{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/crystal-ball-from-innovative-attacks-to","title":"Crystal ball: From innovative attacks to attack effectiveness classifier","arxiv_id":null,"date":"2024-12-24","proceeding":"IEEE Access 2024 12","authors":["Berger","Hajaj","Mariconti","Dvir"],"abstract":"Android OS is one of the most popular operating systems worldwide, making it a desirable\r\ntarget for malware attacks. Some of the latest and most important defensive systems are based on machine\r\nlearning (ML) and cybercriminals continuously search for ways to overcome the barriers posed by these\r\nsystems. Thus, the focus of this work is on evasion attacks in the attempt to show the weaknesses of state of\r\nthe art research and how more resilient systems can be built. Evasion attacks consist of manipulating either\r\nthe actual malicious application (problem-based) or its extracted feature vector (feature-based), to avoid\r\nbeing detected by ML systems. This study presents a set of innovative problem-based evasion attacks against\r\nwell-known Android malware detection systems, which decrease their detection rate by up to 97%. Moreover,\r\nan analysis of the effectiveness of these attacks against VirusTotal (VT) scanners was conducted, empirically\r\nshowing their efficiency against well-known scanners (e.g., McAfee and Comodo) as well. The VT system\r\nproved to be a great candidate for the attacks, as in 98% of the apps, less scanners detected the manipulated\r\napps than the original malicious apps. As not all the attacks are effective in the same manner against the VT\r\nscanners, the attack efficiency classifiers are advised. Each classifier predicts the applicability of one of the\r\nattacks. The set of classifiers creates an ensemble, which shows high success rates, allowing the attacker to\r\ndecide which attack is best to use for each malicious app and defense system.","url_abs":"https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=9663162","url_pdf":"https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=9663162","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"crystal-ball-from-innovative-attacks-to","repo_url":"https://github.com/ArielCyber/Android-crystal-ball","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"none","reach":null}],"tasks":[{"task_slug":"android-malware-detection","task_name":"Android Malware Detection"},{"task_slug":"malware-detection","task_name":"Malware Detection"}],"methods":[{"method_slug":"focus","method_name":"Focus"},{"method_slug":"set","method_name":"SET"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}