Evolving a malware into a family is an effective technique to hinder detection mechanisms. A recent trend exploits generative models to support threat actors in the creation of “mutations” for rapidly prepar- ing malware families. However, artificial intelligence can also be used to develop effective countermeasures. To this end, we propose MalARN, a deep learning-based solution for creating synthetic representations of malware variants to make detectors more robust and facilitate spotting never-seen threats. MalARN takes advantage of a pre-trained large lan- guage model to map both malicious and benign b inary samples into embeddings. To bypass the requirement for executable binaries, an adver- sarial reconstruction network is used to operate directly in the embedding space. Evaluated against four real malware families, MalARN outperforms the baseline solution in terms of specific metrics for unbalanced scenarios.

MalARN: An Adversarial Reconstruction Network for Improving Detection of Evolving Malware

Caviglione L.;Guarascio M.
;
Liguori A.;Manco G.;Ritacco E.;Rullo A.
2027

Abstract

Evolving a malware into a family is an effective technique to hinder detection mechanisms. A recent trend exploits generative models to support threat actors in the creation of “mutations” for rapidly prepar- ing malware families. However, artificial intelligence can also be used to develop effective countermeasures. To this end, we propose MalARN, a deep learning-based solution for creating synthetic representations of malware variants to make detectors more robust and facilitate spotting never-seen threats. MalARN takes advantage of a pre-trained large lan- guage model to map both malicious and benign b inary samples into embeddings. To bypass the requirement for executable binaries, an adver- sarial reconstruction network is used to operate directly in the embedding space. Evaluated against four real malware families, MalARN outperforms the baseline solution in terms of specific metrics for unbalanced scenarios.
2027
Istituto di Calcolo e Reti ad Alte Prestazioni - ICAR
9783032326423
9783032326430
malware detection , synthetic malware generation , adversarial learning
File in questo prodotto:
File Dimensione Formato  
2026_ismis_sec.pdf

solo utenti autorizzati

Descrizione: published version
Tipologia: Versione Editoriale (PDF)
Licenza: NON PUBBLICO - Accesso privato/ristretto
Dimensione 1.15 MB
Formato Adobe PDF
1.15 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/599281
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact