{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T01:01:27Z","timestamp":1780707687385,"version":"3.54.1"},"reference-count":52,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,12,1]],"date-time":"2021-12-01T00:00:00Z","timestamp":1638316800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,12,2]],"date-time":"2021-12-02T00:00:00Z","timestamp":1638403200000},"content-version":"vor","delay-in-days":1,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2021,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Adversarial Malware Example (AME)-based adversarial training can effectively enhance the robustness of Machine Learning (ML)-based malware detectors against AME. AME quality is a key factor to the robustness enhancement. Generative Adversarial Network (GAN) is a kind of AME generation method, but the existing GAN-based AME generation methods have the issues of inadequate optimization, mode collapse and training instability. In this paper, we propose a novel approach (denote as LSGAN-AT) to enhance ML-based malware detector robustness against Adversarial Examples, which includes LSGAN module and AT module. LSGAN module can generate more effective and smoother AME by utilizing brand-new network structures and Least Square (LS) loss to optimize boundary samples. AT module makes adversarial training using AME generated by LSGAN to generate ML-based Robust Malware Detector (RMD). Extensive experiment results validate the better transferability of AME in terms of attacking 6 ML detectors and the RMD transferability in terms of resisting the MalGAN black-box attack. The results also verify the performance of the generated RMD in the recognition rate of AME.<\/jats:p>","DOI":"10.1186\/s42400-021-00102-9","type":"journal-article","created":{"date-parts":[[2021,12,2]],"date-time":"2021-12-02T02:02:59Z","timestamp":1638410579000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":29,"title":["LSGAN-AT: enhancing malware detector robustness against adversarial examples"],"prefix":"10.1186","volume":"4","author":[{"given":"Jianhua","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2975-8857","authenticated-orcid":false,"given":"Xiaolin","family":"Chang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yixiang","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ricardo J.","family":"Rodr\u00edguez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,12,2]]},"reference":[{"key":"102_CR1","doi-asserted-by":"publisher","unstructured":"Allix K, Bissyand\u00e9 TF, Klein J, Le Traon Y (2016) AndroZoo: collecting millions of Android apps for the research community. In: Proceedings of the 13th international conference on mining software repositories, Austin Texas, May 2016, pp 468\u2013471. https:\/\/doi.org\/10.1145\/2901739.2903508","DOI":"10.1145\/2901739.2903508"},{"key":"102_CR2","unstructured":"Arjovsky M, Chintala S, Bottou L (2017) Wasserstein generative adversarial networks. In Proceedings of the 34th international conference on machine learning, Jul. 2017, pp 214\u2013223. Accessed: Sep. 24, 2021. https:\/\/proceedings.mlr.press\/v70\/arjovsky17a.html"},{"key":"102_CR3","first-page":"23","volume":"14","author":"D Arp","year":"2014","unstructured":"Arp D, Spreitzenbarth M, Hubner M, Gascon H, Rieck K, Siemens C (2014) Drebin: effective and explainable detection of android malware in your pocket. Ndss 14:23\u201326","journal-title":"Ndss"},{"key":"102_CR4","doi-asserted-by":"crossref","unstructured":"Berlin K, Slater D, Saxe J (2015) Malicious behavior detection using windows audit logs. In: Proceedings of the 8th ACM workshop on artificial intelligence and security, pp 