{"id":"https://openalex.org/W3217319441","doi":"https://doi.org/10.1109/isi53945.2021.9624787","title":"Single-Shot Black-Box Adversarial Attacks Against Malware Detectors: A Causal Language Model Approach","display_name":"Single-Shot Black-Box Adversarial Attacks Against Malware Detectors: A Causal Language Model Approach","publication_year":2021,"publication_date":"2021-11-02","ids":{"openalex":"https://openalex.org/W3217319441","doi":"https://doi.org/10.1109/isi53945.2021.9624787","mag":"3217319441"},"language":"en","primary_location":{"id":"doi:10.1109/isi53945.2021.9624787","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isi53945.2021.9624787","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE International Conference on Intelligence and Security Informatics (ISI)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5046482790","display_name":"James Lee Hu","orcid":"https://orcid.org/0009-0009-5112-6280"},"institutions":[{"id":"https://openalex.org/I138006243","display_name":"University of Arizona","ror":"https://ror.org/03m2x1q45","country_code":"US","type":"education","lineage":["https://openalex.org/I138006243"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"James Lee Hu","raw_affiliation_strings":["University of Arizona, Tucson, USA"],"affiliations":[{"raw_affiliation_string":"University of Arizona, Tucson, USA","institution_ids":["https://openalex.org/I138006243"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5030373297","display_name":"Mohammadreza Ebrahimi","orcid":"https://orcid.org/0000-0003-1367-3338"},"institutions":[{"id":"https://openalex.org/I2613432","display_name":"University of South Florida","ror":"https://ror.org/032db5x82","country_code":"US","type":"education","lineage":["https://openalex.org/I2613432"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mohammadreza Ebrahimi","raw_affiliation_strings":["University of South Florida, Tampa, USA"],"affiliations":[{"raw_affiliation_string":"University of South Florida, Tampa, USA","institution_ids":["https://openalex.org/I2613432"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5109924510","display_name":"Hsinchun Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I138006243","display_name":"University of Arizona","ror":"https://ror.org/03m2x1q45","country_code":"US","type":"education","lineage":["https://openalex.org/I138006243"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hsinchun Chen","raw_affiliation_strings":["University of Arizona, Tucson, USA"],"affiliations":[{"raw_affiliation_string":"University of Arizona, Tucson, USA","institution_ids":["https://openalex.org/I138006243"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5046482790"],"corresponding_institution_ids":["https://openalex.org/I138006243"],"apc_list":null,"apc_paid":null,"fwci":1.8283,"has_fulltext":false,"cited_by_count":15,"citation_normalized_percentile":{"value":0.86315078,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":96,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9916999936103821,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9034538269042969},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8024961352348328},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.6452751159667969},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5684216618537903},{"id":"https://openalex.org/keywords/cryptovirology","display_name":"Cryptovirology","score":0.5393255949020386},{"id":"https://openalex.org/keywords/evasion","display_name":"Evasion (ethics)","score":0.5161003470420837},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.486419677734375},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.48388633131980896},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.46738114953041077},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.467023640871048},{"id":"https://openalex.org/keywords/byte","display_name":"Byte","score":0.45903754234313965},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4257050156593323},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.09410035610198975}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9034538269042969},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8024961352348328},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.6452751159667969},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5684216618537903},{"id":"https://openalex.org/C84525096","wikidata":"https://www.wikidata.org/wiki/Q3506050","display_name":"Cryptovirology","level":3,"score":0.5393255949020386},{"id":"https://openalex.org/C2781251061","wikidata":"https://www.wikidata.org/wiki/Q5416089","display_name":"Evasion (ethics)","level":3,"score":0.5161003470420837},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.486419677734375},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.48388633131980896},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.46738114953041077},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.467023640871048},{"id":"https://openalex.org/C43364308","wikidata":"https://www.wikidata.org/wiki/Q8799","display_name":"Byte","level":2,"score":0.45903754234313965},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4257050156593323},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.09410035610198975},{"id":"https://openalex.org/C8891405","wikidata":"https://www.wikidata.org/wiki/Q1059","display_name":"Immune