Skip to content

Adversarial Malware Can Be Both Evasive and Deceiving: a Gradient-based Attack Against Prediction and Explainability in Windows PE Malware Detection

Jul 2026 · 2026 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) · pp. 253-261 · 0 citations · 26 references

Abstract

In the last years, several gradient-based attacks have been developed to disclose vulnerabilities of deep neural models and strengthen evasion and transferability abilities of adversarial examples created in various domains. In Windows PE malware detection, various gradient-based methods have been recently tested to optimize the editing or injection of adversarial bytes in unused file sections, and create adversarial malicious PE files to evade deep neural models developed for malware detection. On the other hand, gradient information is commonly used in eXplainable AI (XAI) to obtain explanations for opaque decision-making processes of deep neural black-boxes, while Adversarial XAI has recently emerged as an Adversarial Learning field to investigate the security landscape of XAI. In this study, we describe a holistic, gradient-based attack method, named GAME4EXE, formulated to optimize editing of adversarial bytes in the DOS Header and DOS Stub sections of Windows PE malware. The optimization is driven by the dual adversary purpose of generating adversarial malware that evades a target deep neural model, and aligning the explanation of the evading decisions with that of a goodware-like explanation. A preliminary evaluation shows that a gradient-based attack can be effectively formulated in the Windows PE malware domain, to equip the evasion of a deep neural model with the capability to coherently deceive its decision process explainer and harden attack detection.

View source

Similar papers

Open access Aug 2026

An advanced framework for malware detection using adversarial learning

A systematic framework to enhance adversarial robustness is proposed, validated on the Malimg dataset and supersedes previous approaches by 13.15% in terms of the evasion rate and 37.34% in terms of retraining success.

Muhammad Arham Tariq, Allah Bux Sargano, Z. Habib et al. · 0 citations
Aug 2026

Enhancing robustness of deep learning-based malware detection against adversarial attacks

This paper introduces DefendMal, a novel framework that synergistically combines Denoise Autoencoder with Sequence Squeezing, a Context-aware Adversarial Generator (CAG-AdvGAN), Projected Gradient Descent (PGD) adversarial training, and a Positive–Negative Detector with Variational Autoencoder (PNDetector-VAE) to enhance robustness against evolving adversarial threats.

Dennis Benedict Crasta, Vikash Kumar · 0 citations
Review Open access Aug 2026

Generative Adversarial Networks for Anomaly and Malware Detection

A comprehensive survey of how GAN-based methods are utilized for identifying unusual and harmful activities in cyber settings and addresses ongoing challenges and potential future avenues for employing GANs to counteract emerging cybersecurity threats.

A. Thakore, Neha Gupta, Akash Saxena et al. · 0 citations
Open access Aug 2026

Analyzing Malware Behavior Using Generative Neural Networks

Traditional detection techniques are struggling with ever-evolving malware threats like zero-day attacks, polymorphic malware, and adversarial samples. Current detection systems (signature-based, heuristic-based, conventional machine learning) fail to generalize to unseen/obfuscated malware variants. In an attempt to overcome these constraints, this paper investigates the possibilities of employing Generative Neural Networks (GNNs), in the form of Generative Adversarial Networks (GANs) and Variational Autoencoders (VAEs) for the purpose of malware be haviour analysis and detection. We aim to create a novel framework for detecting malware samples that provides some of the best performance in terms of accuracy, precision, and recall while remaining robust to new or unseen malware. This work aims to firstly implement a generative learning-based approach and to measure its adversarial robustness in comparison with the four existing detection techniques. Experimental results show the accuracy, precision, recall of the proposed model is found to be 96.5%, 95.9%, 94.6% with the false positive rate of the model which can be negligible and it is 3.2% which outperforms the traditional machine learning and deep learning models. Our results demonstrate that GNN-based malware detection not only addresses the limitations of conventional approaches in terms of scalability but also provides a more robust and adaptable framework that could be integrated into future real-time threat intelligence and automated defense systems.

Wurood A. Jbara, N. A. Hussein · 0 citations
#machine learning Preprint Aug 2026

REPLICANT: Learning Policies for Evading and Hardening Malware Detectors

This work presents Replicant, a deep reinforcement learning framework that learns the realistic task of evasion under a strict label-only black-box threat model and demonstrates that learning the task of evasion not only results in stronger attack performance but provides a better signal for hardening malware detectors.

Shae McFadden, Ilias Tsingenopoulos, Mario D'Onghia et al. · 0 citations

GRASP: Hard-Label Black-Box Malware Evasion with Higher Success, Fewer Queries, and Smaller Perturbations

Gradient-seeded Reinforcement Learning And Stealthy Pruning (GRASP), a three-stage framework that tackles challenges of adversarial attacks on machine learning-based malware detectors, and out-performs baselines, achieving higher attack success with fewer queries and smaller file-size inflation.

Yutong Liu, Jianting Ning, Qi Feng et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.