Skip to main navigation Skip to search Skip to main content

Interpretable Defense Against Structural Adversarial Attacks on Android Malware Detection

  • Wenying Wei
  • , Kaifa Zhao
  • , Hao Zhou
  • , Jianfeng Li
  • , Shuohan Wu
  • , Ming Fan
  • , Xiapu Luo
  • , Ting Wang
  • , Kai Zhou
  • , Ting Liu
  • , Yuzhe Tang
  • Hong Kong Polytechnic University
  • Xi'an Jiaotong University
  • Syracuse University

Research output: Contribution to journalArticlepeer-review

Abstract

Android, being one of the most widely used mobile systems, is facing pressing threats from malware. Despite the effectiveness of Android malware detection (AMD) systems, they are still vulnerable to state-of-the-art adversarial attacks. Existing defense methods require the knowledge of target adversaries, such as attack algorithms or obfuscation strategies, which is impractical in real-world scenarios. Additionally, these approaches may adversely affect the performance of the detection model and fail to defend against problem-space attacks, which not only deceive the detection models but also generate executable adversarial software. To address this research gap, we propose a novel interpretable Android guard system, named IADGuard, to help AMD defend against attacks. IADGuard first designs a novel graph explainable method, AGExplainer, to identify suspicious functions and invocations in adversarial malware. With the guidance of AGExplainer, IADGuard develops a rectifier to reverse adversarial modifications on apps’ function invocation relations, which facilitates the detection of adversarial malware by victim AMD. It is noteworthy that IADGuard requires zero knowledge of adversarial models and victim models, thereby preserves the performance of victim AMD. We validate IADGuard over three state-of-the-art problem space attacks that modify apps’ function invocation relations to deceive victim AMD. Experimental results show that IADGuard achieves over 90.5% defense success rate, i.e., helps victim AMD identify adversarial malware. Furthermore, AGExplainer surpasses representative interpreters in identifying essential modifications, helps IADGuard reduce false positives to 1.5%, and improves the detection efficiency by up to 10.4 times.

Original languageEnglish
Pages (from-to)13296-13311
Number of pages16
JournalIEEE Transactions on Information Forensics and Security
Volume20
DOIs
StatePublished - 2025

Keywords

  • adversarial attack
  • Android malware detection
  • Interpretable defense

Fingerprint

Dive into the research topics of 'Interpretable Defense Against Structural Adversarial Attacks on Android Malware Detection'. Together they form a unique fingerprint.

Cite this