deep Learning can be easily fooled. http:\/\/www.kdnuggets.com\/ 2015\/01\/deep-learning-can-be-easily-fooled.html."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"e_1_3_2_1_7_1","unstructured":"BIZETY 2016. Deep Learning Neural Nets Are Effective Against AI Malware. BIZETY. https:\/\/www.bizety.com\/2016\/02\/05\/ deep-learning-neural-nets-are-effective-against-ai-malware\/.  BIZETY 2016. Deep Learning Neural Nets Are Effective Against AI Malware. BIZETY. https:\/\/www.bizety.com\/2016\/02\/05\/ deep-learning-neural-nets-are-effective-against-ai-malware\/."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6638293"},{"key":"e_1_3_2_1_9_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J.","year":"2014","unstructured":"Ian J. Goodfellow , Jonathon Shlens , and Christian Szegedy . 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 ( 2014 ). Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_10_1","volume-title":"Adversarial Perturbations Against Deep Neural Networks for Malware Classification. arXiv preprint arXiv:1606.04435","author":"Grosse Kathrin","year":"2016","unstructured":"Kathrin Grosse , Nicolas Papernot , Praveen Manoharan , Michael Backes , and Patrick McDaniel . 2016. Adversarial Perturbations Against Deep Neural Networks for Malware Classification. arXiv preprint arXiv:1606.04435 ( 2016 ). Kathrin Grosse, Nicolas Papernot, Praveen Manoharan, Michael Backes, and Patrick McDaniel. 2016. Adversarial Perturbations Against Deep Neural Networks for Malware Classification. arXiv preprint arXiv:1606.04435 (2016)."},{"key":"e_1_3_2_1_11_1","volume-title":"Towards deep neural network architectures robust to adversarial examples. arXiv:1412.5068 [cs]","author":"Gu Shixiang","year":"2014","unstructured":"Shixiang Gu and Luca Rigazio . 2014. Towards deep neural network architectures robust to adversarial examples. arXiv:1412.5068 [cs] ( 2014 ). Shixiang Gu and Luca Rigazio. 2014. Towards deep neural network architectures robust to adversarial examples. arXiv:1412.5068 [cs] (2014)."},{"key":"e_1_3_2_1_12_1","unstructured":"Mike James. 2014. The Flaw Lurking In Every Deep Neural Net . http:\/\/www.i-programmer.info\/news\/105-artificial-intelligence\/ 7352-the-flaw-lurking-in-every-deep-neural-net.html.  Mike James. 2014. The Flaw Lurking In Every Deep Neural Net . http:\/\/www.i-programmer.info\/news\/105-artificial-intelligence\/ 7352-the-flaw-lurking-in-every-deep-neural-net.html."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"D.K. Kang J. Zhang A. Silvescu and V. Honavar. 2005. Multinomial event model based abstraction for sequence and text classification. Abstraction Reformulation and Approximation (2005) 901--901.  D.K. Kang J. Zhang A. Silvescu and V. Honavar. 2005. Multinomial event model based abstraction for sequence and text classification. Abstraction Reformulation and Approximation (2005) 901--901.","DOI":"10.1007\/11527862_10"},{"key":"e_1_3_2_1_14_1","unstructured":"Will Knight. 2015. Antivirus that Mimics the Brain Could Catch More Malware. https:\/\/www.technologyreview.com\/s\/542971\/ antivirus-that-mimics-the-brain-could-catch-more-malware\/.  Will Knight. 2015. Antivirus that Mimics the Brain Could Catch More Malware. https:\/\/www.technologyreview.com\/s\/542971\/ antivirus-that-mimics-the-brain-could-catch-more-malware\/."},{"key":"e_1_3_2_1_15_1","unstructured":"Alex Krizhevsky and Geoffrey Hinton. 2009. Learning multiple layers of features from tiny images. (2009).  Alex Krizhevsky and Geoffrey Hinton. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_16_1","unstructured":"Yann LeCun Corinna Cortes and Christopher JC Burges. 1998. The MNIST database of handwritten digits. (1998).  Yann LeCun Corinna Cortes and Christopher JC Burges. 1998. The MNIST database of handwritten digits. (1998)."},{"key":"e_1_3_2_1_17_1","unstructured":"Cade Metz. 2015. Baidu the Chinese Google Is Teaching AI to Spot Malware. https:\/\/www.wired.com\/2015\/11\/ baidu-the-chinese-google-is-teaching-ai-to-spot-malware\/.  