{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T16:04:51Z","timestamp":1772121891989,"version":"3.50.1"},"reference-count":35,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,9,26]],"date-time":"2024-09-26T00:00:00Z","timestamp":1727308800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Science and Technology Council (NSTC), Taiwan","award":["113-2221-E-011-157-MY3"],"award-info":[{"award-number":["113-2221-E-011-157-MY3"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Embed. Comput. Syst."],"published-print":{"date-parts":[[2025,1,31]]},"abstract":"<jats:p>The rapid expansion of the Internet of Things (IoT) has significantly increased the prevalence of malware targeting IoT devices. Although machine learning models offer promising solutions for automatic malware detection, they are increasingly vulnerable to adversarial attacks. These attacks exploit the model\u2019s feedback loop to iteratively refine malware, producing adversarial samples that evade detection. As such, enhancing the robustness of these models is of paramount importance. Our research introduces a novel approach to bolster malware detection by retaining additional semantic information within the execution order analysis of malware programs. The method significantly improves the resilience of detection models against adversarial samples and implements two adversarial attack methods to rigorously test our model\u2019s robustness by generating authentic adversarial examples for validation. We highlight the critical impact of preserving semantic integrity in malware detection and present a solution to counteract the growing threat of adversarial attacks in IoT environments.<\/jats:p>","DOI":"10.1145\/3689427","type":"journal-article","created":{"date-parts":[[2024,8,26]],"date-time":"2024-08-26T10:01:51Z","timestamp":1724666511000},"page":"1-17","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Improving Robustness in IoT Malware Detection through Execution Order Analysis"],"prefix":"10.1145","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1783-463X","authenticated-orcid":false,"given":"Gao-Yu","family":"Lin","sequence":"first","affiliation":[{"name":"Department of Computer Science and Information Engineering, National Taiwan University of Science and Technology, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-3266-8913","authenticated-orcid":false,"given":"Po-Yuan","family":"Wang","sequence":"additional","affiliation":[{"name":"National Taiwan University of Science and Technology, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9796-0643","authenticated-orcid":false,"given":"Shin-Ming","family":"Cheng","sequence":"additional","affiliation":[{"name":"National Taiwan University of Science and Technology, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5808-9496","authenticated-orcid":false,"given":"Hahn-Ming","family":"Lee","sequence":"additional","affiliation":[{"name":"National Taiwan University of Science and Technology, Taipei, Taiwan"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,9,26]]},"reference":[{"key":"e_1_3_1_2_2","unstructured":"[n.d.]. Angr. Retrieved October 9 2023 from https:\/\/angr.io\/"},{"key":"e_1_3_1_3_2","unstructured":"[n.d.]. Execution Order Analysis Dataset. Retrieved Dec. 10th 2023 from https:\/\/gitlab.com\/Gao-Yu\/execution-order-analysis-dataset"},{"key":"e_1_3_1_4_2","unstructured":"[n.d.]. Malware AV-TEST. Retrieved January 5 2024 from https:\/\/www.av-test.org\/en\/statistics\/malware\/"},{"key":"e_1_3_1_5_2","unstructured":"[n.d.]. VirusTotal. Retrieved January 2 2024 from https:\/\/www.virustotal.com\/gui\/intelligence-overview"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.56471\/slujst.v4i.266"},{"key":"e_1_3_1_7_2","first-page":"1296","volume-title":"Proceedings of the 2019 IEEE 39th ICDCS","author":"Abusnaina Ahmed","year":"2019","unstructured":"Ahmed Abusnaina, Aminollah Khormali, Hisham Alasmary, Jeman Park, Afsah Anwar, and Aziz Mohaisen. 2019. Adversarial learning attacks on graph-based IoT malware detection systems. In Proceedings of the 2019 IEEE 39th ICDCS. 1296\u20131305."},{"key":"e_1_3_1_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2925929"},{"issue":"11","key":"e_1_3_1_9_2","article-title":"A survey on malware detection with graph representation learning","volume":"56","author":"Bilot Tristan","year":"2024","unstructured":"Tristan Bilot, Nour El Madhoun, Khaldoun Al Agha, and Anis Zouaoui. 2024. A survey on malware detection with graph representation learning. ACM Computing Surveys 56, 11 (2024).","journal-title":"ACM Computing Surveys"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.56471\/slujst.v4i.266"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598054"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3082330"},{"key":"e_1_3_1_13_2","unstructured":"Jacob Devlin. 2019. BERT: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the NAACL-HLT 2019. 4171--4186."},{"key":"e_1_3_1_14_2","unstructured":"Mohammadreza Ebrahimi Ning Zhang James Hu Muhammad Taqi Raza and Hsinchun Chen. 2020. Binary black-box evasion attacks against deep learning-based static malware detectors with adversarial byte-level language model. arXiv:2012.07994. Retrieved from https:\/\/arxiv.org\/abs\/2012.07994"},{"key":"e_1_3_1_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3652032.3657577"},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"e_1_3_1_17_2","first-page":"1","volume-title":"Proceedings of the 2021 9th ISDFS","author":"G\u00fclmez Sibel","year":"2021","unstructured":"Sibel G\u00fclmez and Ibrahim Sogukpinar. 