system","level":2,"score":0.0},{"id":"https://openalex.org/C203014093","wikidata":"https://www.wikidata.org/wiki/Q101929","display_name":"Immunology","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isi53945.2021.9624787","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isi53945.2021.9624787","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 IEEE International Conference on Intelligence and Security Informatics (ISI)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.5099999904632568,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":43,"referenced_works":["https://openalex.org/W2144906988","https://openalex.org/W2618219509","https://openalex.org/W2784452215","https://openalex.org/W2809895662","https://openalex.org/W2887324343","https://openalex.org/W2896457183","https://openalex.org/W2909060985","https://openalex.org/W2911919851","https://openalex.org/W2913848079","https://openalex.org/W2919491917","https://openalex.org/W2942795289","https://openalex.org/W2943796454","https://openalex.org/W2946661411","https://openalex.org/W2951672137","https://openalex.org/W2963062382","https://openalex.org/W2963165251","https://openalex.org/W2966708309","https://openalex.org/W2970597249","https://openalex.org/W2973628901","https://openalex.org/W2982725903","https://openalex.org/W3021016503","https://openalex.org/W3034445277","https://openalex.org/W3090219579","https://openalex.org/W3111818035","https://openalex.org/W3112370249","https://openalex.org/W3164220323","https://openalex.org/W4287795696","https://openalex.org/W4288638181","https://openalex.org/W4293472651","https://openalex.org/W4297747285","https://openalex.org/W4385245566","https://openalex.org/W6738397735","https://openalex.org/W6739901393","https://openalex.org/W6745899033","https://openalex.org/W6748325151","https://openalex.org/W6750404860","https://openalex.org/W6752705692","https://openalex.org/W6755207826","https://openalex.org/W6758026774","https://openalex.org/W6758975236","https://openalex.org/W6763701032","https://openalex.org/W6779879114","https://openalex.org/W6787397131"],"related_works":["https://openalex.org/W2963115223","https://openalex.org/W4312707592","https://openalex.org/W3216486624","https://openalex.org/W4303198045","https://openalex.org/W4382173550","https://openalex.org/W2936028052","https://openalex.org/W3197643498","https://openalex.org/W3009299257","https://openalex.org/W2966708309","https://openalex.org/W2938667439"],"abstract_inverted_index":{"Deep":[0],"Learning":[1],"(DL)-based":[2],"malware":[3,21,43,71,104,109,114,162,170,196],"detectors":[4,44,105,115],"are":[5,129],"increasingly":[6],"adopted":[7],"for":[8],"early":[9],"detection":[10],"of":[11,41,56,78,139,168],"malicious":[12,76],"behavior":[13],"in":[14,123,134],"cybersecurity.":[15],"However,":[16,94],"their":[17],"sensitivity":[18],"to":[19,37,52,67,106,131,137,161,210],"adversarial":[20,30,70,108,126],"variants":[22,31,72],"has":[23,49,87],"raised":[24],"immense":[25],"security":[26],"concerns.":[27],"Generating":[28],"such":[29],"by":[32,164,215],"the":[33,39,75,103,166,169,189],"defender":[34],"is":[35],"crucial":[36],"improving":[38],"resistance":[40],"DL-based":[42,149],"against":[45],"them.":[46],"This":[47],"necessity":[48],"given":[50,80],"rise":[51],"an":[53],"emerging":[54],"stream":[55],"machine":[57],"learning":[58],"research,":[59,84],"Adversarial":[60],"Malware":[61],"example":[62],"Generation":[63],"(AMG),":[64],"which":[65],"aims":[66],"generate":[68,107],"evasive":[69],"that":[73,112,128,146],"preserve":[74],"functionality":[77],"a":[79,117,147,173,178,194],"malware.":[81],"Within":[82],"AMG":[83,97],"black-box":[85,96],"method":[86],"gained":[88],"more":[89],"attention":[90],"than":[91],"white-box":[92],"methods.":[93],"most":[95,113],"methods":[98,192],"require":[99],"numerous":[100],"interactions":[101],"with":[102,157],"examples.":[110],"Given":[111],"enforce":[116],"query":[118,160],"limit,":[119],"this":[120,142],"could":[121],"result":[122],"generating":[124],"non-realistic":[125],"examples":[127],"likely":[130],"be":[132],"detected":[133],"practice":[135],"due":[136],"lack":[138],"stealth.":[140],"In":[141],"study,":[143],"we":[144],"show":[145],"novel":[148],"causal":[150],"language":[151],"model":[152],"enables":[153,207],"single-shot":[154],"evasion":[155,204],"(i.e.,":[156],"only":[158],"one":[159],"detector)":[163],"treating":[165],"content":[167],"executable":[171],"as":[172],"byte":[174],"sequence":[175],"and":[176],"training":[177],"Generative":[179],"Pre-Trained":[180],"Transformer":[181],"(GPT).":[182],"Our":[183],"proposed":[184],"method,":[185],"MalGPT,":[186],"significantly":[187],"outperformed":[188],"leading":[190],"benchmark":[191],"on":[193],"real-world":[195],"dataset":[197],"obtained":[198],"from":[199],"VirusTotal,":[200],"achieving":[201],"over":[202],"24.51%":[203],"rate.":[205],"MalGPT":[206],"cybersecurity":[208],"researchers":[209],"develop":[211],"advanced":[212],"defense":[213],"capabilities":[214],"emulating":[216],"large-scale":[217],"realistic":[218],"AMG.":[219]},"counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":5},{"year":2023,"cited_by_count":4},{"year":2022,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