35\u201344","DOI":"10.1145\/2808769.2808773"},{"key":"102_CR5","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1016\/j.patcog.2018.07.023","volume":"84","author":"B Biggio","year":"2018","unstructured":"Biggio B, Roli F (2018) Wild patterns: ten years after the rise of adversarial machine learning. Pattern Recognit 84:317\u2013331","journal-title":"Pattern Recognit"},{"key":"102_CR6","doi-asserted-by":"publisher","first-page":"326","DOI":"10.1016\/j.cose.2017.11.007","volume":"73","author":"S Chen","year":"2018","unstructured":"Chen S et al (2018) Automated poisoning attacks and defenses in malware detection systems: an adversarial machine learning approach. Comput Secur 73:326\u2013344","journal-title":"Comput Secur"},{"key":"102_CR7","doi-asserted-by":"crossref","unstructured":"Chen L, Ye Y, Bourlai T (2017) Adversarial machine learning in malware detection: arms race between evasion attack and defense. In: 2017 European intelligence and security informatics conference (EISIC), 2017, pp 99\u2013106","DOI":"10.1109\/EISIC.2017.21"},{"key":"102_CR8","unstructured":"Chocolatey\u2014The package manager for Windows, Chocolatey Software. https:\/\/chocolatey.org\/ (accessed Jul. 21, 2021)"},{"key":"102_CR9","doi-asserted-by":"crossref","unstructured":"Christodorescu M, Jha S, Seshia SA, Song D, Bryant RE (2005) Semantics-aware malware detection. In: 2005 IEEE symposium on security and privacy (S&P\u201905), 2005, pp 32\u201346","DOI":"10.1109\/SP.2005.20"},{"issue":"1","key":"102_CR10","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1109\/MSP.2017.2765202","volume":"35","author":"A Creswell","year":"2018","unstructured":"Creswell A, White T, Dumoulin V, Arulkumaran K, Sengupta B, Bharath AA (2018) Generative adversarial networks: an overview. IEEE Signal Process Mag 35(1):53\u201365","journal-title":"IEEE Signal Process Mag"},{"key":"102_CR11","unstructured":"\u201cCuckoo Sandbox\u2014Automated Malware Analysis.\u201d https:\/\/cuckoosandbox.org\/. Accessed April 23, 2021"},{"issue":"1","key":"102_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11416-015-0261-z","volume":"13","author":"A Damodaran","year":"2017","unstructured":"Damodaran A, Troia FD, Visaggio CA, Austin TH, Stamp M (2017) A comparison of static, dynamic, and hybrid analysis for malware detection. J Comput Virol Hacking Tech 13(1):1\u201312. https:\/\/doi.org\/10.1007\/s11416-015-0261-z","journal-title":"J Comput Virol Hacking Tech"},{"key":"102_CR13","doi-asserted-by":"crossref","unstructured":"Gonog L, Zhou Y (2019) A review: generative adversarial networks. In: 2019 14th IEEE conference on industrial electronics and applications (ICIEA), 2019, pp 505\u2013510","DOI":"10.1109\/ICIEA.2019.8833686"},{"key":"102_CR14","doi-asserted-by":"crossref","unstructured":"Grosse K, Papernot N, Manoharan P, Backes M, McDaniel P (2016) Adversarial perturbations against deep neural networks for malware classification. arXiv: http:\/\/arxiv.org\/abs\/1606.04435, 2016","DOI":"10.1109\/SP.2016.41"},{"key":"102_CR15","doi-asserted-by":"crossref","unstructured":"Grosse K, Papernot N, Manoharan P, Backes M, McDaniel P (2017) Adversarial examples for malware detection. In European symposium on research in computer security, pp 62\u201379","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"102_CR16","unstructured":"Hu W, Tan Y (2017) Generating adversarial malware examples for black-box attacks based on GAN,\u201d ArXiv170205983 Cs, Feb. 2017, Accessed: Apr. 23, 2021. http:\/\/arxiv.org\/abs\/1702.05983"},{"key":"102_CR17","doi-asserted-by":"crossref","unstructured":"Huang L, Joseph AD, Nelson B, Rubinstein BI, Tygar JD (2011) Adversarial machine learning. In: Proceedings of the 4th ACM workshop on security and artificial