中文

EvilModel 2.0:将神经网络模型引入恶意软件攻击

密码学与安全 2022-06-29 v3 人工智能

摘要

随着人工智能(AI)的不断发展,安全问题逐渐显现。早期的工作验证了将神经网络模型转化为隐写恶意软件的可能性,即将恶意软件嵌入模型中,且对模型性能的影响有限。然而,由于性能下降和额外的工作量,现有方法不适用于现实世界的攻击场景,且未引起安全社区的足够重视。因此,我们提出了一种改进的隐写恶意软件 EvilModel。通过分析神经网络模型的组成,提出了三种将恶意软件嵌入模型的新方法:MSB保留、快速替换和半替换,这些方法可以嵌入占模型体积一半的恶意软件而不影响模型的性能。我们使用十个主流神经网络模型和19个恶意软件样本构建了550个 EvilModel。实验表明,EvilModel 实现了48.52%的嵌入率。提出了一种定量算法来评估现有的嵌入方法。我们还设计了一个触发器,并提出了针对目标攻击的威胁场景。通过对嵌入容量、性能影响和检测规避的实验和分析,证明了所提方法的实用性和有效性。

关键词

引用

@article{arxiv.2109.04344,
  title  = {EvilModel 2.0: Bringing Neural Network Models into Malware Attacks},
  author = {Zhi Wang and Chaoge Liu and Xiang Cui and Jie Yin and Xutong Wang},
  journal= {arXiv preprint arXiv:2109.04344},
  year   = {2022}
}

备注

A newer version of this paper has been accepted at Computers & Security. Free access to the final version at https://authors.elsevier.com/c/1fJhFc43uylbS before August 16, 2022. This paper is an extended version of work that was first presented at the 26th IEEE Symposium on Computers and Communications (ISCC 2021)