Generating End-to-End Adversarial Examples for Malware Classifiers Using Explainability
Authors:
Ishai Rosenberg,
Shai Meir,
Jonathan Berrebi,
Ilay Gordon,
Guillaume Sicard,
Eli David
Abstract:
In recent years, the topic of explainable machine learning (ML) has been extensively researched. Up until now, this research focused on regular ML users use-cases such as debugging a ML model. This paper takes a different posture and show that adversaries can leverage explainable ML to bypass multi-feature types malware classifiers. Previous adversarial attacks against such classifiers only add ne…
▽ More
In recent years, the topic of explainable machine learning (ML) has been extensively researched. Up until now, this research focused on regular ML users use-cases such as debugging a ML model. This paper takes a different posture and show that adversaries can leverage explainable ML to bypass multi-feature types malware classifiers. Previous adversarial attacks against such classifiers only add new features and not modify existing ones to avoid harming the modified malware executable's functionality. Current attacks use a single algorithm that both selects which features to modify and modifies them blindly, treating all features the same. In this paper, we present a different approach. We split the adversarial example generation task into two parts: First we find the importance of all features for a specific sample using explainability algorithms, and then we conduct a feature-specific modification, feature-by-feature. In order to apply our attack in black-box scenarios, we introduce the concept of transferability of explainability, that is, applying explainability algorithms to different classifiers using different features subsets and trained on different datasets still result in a similar subset of important features. We conclude that explainability algorithms can be leveraged by adversaries and thus the advocates of training more interpretable classifiers should consider the trade-off of higher vulnerability of those classifiers to adversarial attacks.
△ Less
Submitted 1 June, 2022; v1 submitted 28 September, 2020;
originally announced September 2020.
Whos Ditching the Bus?
Authors:
Simon J. Berrebi,
Kari E. Watkins
Abstract:
This paper uses stop-level passenger count data in four cities to understand the nation-wide bus ridership decline between 2012 and 2018. The local characteristics associated with ridership change are evaluated in Portland, Miami, Minneapolis/St-Paul, and Atlanta. Poisson models explain ridership as a cross-section and the change thereof as a panel. While controlling for the change in frequency, j…
▽ More
This paper uses stop-level passenger count data in four cities to understand the nation-wide bus ridership decline between 2012 and 2018. The local characteristics associated with ridership change are evaluated in Portland, Miami, Minneapolis/St-Paul, and Atlanta. Poisson models explain ridership as a cross-section and the change thereof as a panel. While controlling for the change in frequency, jobs, and population, the correlation with local socio-demographic characteristics are investigated using data from the American Community Survey. The effect of changing neighborhood demographics on bus ridership are modeled using Longitudinal Employer-Household Dynamics data. At a point in time, neighborhoods with high proportions of non-white, carless, and most significantly, high-school-educated residents are the most likely to have high ridership. Over time, white neighborhoods are losing the most ridership across all four cities. In Miami and Atlanta, places with high concentrations of residents with college education and without access to a car also lose ridership at a faster rate. In Minneapolis/St-Paul, the proportion of college-educated residents is linked to ridership gain. The sign and significance of these results remain consistent even when controlling for intra-urban migration. Although bus ridership is declining across neighborhood characteristics, these results suggest that the underlying cause of bus ridership decline must be primarily affecting the travel behavior of white bus riders.
△ Less
Submitted 11 March, 2020; v1 submitted 7 January, 2020;
originally announced January 2020.