intelligence, 2011, pp 43\u201358","DOI":"10.1145\/2046684.2046692"},{"key":"102_CR18","unstructured":"Huang S, Papernot N, Goodfellow I, Duan Y, Abbeel P (2017) Adversarial attacks on neural network policies. ArXiv170202284 Cs Stat, Feb. 2017, Accessed: Jul. 14, 2021. [Online]. Available: http:\/\/arxiv.org\/abs\/1702.02284"},{"issue":"4","key":"102_CR19","first-page":"4415","volume":"56","author":"ME Khoda","year":"2019","unstructured":"Khoda ME, Imam T, Kamruzzaman J, Gondal I, Rahman A (2019) Robust malware defense in industrial IoT applications using machine learning with selective adversarial samples. IEEE Trans Ind Appl 56(4):4415\u20134424","journal-title":"IEEE Trans Ind Appl"},{"key":"102_CR20","unstructured":"Kingma DP, Ba J (2014) Adam: a method for stochastic optimization. ArXiv Prepr. http:\/\/arxiv.org\/abs\/1412.6980"},{"key":"102_CR21","doi-asserted-by":"publisher","first-page":"3886","DOI":"10.1109\/TIFS.2020.3003571","volume":"15","author":"D Li","year":"2020","unstructured":"Li D, Li Q (2020) Adversarial deep ensemble: evasion attacks and defenses for malware detection. IEEE Trans Inf Forensics Secur 15:3886\u20133900. https:\/\/doi.org\/10.1109\/TIFS.2020.3003571","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"102_CR22","doi-asserted-by":"publisher","unstructured":"Lucas K, Sharif M, Bauer L, Reiter MK, Shintre S (2021) Malware Makeover: breaking ML-based static analysis by modifying executable bytes. In: Proceedings of the 2021 ACM Asia conference on computer and communications security, New York, NY, USA, May 2021, pp. 744\u2013758. https:\/\/doi.org\/10.1145\/3433210.3453086","DOI":"10.1145\/3433210.3453086"},{"key":"102_CR23","doi-asserted-by":"crossref","unstructured":"Lugmayr A, Danelljan M, Van Gool L, Timofte R (2020) Srflow: learning the super-resolution space with normalizing flow. In: European conference on computer vision, 2020, pp 715\u2013732","DOI":"10.1007\/978-3-030-58558-7_42"},{"key":"102_CR24","unstructured":"Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A (2018) Towards deep learning models resistant to adversarial attacks. https:\/\/openreview.net\/forum?id=rJzIBfZAb"},{"key":"102_CR25","unstructured":"Malware Statistics & Trends Report | AV-TEST.\u201d https:\/\/www.av-test.org\/en\/statistics\/malware\/. Accessed Jul. 14, 2021"},{"key":"102_CR26","doi-asserted-by":"crossref","unstructured":"Mao X, Li Q, Xie H, Lau RYK, Wang Z, Paul Smolley S (2017) Least squares generative adversarial networks, 2017, pp. 2794\u20132802. Accessed: Apr. 23, 2021. https:\/\/openaccess.thecvf.com\/content_iccv_2017\/html\/Mao_Least_Squares_Generative_ICCV_2017_paper.html","DOI":"10.1109\/ICCV.2017.304"},{"key":"102_CR27","unstructured":"Microsoft Malware Classification Challenge (BIG 2015). https:\/\/kaggle.com\/c\/malware-classification (accessed Jul. 21, 2021)"},{"key":"102_CR28","unstructured":"Nair V, Hinton GE (2010) Rectified linear units improve restricted boltzmann machines"},{"issue":"1","key":"102_CR29","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1007\/s10207-014-0248-7","volume":"14","author":"A Nappa","year":"2015","unstructured":"Nappa A, Rafique MZ, Caballero J (2015) The MALICIA dataset: identification and analysis of drive-by download operations. Int J Inf Secur 14(1):15\u201333","journal-title":"Int J Inf Secur"},{"key":"102_CR30","volume-title":"8. Two-person cooperative games","author":"JF Nash","year":"2016","unstructured":"Nash JF (2016) 8. Two-person cooperative games. Princeton University Press, Princeton"},{"issue":"4","key":"102_CR31","doi-asserted-by":"publisher","first-page":"500","DOI":"10.1109\/TETCI.2020.2991774","volume":"4","author":"Z Pan","year":"2020","unstructured":"Pan