{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T15:54:33Z","timestamp":1782834873024,"version":"3.54.5"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,5,14]],"date-time":"2021-05-14T00:00:00Z","timestamp":1620950400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,5,14]],"date-time":"2021-05-14T00:00:00Z","timestamp":1620950400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Strategic Priority Research Program of CAS","award":["No.XDC02010300."],"award-info":[{"award-number":["No.XDC02010300."]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2021,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Outside the explosive successful applications of deep learning (DL) in natural language processing, computer vision, and information retrieval, there have been numerous Deep Neural Networks (DNNs) based alternatives for common security-related scenarios with malware detection among more popular. Recently, adversarial learning has gained much focus. However, unlike computer vision applications, malware adversarial attack is expected to guarantee malwares\u2019 original maliciousness semantics. This paper proposes a novel adversarial instruction learning technique, DeepMal, based on an adversarial instruction learning approach for static malware detection. So far as we know, DeepMal is the first practical and systematical adversarial learning method, which could directly produce adversarial samples and effectively bypass static malware detectors powered by DL and machine learning (ML) models while preserving attack functionality in the real world. Moreover, our method conducts small-scale attacks, which could evade typical malware variants analysis (e.g., duplication check). We evaluate DeepMal on two real-world datasets, six typical DL models, and three typical ML models. Experimental results demonstrate that, on both datasets, DeepMal can attack typical malware detectors with the mean <jats:italic>F1-score<\/jats:italic> and <jats:italic>F1-score<\/jats:italic> decreasing maximal 93.94% and 82.86% respectively. Besides, three typical types of malware samples (Trojan horses, Backdoors, Ransomware) prove to preserve original attack functionality, and the mean duplication check ratio of malware adversarial samples is below 2.0%. Besides, DeepMal can evade dynamic detectors and be easily enhanced by learning more dynamic features with specific constraints.<\/jats:p>","DOI":"10.1186\/s42400-021-00079-5","type":"journal-article","created":{"date-parts":[[2021,5,13]],"date-time":"2021-05-13T23:07:29Z","timestamp":1620947249000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":26,"title":["DeepMal: maliciousness-Preserving adversarial instruction learning against static malware detection"],"prefix":"10.1186","volume":"4","author":[{"given":"Chun","family":"Yang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jinghui","family":"Xu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shuangshuang","family":"Liang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanna","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Wen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Boyang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dan","family":"Meng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,5,14]]},"reference":[{"key":"79_CR1","doi-asserted-by":"publisher","unstructured":"Anderson, B, McGrew D (2017) Machine learning for encrypted malware traffic classification: Accounting for noisy labels and non-stationarity In: Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. KDD \u201917, 1723\u20131732.. ACM, New York. https:\/\/doi.org\/10.1145\/3097983.3098163. http:\/\/doi.acm.org\/10.1145\/3097983.3098163.","DOI":"10.1145\/3097983.3098163"},{"key":"79_CR2","doi-asserted-by":"crossref","unstructured":"Anderson, HS, Woodbridge J, Filar B (2016) Deepdga: Adversarially-tuned domain generation and detection In: Proceedings of the 2016 ACM Workshop on Artificial Intelligence and Security, 13\u201321.. ACM. https:\/\/arxiv.org\/abs\/1610.01969.","DOI":"10.1145\/2996758.2996767"},{"key":"79_CR3","doi-asserted-by":"publisher","unstructured":"Banescu, S, Collberg C, Ganesh V, Newsham Z, Pretschner A (2016) Code obfuscation against symbolic execution attacks In: Proceedings