Table 6 Attack Success Rate of MalAOI and baselines for different detection models.

From: Evading control flow graph based GNN malware detectors via active opcode insertion method with maliciousness preserving

Adversarial Model

MalAOI

GNN-based Gym-malware

FRI1

FRI2

FAI

epoch

Model Type

Characterization

100

GCN

Malconv

443 / 500 (88.60%)

21 / 500 (4.20%)

201 / 500 (40.20%)

211 / 500 (42.20%)

284 / 500 (56.80%)

1-Grams

432 / 500 (86.40%)

17 / 500 (3.40%)

194 / 500 (38.80%)

201 / 500 (40.20%)

263 / 500 (52.60%)

2-Grams

485 / 500 (97.00%)

19 / 500 (3.80%)

192 / 500 (38.40%)

192 / 500 (38.40%)

288 / 500 (57.60%)

3-Grams

482 / 500 (96.30%)

25 / 500 (5.00%)

152 / 500 (30.40%)

192 / 500 (38.40%)

272 / 500 (54.40%)

GAT

Malconv

450 / 500 (90.00%)

12 / 500 (2.40%)

212 / 500 (42.30%)

232 / 500 (46.40%)

272 / 500 (54.40%)

1-Grams

432 / 500 (86.40%)

18 / 500 (3.60%)

216 / 500 (43.20%)

213 / 500 (42.60%)

268 / 500 (53.60%)

2-Grams

465 / 500 (93.00%)

24 / 500 (4.80%)

200 / 500 (40.00%)

207 / 500 (41.40%)

282 / 500 (56.40%)

3-Grams

463 / 500 (92.60%)

16 / 500 (3.20%)

180 / 500 (36.00%)

186 / 500 (37.20%)

250 / 500 (50.00%)

DGCNN

Malconv

464 / 500 (92.80%)

8 / 500 (1.60%)

201 / 500 (40.20%)

212 / 500 (42.40%)

291 / 500 (58.20%)

1-Grams

467 / 500 (93.40%)

15 / 500 (3.00%)

203 / 500 (40.60%)

209 / 500 (41.80%)

289 / 500 (59.80%)

2-Grams

471 / 500 (94.20%)

13 / 500 (2.60%)

185 / 500 (37.00%)

231 / 500 (46.20%)

279 / 500 (55.80%)

3-Grams

429 / 500 (85.80%)

16 / 500 (3.20%)

157 / 500 (31.40%)

205 / 500 (41.00%)

280 / 500 (56.00%)

300

GCN

Malconv

479 / 500 (95.80%)

13 / 500 (2.60%)

232 / 500 (46.40%)

229 / 500 (45.80%)

302 / 500 (60.40%)

1-Grams

483 / 500 (96.60%)

7 / 500 (1.40%)

261 / 500 (52.20%)

216 / 500 (43.20%)

289 / 500 (57.80%)

2-Grams

478 / 500 (95.60%)

10 / 500 (2.00%)

203 / 500 (40.60%)

199 / 500 (39.80%)

277 / 500 (55.40%)

3-Grams

467 / 500 (93.40%)

28 / 500 (5.60%)

194 / 500 (38.80%)

201 / 500 (40.20%)

254 / 500 (50.80%)

GAT

Malconv

481 / 500 (96.20%)

16 / 500 (3.20%)

221 / 500 (44.20%)

245 / 500 (49.00%)

291 / 500 (58.10%)

1-Grams

491 / 500 (98.20%)

18 / 500 (3.60%)

247 / 500 (49.40%)

223 / 500 (44.60%)

275 / 500 (51.00%)

2-Grams

496 / 500 (99.20%)

11 / 500 (2.20%)

235 / 500 (47.00%)

207 / 500 (41.40%)

292 / 500 (58.40%)

3-Grams

461 / 500 (92.20%)

21 / 500 (4.20%)

186 / 500 (39.20%)

201 / 500 (40.20%)

249 / 500 (49.80%)

DGCNN

Malconv

463 / 500 (92.60%)

15 / 500 (3.00%)

196 / 500 (39.20%)

229 / 500 (45.80%)

282 / 500 (56.40%)

1-Grams

494 / 500 (98.80%)

13 / 500 (2.60%)

215 / 500 (43.00%)

202 / 500 (40.40%)

314 / 500 (62.80%)

2-Grams

491 / 500 (98.20%)

12 / 500 (2.40%)

222 / 500 (44.40%)

216 / 500 (43.20%)

293 / 500 (58.60%)

3-Grams

481 / 500 (96.20%)

19 / 500 (2.80%)

177 / 500 (35.40%)

193 / 500 (38.60%)

248 / 500 (49.60%)

Average

11248 / 12000 (93.73%)

387 / 12000 (3.22%)

4882 / 12000 (40.68%)

5052 / 12000 (42.10%)

6684 / 12000 (55.70%)