Z et al (2020) Loss functions of generative adversarial networks (GANs): opportunities and challenges. IEEE Trans Emerg Top Comput Intell 4(4):500\u2013522. https:\/\/doi.org\/10.1109\/TETCI.2020.2991774","journal-title":"IEEE Trans Emerg Top Comput Intell"},{"key":"102_CR32","unstructured":"Pang T, Yang X, Dong Y, Su H, Zhu J (2021) Bag of tricks for adversarial training. https:\/\/openreview.net\/forum?id=Xb8xvrtB8Ce"},{"key":"102_CR33","doi-asserted-by":"crossref","unstructured":"Papernot N, McDaniel P, Jha S, Fredrikson M, Celik ZB, Swami A (2016) The limitations of deep learning in adversarial settings. In: 2016 IEEE European symposium on security and privacy (EuroS&P), 2016, pp 372\u2013387","DOI":"10.1109\/EuroSP.2016.36"},{"key":"102_CR34","first-page":"2825","volume":"12","author":"F Pedregosa","year":"2011","unstructured":"Pedregosa F et al (2011) Scikit-learn: machine learning in Python. J Mach Learn Res 12:2825\u20132830","journal-title":"J Mach Learn Res"},{"key":"102_CR35","doi-asserted-by":"crossref","unstructured":"Sewak M, Sahay SK, Rathore H (2020) DOOM: a novel adversarial-DRL-based op-code level metamorphic malware obfuscator for the enhancement of IDS. In: Adjunct proceedings of the 2020 ACM international joint conference on pervasive and ubiquitous computing and proceedings of the 2020 ACM international symposium on wearable computers, 2020, pp 131\u2013134","DOI":"10.1145\/3410530.3414411"},{"key":"102_CR36","doi-asserted-by":"crossref","unstructured":"Suciu O, Coull SE, Johns J (2019) Exploring adversarial examples in malware detection. In: 2019 IEEE security and privacy workshops (SPW), 2019, pp 8\u201314","DOI":"10.1109\/SPW.2019.00015"},{"key":"102_CR37","unstructured":"Szegedy C et al (2014) Intriguing properties of neural networks. ArXiv13126199 Cs, Feb. 2014, Accessed: Apr. 23, 2021. [Online]. http:\/\/arxiv.org\/abs\/1312.6199"},{"key":"102_CR38","unstructured":"VirusTotal. https:\/\/www.virustotal.com\/gui\/ (accessed Jul. 21, 2021)"},{"key":"102_CR39","unstructured":"VirusShare.com.\u201d https:\/\/virusshare.com\/research (accessed Apr. 23, 2021)"},{"key":"102_CR40","doi-asserted-by":"publisher","first-page":"12","DOI":"10.1016\/j.jpdc.2019.03.003","volume":"130","author":"X Wang","year":"2019","unstructured":"Wang X, Li J, Kuang X, Tan Y, Li J (2019a) The security of machine learning in an adversarial setting: a survey. J Parallel Distrib Comput 130:12\u201323","journal-title":"J Parallel Distrib Comput"},{"key":"102_CR41","doi-asserted-by":"publisher","first-page":"124503","DOI":"10.1109\/ACCESS.2020.3006130","volume":"8","author":"D Wang","year":"2020","unstructured":"Wang D, Dong L, Wang R, Yan D, Wang J (2020) Targeted speech adversarial example generation with generative adversarial network. IEEE Access 8:124503\u2013124513","journal-title":"IEEE Access"},{"key":"102_CR42","doi-asserted-by":"crossref","unstructured":"Wang Y, Liu J, Chang Z (2019) Assessing transferability of adversarial examples against malware detection classifiers. In: Proceedings of the 16th ACM international conference on computing frontiers, 2019, pp 211\u2013214","DOI":"10.1145\/3310273.3323072"},{"key":"102_CR43","doi-asserted-by":"crossref","unstructured":"Wang Q et al. (2017) Adversary resistant deep neural networks with an application to malware detection. In: Proceedings of the 23rd ACM sigkdd international conference on knowledge discovery and data mining, 2017, pp 1145\u20131153","DOI":"10.1145\/3097983.3098158"},{"key":"102_CR44","doi-asserted-by":"publisher","unstructured":"Xiao C, Li B, Zhu J, He W, Liu M, Song D (2018) Generating adversarial examples with adversarial networks. In: Proceedings of the