2021. Graph-based malware detection using opcode sequences. In Proceedings of the 2021 9th ISDFS. 1\u20135."},{"key":"e_1_3_1_18_2","unstructured":"Ishita Gupta Sneha Kumari Priya Jha and Mohona Ghosh. 2024. Leveraging LSTM and GAN for modern malware detection. Retrieved from https:\/\/arxiv.org\/abs\/2405.04373"},{"key":"e_1_3_1_19_2","volume-title":"Proceedings of the IEEE\/IFIP International Conference on DSN","author":"Herath Jerome Dinal","year":"2022","unstructured":"Jerome Dinal Herath, Priti Prabhakar Wakodikar, Ping Yang, and Guanhua Yan. 2022. CFGExplainer: Explaining graph neural network-based malware classification from control flow graphs. In Proceedings of the IEEE\/IFIP International Conference on DSN."},{"key":"e_1_3_1_20_2","unstructured":"Junguang Jiang Yang Shu Jianmin Wang and Mingsheng Long. 2022. Transferability in deep learning: A survey. Retrieved from https:\/\/arxiv.org\/abs\/2201.05867"},{"key":"e_1_3_1_21_2","first-page":"1","volume-title":"Proceedings of the IFIP on NTMS","author":"Kalash Mahmoud","year":"2018","unstructured":"Mahmoud Kalash, Mrigank Rochan, Noman Mohammed, Neil D. B. Bruce, Yang Wang, and Farkhund Iqbal. 2018. Malware classification with deep convolutional neural networks. In Proceedings of the IFIP on NTMS. 1\u20135."},{"key":"e_1_3_1_22_2","first-page":"775","volume-title":"Proceedings of the IEEE TrustCom 2020","author":"Lee Y.-T.","year":"2020","unstructured":"Y.-T. Lee, T. Ban, T.-L. Wan, S.-M. Cheng, R. Isawa, T. Takahashi, and D. Inoue. 2020. Cross platform IoT-malware family classification based on printable strings. In Proceedings of the IEEE TrustCom 2020. 775\u2013784."},{"key":"e_1_3_1_23_2","volume-title":"Robustness Evaluation of Graph-based Malware Detection Using Code-level Adversarial Attack with Explainability","author":"Ouyang Liang-Bo","year":"2021","unstructured":"Liang-Bo Ouyang. 2021. Robustness Evaluation of Graph-based Malware Detection Using Code-level Adversarial Attack with Explainability. Master. NTUST, Taipei, Taiwan."},{"key":"e_1_3_1_24_2","first-page":"1332","volume-title":"Proceedings of the 2020 IEEE Symposium on SP","author":"Pierazzi Fabio","year":"2020","unstructured":"Fabio Pierazzi, Feargus Pendlebury, Jacopo Cortellazzi, and Lorenzo Cavallaro. 2020. Intriguing properties of adversarial ml attacks in the problem space. In Proceedings of the 2020 IEEE Symposium on SP. 1332\u20131349."},{"key":"e_1_3_1_25_2","volume-title":"Proceedings of the AAAI 2018","author":"Raff Edward","year":"2018","unstructured":"Edward Raff, Jon Barker, Jared Sylvester, Robert Brandon, Bryan Catanzaro, and Charles Nicholas. 2018. Malware detection by eating a whole EXE. In Proceedings of the AAAI 2018."},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.5555\/3455716.3455856"},{"key":"e_1_3_1_27_2","first-page":"234","volume-title":"Proceedings of the IEEE on ICWR 2020","author":"Rezaei Tina","year":"2020","unstructured":"Tina Rezaei and Ali Hamze. 2020. An efficient approach for malware detection using PE header specifications. In Proceedings of the IEEE on ICWR 2020. 234\u2013239."},{"key":"e_1_3_1_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3641861"},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.5555\/3295222.3295349"},{"key":"e_1_3_1_30_2","first-page":"156","volume-title":"Proceedings of the 10th ACM CODASPY","author":"Vij Devyani","year":"2020","unstructured":"Devyani Vij, Vivek Balachandran, Tony Thomas, and Roopak Surendran. 2020. GRAMAC: A graph based Android malware classification mechanism. In Proceedings of the 10th ACM CODASPY. 156\u2013158."},{"key":"e_1_3_1_31_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-021-06808-8"},{"key":"e_1_3_1_32_2","unstructured":"Keyulu Xu Weihua Hu Jure Leskovec and Stefanie Jegelka. 2018. How powerful are graph neural networks? In Proceedings of the International Conference on Learning Representations. Retrieved from https:\/\/openreview.net\/forum?id=ryGs6iA5Km"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2022.3225137"},{"key":"e_1_3_1_34_2","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-021-00079-5"},{"key":"e_1_3_1_35_2","volume-title":"An Imperceptible Adversarial Attack on Structure-Based Malware Detectors","author":"Yang Chi-Hsin","year":"2022","unstructured":"Chi-Hsin Yang. 2022. An Imperceptible Adversarial Attack on Structure-Based Malware Detectors. Master. NTUST, Taipei, Taiwan."},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1002\/int.22880"}],"container-title":["ACM Transactions on Embedded Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689427","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689427","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:05:45Z","timestamp":1750291545000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689427"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9,26]]},"references-count":35,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1,31]]}},"alternative-id":["10.1145\/3689427"],"URL":"https:\/\/doi.org\/10.1145\/3689427","relation":{},"ISSN":["1539-9087","1558-3465"],"issn-type":[{"value":"1539-9087","type":"print"},{"value":"1558-3465","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,9,26]]},"assertion":[{"value":"2024-01-07","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-07-29","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-09-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}