of the 32Nd Annual Conference on Computer Security Applications. ACSAC \u201916, 189\u2013200.. ACM, New York. https:\/\/doi.org\/10.1145\/2991079.2991114. http:\/\/doi.acm.org\/10.1145\/2991079.2991114.","DOI":"10.1145\/2991079.2991114"},{"key":"79_CR4","doi-asserted-by":"crossref","unstructured":"Banescu, S, Collberg C, Pretschner A (2017) Predicting the resilience of obfuscated code against symbolic execution attacks via machine learning In: Proceedings of the 26th USENIX Security Symposium. https:\/\/dl.acm.org\/doi\/abs\/10.5555\/3241189.3241241.","DOI":"10.1145\/2991079.2991114"},{"key":"79_CR5","unstructured":"Brown, TB, Man\u00e9 D, Roy A, Abadi M, Gilmer J (2017) Adversarial patch. arXiv preprint arXiv:1712.09665."},{"key":"79_CR6","doi-asserted-by":"crossref","unstructured":"Burnaev, E, Smolyakov D (2016) One-class svm with privileged information and its application to malware detection. arXiv preprint arXiv:1609.08039.","DOI":"10.1109\/ICDMW.2016.0046"},{"key":"79_CR7","doi-asserted-by":"publisher","unstructured":"Cabau, G, Buhu M, Oprisa CP (2017) Malware classification based on dynamic behavior In: International Symposium on Symbolic & Numeric Algorithms for Scientific Computing.. IEEE. https:\/\/doi.org\/10.1109\/SYNASC.2016.057, https:\/\/ieeexplore.ieee.org\/document\/7829629.","DOI":"10.1109\/SYNASC.2016.057"},{"key":"79_CR8","doi-asserted-by":"crossref","unstructured":"Dahl, GE, Stokes JW, Deng L, Yu D (2013) Large-scale malware classification using random projections and neural networks In: Acoustics, Speech and Signal Processing (ICASSP), 2013 IEEE International Conference On, 3422\u20133426.. IEEE. https:\/\/ieeexplore.ieee.org\/document\/6638293.","DOI":"10.1109\/ICASSP.2013.6638293"},{"key":"79_CR9","doi-asserted-by":"crossref","unstructured":"Evtimov, I, Eykholt K, Fernandes E, Kohno T, Li B, Prakash A, Rahmati A, Song D (2017) Robust physical-world attacks on deep learning models. arXiv preprint arXiv:1707.08945 1.","DOI":"10.1109\/CVPR.2018.00175"},{"key":"79_CR10","doi-asserted-by":"publisher","unstructured":"Farhadi, MR, Fung BC, Charland P, Debbabi M (2014) Binclone: Detecting code clones in malware In: 2014 Eighth International Conference on Software Security and Reliability (SERE), 78\u201387.. IEEE, San Francisco. https:\/\/ieeexplore.ieee.org\/document\/6895418, https:\/\/doi.org\/10.1109\/SERE.2014.21.","DOI":"10.1109\/SERE.2014.21"},{"issue":"3","key":"79_CR11","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1145\/3003816","volume":"49","author":"J Gardiner","year":"2016","unstructured":"Gardiner, J, Nagaraja S (2016) On the security of machine learning in malware c&c detection: A survey. ACM Comput Surv (CSUR) 49(3):59.","journal-title":"ACM Comput Surv (CSUR)"},{"key":"79_CR12","unstructured":"Goodfellow, IJ, Shlens J, Szegedy C (2014) Explaining and harnessing adversarial examples. CoRR abs\/1412.6572. https:\/\/arxiv.org\/abs\/1412.6572."},{"key":"79_CR13","unstructured":"Grosse, K, Papernot N, Manoharan P, Backes M, McDaniel P (2016) Adversarial perturbations against deep neural networks for malware classification. arXiv preprint arXiv:1606.04435."},{"key":"79_CR14","doi-asserted-by":"publisher","unstructured":"Han, K, Lim JH, Im EG (2013) Malware analysis method using visualization of binary files In: Proceedings of the 2013 Research in Adaptive and Convergent Systems. RACS \u201913, 317\u2013321.. ACM, New York. https:\/\/doi.org\/10.1145\/2513228.2513294. http:\/\/doi.acm.org\/10.1145\/2513228.2513294.","DOI":"10.1145\/2513228.2513294"},{"key":"79_CR15","doi-asserted-by":"publisher","unstructured":"Ijaz, M, Durad MH, Ismail M (2019) Static and dynamic malware analysis using machine learning In: International Bhurban Conference on Applied Sciences & Technology.. IEEE. https:\/\/ieeexplore.ieee.org\/document\/8667136, https:\/\/doi.org\/10.1109\/IBCAST.2019.8667136.","DOI":"10.1109\/IBCAST.2019.8667136"},{"issue":"2","key":"79_CR16","doi-asserted-by":"publisher","first-page":"646","DOI":"10.1016\/j.jnca.2012.10.004","volume":"36","author":"R Islam","year":"2013","unstructured":"Islam, R, Tian R, Batten LM, Versteeg S (2013) Classification of malware based on integrated static and dynamic features. J Netw Comput Appl 36(2):646\u2013656.","journal-title":"J Netw Comput Appl"},{"key":"79_CR17","unstructured":"Jang, J, Woo M, Brumley D (2013) Towards automatic software lineage inference In: SEC\u201913: Proceedings of the 22nd USENIX conference on Security, 81\u201396. https:\/\/dl.acm.org\/doi\/10.5555\/2534766.2534774."