Cade Metz. 2015. Baidu the Chinese Google Is Teaching AI to Spot Malware. https:\/\/www.wired.com\/2015\/11\/ baidu-the-chinese-google-is-teaching-ai-to-spot-malware\/."},{"key":"e_1_3_2_1_18_1","unstructured":"MIT Technology Review 2016. Machine-Learning Algorithm Combs the Darknet for Zero Day Exploits and Finds them. MIT Technology Review.  MIT Technology Review 2016. Machine-Learning Algorithm Combs the Darknet for Zero Day Exploits and Finds them. MIT Technology Review."},{"key":"e_1_3_2_1_19_1","unstructured":"Linda Musthaler. 2016. How to use deep learning AI to detect and prevent malware and APTs in real-time.  Linda Musthaler. 2016. How to use deep learning AI to detect and prevent malware and APTs in real-time."},{"key":"e_1_3_2_1_20_1","volume-title":"Unifying Adversarial Training Algorithms with Flexible Deep Data Gradient Regularization. arXiv:1601.07213 [cs]","author":"Alexander G.","year":"2016","unstructured":"Alexander G. Ororbia II, C. Lee Giles , and Daniel Kifer . 2016. Unifying Adversarial Training Algorithms with Flexible Deep Data Gradient Regularization. arXiv:1601.07213 [cs] ( 2016 ). Alexander G. Ororbia II, C. Lee Giles, and Daniel Kifer. 2016. Unifying Adversarial Training Algorithms with Flexible Deep Data Gradient Regularization. arXiv:1601.07213 [cs] (2016)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_1_22_1","volume-title":"Distillation as a defense to adversarial perturbations against deep neural networks. arXiv preprint arXiv:1511.04508","author":"Papernot Nicolas","year":"2015","unstructured":"Nicolas Papernot , Patrick McDaniel , Xi Wu , Somesh Jha , and Ananthram Swami . 2015. Distillation as a defense to adversarial perturbations against deep neural networks. arXiv preprint arXiv:1511.04508 ( 2015 ). Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami. 2015. Distillation as a defense to adversarial perturbations against deep neural networks. arXiv preprint arXiv:1511.04508 (2015)."},{"key":"e_1_3_2_1_23_1","volume-title":"Deep Neural Network Based Malware Detection Using Two Dimensional Binary Program Features. CoRR","author":"Saxe Joshua","year":"2015","unstructured":"Joshua Saxe and Konstantin Berlin . 2015. Deep Neural Network Based Malware Detection Using Two Dimensional Binary Program Features. CoRR ( 2015 ). Joshua Saxe and Konstantin Berlin. 2015. Deep Neural Network Based Malware Detection Using Two Dimensional Binary Program Features. CoRR (2015)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/2627435.2670313"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.20"},{"key":"e_1_3_2_1_26_1","unstructured":"Symantec 2016. Internet Security Threat Report. Symantec. https:\/\/www.symantec. com\/content\/dam\/symantec\/docs\/reports\/istr-21--2016-en.pdf.  Symantec 2016. Internet Security Threat Report. Symantec. https:\/\/www.symantec. com\/content\/dam\/symantec\/docs\/reports\/istr-21--2016-en.pdf."},{"key":"e_1_3_2_1_27_1","volume-title":"International Conference on Learning Representations.","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy , Wojciech Zaremba , Ilya Sutskever , Joan Bruna , Dumitru Erhan , Ian Goodfellow , and Rob Fergus . 2014 . Intriguing properties of neural networks . In International Conference on Learning Representations. Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2619239.2631434"}],"event":{"name":"KDD '17: The 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","location":"Halifax NS Canada","acronym":"KDD '17","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3097983.3098158","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3097983.3098158","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T03:30:02Z","timestamp":1750217402000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3097983.3098158"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,8,13]]},"references-count":28,"alternative-id":["10.1145\/3097983.3098158","10.1145\/3097983"],"URL":"https:\/\/doi.org\/10.1145\/3097983.3098158","relation":{},"subject":[],"published":{"date-parts":[[2017,8,13]]},"assertion":[{"value":"2017-08-13","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}