中文

利用低级行为对抗样本的规避型勒索软件攻击

密码学与安全 2025-08-28 v1

摘要

保护最先进的基于人工智能的网络安全防御系统免受网络攻击至关重要。攻击者通过向攻击特征添加微小变化(即扰动)来创建对抗样本,以规避或欺骗深度学习模型。本文介绍了低级行为对抗样本的概念及其规避型勒索软件的威胁模型。我们制定了生成规避型恶意软件最优源代码的方法和威胁模型。然后,我们使用泄露的Conti勒索软件源代码及其微行为控制函数来检验该方法。微行为控制函数是我们的测试组件,用于模拟更改勒索软件中的源代码;通过指定线程数、文件加密比率以及启动时文件加密后的延迟,可以改变勒索软件的行为。我们评估了攻击者利用微行为控制函数能在多大程度上控制勒索软件的行为特征,以降低勒索软件检测器的检测率。

关键词

引用

@article{arxiv.2508.08656,
  title  = {Evasive Ransomware Attacks Using Low-level Behavioral Adversarial Examples},
  author = {Manabu Hirano and Ryotaro Kobayashi},
  journal= {arXiv preprint arXiv:2508.08656},
  year   = {2025}
}

备注

\copyright 2025 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works