twenty-seventh international joint conference on artificial intelligence, IJCAI-18, Jul. 2018, pp 3905\u20133911. https:\/\/doi.org\/10.24963\/ijcai.2018\/543","DOI":"10.24963\/ijcai.2018\/543"},{"key":"102_CR45","unstructured":"Xiao C, Li B, Zhu J-Y, He W, Liu M, Song D (2016) Generating adversarial examples with adversarial networks. Accessed: Apr. 29, 2021. http:\/\/arxiv.org\/abs\/1801.02610"},{"issue":"9","key":"102_CR46","doi-asserted-by":"publisher","first-page":"2805","DOI":"10.1109\/TNNLS.2018.2886017","volume":"30","author":"X Yuan","year":"2019","unstructured":"Yuan X, He P, Zhu Q, Li X (2019) Adversarial examples: attacks and defenses for deep learning. IEEE Trans Neural Netw Learn Syst 30(9):2805\u20132824. https:\/\/doi.org\/10.1109\/TNNLS.2018.2886017","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"102_CR47","doi-asserted-by":"publisher","unstructured":"Yuan Z, Lu Y, Wang Z, Xue Y (2014) Droid-Sec: deep learning in android malware detection. In: Proceedings of the 2014 ACM conference on SIGCOMM, New York, NY, USA, Aug. 2014, pp. 371\u2013372. https:\/\/doi.org\/10.1145\/2619239.2631434","DOI":"10.1145\/2619239.2631434"},{"key":"102_CR48","doi-asserted-by":"publisher","unstructured":"Yuan J, Zhou S, Lin L, Wang F, Cui J (2020) Black-box adversarial attacks against deep learning based malware binaries detection with GAN, ECAI 2020, pp 2536\u20132542. https:\/\/doi.org\/10.3233\/FAIA200388","DOI":"10.3233\/FAIA200388"},{"key":"102_CR49","unstructured":"Zhang H, Yu Y, Jiao J, Xing E, El Ghaoui L, Jordan M (2019) Theoretically principled trade-off between robustness and accuracy. In: International conference on machine learning, pp 7472\u20137482"},{"issue":"2","key":"102_CR50","doi-asserted-by":"publisher","first-page":"153","DOI":"10.1007\/s11416-021-00378-y","volume":"17","author":"Y Zhang","year":"2021","unstructured":"Zhang Y, Li H, Zheng Y, Yao S, Jiang J (2021) Enhanced DNNs for malware classification with GAN-based adversarial training. J Comput Virol Hacking Tech 17(2):153\u2013163. https:\/\/doi.org\/10.1007\/s11416-021-00378-y","journal-title":"J Comput Virol Hacking Tech"},{"key":"102_CR51","unstructured":"Zhao J, Mathieu M, LeCun Y (2017) Energy-based generative adversarial networks: 5th international conference on learning representations, ICLR 2017. Accessed: Sep. 24, 2021. http:\/\/www.scopus.com\/inward\/record.url?scp=85087518435&partnerID=8YFLogxK"},{"key":"102_CR52","doi-asserted-by":"publisher","unstructured":"Zhou Y, Jiang X (2012) Dissecting android malware: characterization and evolution. In: 2012 IEEE symposium on security and privacy, May 2012, pp 95\u2013109. https:\/\/doi.org\/10.1109\/SP.2012.16","DOI":"10.1109\/SP.2012.16"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00102-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-021-00102-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00102-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,12,2]],"date-time":"2021-12-02T02:06:18Z","timestamp":1638410778000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00102-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12]]},"references-count":52,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,12]]}},"alternative-id":["102"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00102-9","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,12]]},"assertion":[{"value":"30 July 2021","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 October 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 December 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"No potential conflict of interest was reported by the authors.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"38"}}