Windows malware detectors vary widely in vulnerability to attacks

Breaking Windows Malware Detection: A Comprehensive Evaluation of Problem-Space Adversarial Robustness

Cryptography and Security

Summary

Machine learning tools used to detect Windows malware can be tricked by special changes attackers make. The authors tested many types of attacks on several popular detectors to see which ones get fooled the most and why. They found that some detectors are more vulnerable depending on how they analyze malware, and that certain attacks work better than others. Also, making detectors tougher against one attack type doesn’t always help against others. The study helps us understand where malware detectors still have weaknesses and how attacks can spread to different detectors.

What this means in practice

  • For cybersecurity teams: Evaluate and improve malware detection tools with insight on vulnerabilities across attack types and model architectures.
  • For software antivirus developers: Design more robust Windows malware detectors by focusing on complementary attack defenses informed by real-world adversarial patterns.$Commercial implications: Enables development of commercial antivirus products with stronger defense capabilities against evasive malware attacks.

Authors

Mashal Zainab, Salijona Dyrmishi, Hamid Bostani, Lorenzo Cavallaro, Maxime Cordy

Abstract

Problem-space evasion attacks have exposed critical weaknesses in machine learning-based malware detectors; yet, their evaluation remains fragmented across models, datasets, and attack methodologies, often neglecting domain-specific requirements such as executability and functionality preservation. We address this gap with a unified, large-scale evaluation of nine state-of-the-art evasion attacks against eight Windows malware detectors, including seven open-source models and one commercial detector, under executability-preserving conditions. Our study analyzes attack effectiveness, complementarity, transferability, and adversarial hardening to evaluate robustness along complementary dimensions. We show that detector vulnerability depends strongly on both model representation and attack type: raw-byte detectors are particularly susceptible to several classes of problem-space manipulation, but no detector family is uniformly robust across all attacks. Importantly, effectiveness is not explained by transformation-space size alone: the strongest attacks can achieve substantially higher success while using fewer distinct transformations and concentrating on a small set of high-impact manipulations. We further show that two complementary attacks are sufficient to cover approximately 99% of the adversarial examples produced by the remaining evaluated attacks. Transferability exhibits a different pattern from direct attack success: attacks with low direct success can produce highly transferable evasions. Finally, adversarial hardening is highly attack- and model-dependent: robustness gains often fail to transfer across attacks and can even increase susceptibility to unseen attacks. These findings highlight limitations in current malware robustness evaluations, establish a comprehensive empirical baseline, and clarify relationships between effectiveness, transferability, and defense robustness.