},{"key":"79_CR18","doi-asserted-by":"publisher","unstructured":"Junod, P, Rinaldini J, Wehrli J, Michielin J (2015) Obfuscator-llvm\u2013software protection for the masses In: 2015 IEEE\/ACM 1st International Workshop on Software Protection, 3\u20139.. IEEE. https:\/\/doi.org\/10.1109\/SPRO.2015.10.","DOI":"10.1109\/SPRO.2015.10"},{"key":"79_CR19","doi-asserted-by":"publisher","unstructured":"Khoo, WM, Mycroft A, Anderson R (2013) Rendezvous: A search engine for binary code In: 2013 10th Working Conference on Mining Software Repositories (MSR), 329\u2013338.. IEEE. https:\/\/doi.org\/10.1109\/MSR.2013.6624046.","DOI":"10.1109\/MSR.2013.6624046"},{"key":"79_CR20","unstructured":"Kurakin, A, Goodfellow I, Bengio S (2016) Adversarial examples in the physical world. arXiv preprint arXiv:1607.02533."},{"key":"79_CR21","doi-asserted-by":"publisher","unstructured":"Luo, L, Ming J, Wu D, Liu P, Zhu S (2014) Semantics-based obfuscation-resilient binary code similarity comparison with applications to software plagiarism detection In: Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering, 389\u2013400.. IEEE. https:\/\/doi.org\/10.1109\/TSE.2017.2655046, https:\/\/ieeexplore.ieee.org\/document\/7823022.","DOI":"10.1109\/TSE.2017.2655046"},{"key":"79_CR22","doi-asserted-by":"crossref","unstructured":"Madou, M, Put LV, Bosschere KD (2006) Loco: an interactive code (de)obfuscation tool. https:\/\/doi.org\/10.1145\/1111542.1111566, https:\/\/www.researchgate.net\/publication\/220989942.","DOI":"10.1145\/1111542.1111566"},{"key":"79_CR23","doi-asserted-by":"publisher","unstructured":"Myles, G, Collberg C (2005) K-gram based software birthmarks In: Proceedings of the 2005 ACM Symposium on Applied Computing, 314\u2013318.. 2005 ACM Symposium on Applied Computing. https:\/\/doi.org\/10.1145\/1066677.1066753.","DOI":"10.1145\/1066677.1066753"},{"key":"79_CR24","doi-asserted-by":"publisher","unstructured":"Narodytska, N, Kasiviswanathan S (2017) Simple black-box adversarial attacks on deep neural networks In: 2017 IEEE Conference on Computer Vision and Pattern Recognition Workshops (CVPRW), 1310\u20131318.. IEEE. https:\/\/doi.org\/10.1109\/CVPRW.2017.172.","DOI":"10.1109\/CVPRW.2017.172"},{"key":"79_CR25","doi-asserted-by":"publisher","unstructured":"Nataraj, L, Karthikeyan S, Jacob G, Manjunath B (2011) Malware images: visualization and automatic classification In: Proceedings of the 8th International Symposium on Visualization for Cyber Security, 4.. ACM. https:\/\/doi.org\/10.1145\/2016904.2016908.","DOI":"10.1145\/2016904.2016908"},{"key":"79_CR26","unstructured":"Necula, GC, Mcpeak S, Rahul SP, Weimer W (2002) Cil: Intermediate language and tools for analysis and transformation of c programs In: Compiler Construction, 11th International Conference, CC 2002, Held as Part of the Joint European Conferences on Theory and Practice of Software, ETAPS 2002, Grenoble, France, April 8-12, 2002, Proceedings.. International Conference on Compiler Construction. https:\/\/doi.org\/10.1007\/3-540-45937-5_16, https:\/\/link.springer.com\/chapter\/10.1007\/3-540-45937-5_16."},{"key":"79_CR27","unstructured":"Papernot, N, McDaniel P, Goodfellow I (2016) Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv preprint arXiv:1605.07277."},{"key":"79_CR28","doi-asserted-by":"publisher","unstructured":"Papernot, N, McDaniel P, Goodfellow I, Jha S, Celik ZB, Swami A (2017) Practical black-box attacks against machine learning In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, 506\u2013519.. ACM. https:\/\/doi.org\/10.1145\/3052973.3053009.","DOI":"10.1145\/3052973.3053009"},{"key":"79_CR29","doi-asserted-by":"crossref","unstructured":"Pierazzi, F, Pendlebury F, Cortellazzi J, Cavallaro L (2019) Intriguing properties of adversarial ml attacks in the problem space. https:\/\/arxiv.org\/abs\/1911.02142.","DOI":"10.1109\/SP40000.2020.00073"},{"key":"79_CR30","doi-asserted-by":"publisher","unstructured":"Saxe, J, Berlin K (2015) Deep neural network based