Publication: Extending Image-Based Techniques for Certifiably Robust Defense of Malware Classifiers Against Localized Adversarial Example Attacks
dc.contributor.advisor | Mittal, Prateek | |
dc.contributor.author | Lee, Youngseo | |
dc.date.accessioned | 2025-08-12T13:51:23Z | |
dc.date.available | 2025-08-12T13:51:23Z | |
dc.date.issued | 2025-04-14 | |
dc.description.abstract | The fast-evolving nature of malware calls for the development of detection tools that work on attacks that were previously unseen. MalConv, a static classifier built on a convolutional neural network, is a significant step in this direction, but is unable to provide mathematical guarantees of its accuracy on its own. In this project, techniques that defend image classifiers from localized adversarial example attacks and calculate certified accuracy are applied to malware classifiers. In particular, De-Randomized Smoothed MalConv, an existing application of an image-based technique with a small receptive field, is extended for better performance on small files in models I call DRSM2 and PCM. DRSM2 improves DRSM to better utilize its base classifiers for small inputs; PCM applies PatchCleanser, an image-based technique with a large receptive field, to malware detection. Both models outperform the original DRSM, with DRSM2 achieving higher standard and certified accuracies but PCM providing certified accuracies for big perturbation sizes that DRSM2 cannot handle. | |
dc.identifier.uri | https://theses-dissertations.princeton.edu/handle/88435/dsp01p8418r678 | |
dc.language.iso | en_US | |
dc.title | Extending Image-Based Techniques for Certifiably Robust Defense of Malware Classifiers Against Localized Adversarial Example Attacks | |
dc.type | Princeton University Senior Theses | |
dspace.entity.type | Publication | |
dspace.workflow.startDateTime | 2025-04-15T01:13:38.864Z | |
pu.contributor.authorid | 920245496 | |
pu.date.classyear | 2025 | |
pu.department | Electrical and Computer Engineering | |
pu.minor | Robotics |
Files
Original bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- Lee_Youngseo.pdf
- Size:
- 2.6 MB
- Format:
- Adobe Portable Document Format
License bundle
1 - 1 of 1
No Thumbnail Available
- Name:
- license.txt
- Size:
- 100 B
- Format:
- Item-specific license agreed to upon submission
- Description: