{"id":"https://openalex.org/W4409670812","doi":"https://doi.org/10.1145/3696410.3714552","title":"Not All Benignware Are Alike: Enhancing Clean-Label Attacks on Malware Classifiers","display_name":"Not All Benignware Are Alike: Enhancing Clean-Label Attacks on Malware Classifiers","publication_year":2025,"publication_date":"2025-04-22","ids":{"openalex":"https://openalex.org/W4409670812","doi":"https://doi.org/10.1145/3696410.3714552"},"language":"en","primary_location":{"id":"doi:10.1145/3696410.3714552","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714552","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714552","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714552","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5014763916","display_name":"Xutong Wang","orcid":"https://orcid.org/0000-0001-7712-7884"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Xutong Wang","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102366670","display_name":"Yun Feng","orcid":null},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yun Feng","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5117249387","display_name":"Bingsheng Bi","orcid":null},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Bingsheng Bi","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5107888726","display_name":"Y. Cao","orcid":null},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yaqin Cao","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103029944","display_name":"Ze Jin","orcid":"https://orcid.org/0000-0003-3379-5113"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ze Jin","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5093406304","display_name":"Xinyu Liu","orcid":"https://orcid.org/0000-0002-8449-839X"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xinyu Liu","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5031905258","display_name":"Yuling Liu","orcid":"https://orcid.org/0000-0002-2740-9362"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuling Liu","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China and School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I4210165038"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5103325591","display_name":"Yunpeng Li","orcid":"https://orcid.org/0000-0002-5156-889X"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"government","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yunpeng Li","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5014763916"],"corresponding_institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I4210165038"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.08952755,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"2053","last_page":"2063"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9944999814033508,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8708896636962891},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.704831600189209},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.49784326553344727},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.38400039076805115},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.33509477972984314}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8708896636962891},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.704831600189209},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.49784326553344727},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.38400039076805115},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.33509477972984314}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3696410.3714552","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714552","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714552","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3696410.3714552","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714552","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714552","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4409670812.pdf"},"referenced_works_count":30,"referenced_works":["https://openalex.org/W151377110","https://openalex.org/W2046185165","https://openalex.org/W2194775991","https://openalex.org/W2747329762","https://openalex.org/W2807363941","https://openalex.org/W2900587877","https://openalex.org/W2934843808","https://openalex.org/W2964136807","https://openalex.org/W2970335439","https://openalex.org/W2990270730","https://openalex.org/W3034414373","https://openalex.org/W3043789969","https://openalex.org/W3083185154","https://openalex.org/W3090898103","https://openalex.org/W3106196258","https://openalex.org/W3106646114","https://openalex.org/W3114686421","https://openalex.org/W3163186834","https://openalex.org/W3178593045","https://openalex.org/W3209100754","https://openalex.org/W3212023986","https://openalex.org/W3215076255","https://openalex.org/W4302012690","https://openalex.org/W4311165833","https://openalex.org/W4323655037","https://openalex.org/W4382322788","https://openalex.org/W4384948718","https://openalex.org/W4386083011","https://openalex.org/W4390871934","https://openalex.org/W4393160197"],"related_works":["https://openalex.org/W2961085424","https://openalex.org/W4306674287","https://openalex.org/W4387369504","https://openalex.org/W4394896187","https://openalex.org/W3170094116","https://openalex.org/W4386462264","https://openalex.org/W3107602296","https://openalex.org/W4364306694","https://openalex.org/W4312192474","https://openalex.org/W4283697347"],"abstract_inverted_index":{"Machine":[0],"Learning":[1],"(ML)":[2],"based":[3,198],"malware":[4,38,96,109],"classifiers":[5],"are":[6,134],"vulnerable":[7],"to":[8,15,58,114,139,149,207],"exploitation":[9],"during":[10,46],"the":[11,16,25,31,37,44,56,63,84,95,100,104,108,125,150,179,186,222],"training":[12,47],"phase":[13],"due":[14],"necessity":[17],"of":[18,33,72,86,127,174,181,188,227],"regular":[19],"retraining":[20],"with":[21,52],"samples":[22,50],"collected":[23],"from":[24],"wild.":[26],"Recent":[27],"studies":[28],"have":[29,122],"highlighted":[30],"efficacy":[32],"backdoor":[34,77],"attacks":[35,78,117,183],"in":[36,83,94,99,107],"domain,":[39,103],"where":[40],"attackers":[41,113,119],"can":[42],"manipulate":[43],"model":[45,57,106],"by":[48],"injecting":[49],"embedded":[51],"specific":[53],"triggers,":[54],"causing":[55],"establish":[59],"an":[60],"association":[61],"between":[62],"trigger":[64,216],"and":[65,145,184,204,218,224],"a":[66,162],"designated":[67],"class,":[68],"thereby":[69,177],"achieving":[70],"evasion":[71],"detection.":[73],"While":[74],"research":[75],"on":[76,199],"has":[79,90],"been":[80,91],"extensively":[81],"explored":[82],"field":[85],"computer":[87,101],"vision,":[88],"it":[89],"largely":[92],"overlooked":[93],"domain.":[97],"Unlike":[98],"vision":[102],"threat":[105],"domain":[110],"typically":[111],"restricts":[112],"employing":[115],"clean-label":[116,131,189],"(i.e.,":[118],"do":[120],"not":[121],"control":[123],"over":[124],"labeling":[126],"poisoned":[128],"data).":[129],"However,":[130],"attack":[132],"methods":[133,197],"generally":[135],"less":[136],"effective":[137,165],"compared":[138],"those":[140],"that":[141,167],"involve":[142],"embedding":[143],"triggers":[144],"altering":[146],"sample":[147],"labels":[148],"target":[151],"class":[152],"(called":[153],"corrupted-label":[154,182],"attacks).":[155],"To":[156],"address":[157],"this":[158],"limitation,":[159],"we":[160,192],"propose":[161],"simple":[163],"yet":[164],"method":[166],"involves":[168],"Poisoning":[169],"Malware-Similar":[170],"Benignware":[171],"(PMSB)":[172],"instead":[173],"random":[175],"selection,":[176],"approximating":[178],"scenario":[180],"enhancing":[185],"effectiveness":[187],"attacks.":[190],"Additionally,":[191],"introduce":[193],"three":[194,214,219],"similarity":[195],"measurement":[196],"feature-based":[200],"distance,":[201,203],"distribution-based":[202],"contribution-based":[205],"difference":[206],"select":[208],"malware-similar":[209],"benignware.":[210],"Comprehensive":[211],"evaluations":[212],"across":[213],"different":[215],"types":[217],"datasets":[220],"demonstrate":[221],"superiority":[223],"general":[225],"applicability":[226],"PMSB.":[228]},"counts_by_year":[],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