malware detection using two dimensional binary program features In: Malicious and Unwanted Software (MALWARE), 2015 10th International Conference On, 11\u201320.. IEEE. https:\/\/doi.org\/10.1109\/MALWARE.2015.7413680.","DOI":"10.1109\/MALWARE.2015.7413680"},{"key":"79_CR31","doi-asserted-by":"crossref","unstructured":"Su, J, Vargas DV, Sakurai K (2019) One pixel attack for fooling deep neural networks. IEEE Trans Evol Comput abs\/1710.08864. http:\/\/arxiv.org\/abs\/1710.08864.","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"79_CR32","unstructured":"Szegedy, C, Zaremba W, Sutskever I, Bruna J, Erhan D, Goodfellow I, Fergus R (2013) Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199."},{"key":"79_CR33","doi-asserted-by":"crossref","unstructured":"Vinod, P, Jaipur R, Laxmi V, Gaur M (2009) Survey on malware detection methods In: Proceedings of the 3rd Hackers\u2019 Workshop on Computer and Internet Security (IITKHACK\u201909), 74\u201379. https:\/\/dx.doi.org\/10.1145\/1327452.1327492.","DOI":"10.1145\/1327452.1327492"},{"key":"79_CR34","doi-asserted-by":"publisher","unstructured":"Wang, Q, Guo W, Zhang K, Ororbia II AG, Xing X, Liu X, Giles CL (2017) Adversary resistant deep neural networks with an application to malware detection In: Proceedings of the 23rd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 1145\u20131153.. ACM. https:\/\/doi.org\/10.1145\/3097983.3098158.","DOI":"10.1145\/3097983.3098158"},{"key":"79_CR35","doi-asserted-by":"publisher","unstructured":"Wu, Y, Zhang B, Lai Z, Su J (2012) Malware network behavior extraction based on dynamic binary analysis In: IEEE International Conference on Software Engineering & Service Science.. IEEE. https:\/\/doi.org\/10.1109\/ICSESS.2012.6269469, https:\/\/ieeexplore.ieee.org\/document\/6269469.","DOI":"10.1109\/ICSESS.2012.6269469"},{"key":"79_CR36","doi-asserted-by":"crossref","unstructured":"Yang, C, Wen Y, Guo J, Song H, Li L, Che H, Meng D (2018) A convolutional neural network based classifier for uncompressed malware samples In: Proceedings of the 1st Workshop on Security-Oriented Designs of Computer Architectures and Processors, 15\u201317.. ACM. https:\/\/dl.acm.org\/doi\/10.1145\/3267494.3267496.","DOI":"10.1145\/3267494.3267496"},{"issue":"3","key":"79_CR37","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1145\/3073559","volume":"50","author":"Y Ye","year":"2017","unstructured":"Ye, Y, Li T, Adjeroh D, Iyengar SS (2017) A survey on malware detection using data mining techniques. ACM Comput Surv 50(3):41\u201314140. https:\/\/doi.org\/10.1145\/3073559.","journal-title":"ACM Comput Surv"},{"key":"79_CR38","doi-asserted-by":"publisher","unstructured":"You, I, Yim K (2010) Malware obfuscation techniques: A brief survey In: Broadband, Wireless Computing, Communication and Applications (BWCCA), 2010 International Conference On, 297\u2013300.. IEEE. https:\/\/doi.org\/10.1109\/BWCCA.2010.85.","DOI":"10.1109\/BWCCA.2010.85"},{"key":"79_CR39","doi-asserted-by":"publisher","unstructured":"Yuan, Z, Lu Y, Wang Z, Xue Y (2014) Droid-sec: deep learning in android malware detection In: ACM SIGCOMM Computer Communication Review, 371\u2013372.. ACM. https:\/\/doi.org\/10.1145\/2619239.2631434.","DOI":"10.1145\/2619239.2631434"},{"key":"79_CR40","unstructured":"Yue, S (2017) Imbalanced malware images classification: a cnn based approach. arXiv preprint arXiv:1708.08042."}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00079-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-021-00079-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00079-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,13]],"date-time":"2021-05-13T23:08:27Z","timestamp":1620947307000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00079-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,14]]},"references-count":40,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,12]]}},"alternative-id":["79"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00079-5","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,14]]},"assertion":[{"value":"13 November 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 February 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"14 May 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"16"}}