MARATTO

article

Adversarial Retraining and White-Box Attacks for Robust Malware Detection

Abstract

This paper investigates the vulnerability of deep learning models to adversarial attacks in malware detection and evaluates adversarial retraining as a defense mechanism. We assess DNN, Wide&DNN, CNN, and CNN&GRU&Att models under clean conditions, adversarial attacks (FGSM, PGD, BIM), and retraining. Results show a sharp performance drop under attacks, with Wide&DNN and CNN&GRU&Att exhibiting greater resilience. Adversarial retraining significantly enhances robustness, often restoring or improving pre-attack performance. Analysis of accuracy, precision, recall, Fl-score, and AUC underscores the need for strong defense strategies and complex architectures.

Research topics

  • Advanced Malware Detection Techniques
  • Adversarial Robustness in Machine Learning
  • Cryptographic Implementations and Security

Read the original research

This page summarises published work. The authoritative version sits with the publisher.

DOI: 10.1109/isdfs65363.2025.11012053

Is something wrong with this record? Report it or request removal.

Discussion

Discuss this research

Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.

No discussion yet. Open the first thread.