Table 8 Extra Payload of MalAOI.

From: Evading control flow graph based GNN malware detectors via active opcode insertion method with maliciousness preserving

Adversarial Model

AGFR

AGBR

AGOR

Model Type

Characterization

GCN

Malconv

35.93KB / 953.23KB (3.76%)

60.51 / 1051.41 (60.51%)

7887.08 / 6441.25 (122.44%)

1-Grams

55.85KB / 229.29KB (24.36%)

304.49 / 1683.20 (18.09%)

10613.28 / 8771.40 (121.03%)

2-Grams

11.69KB / 247.65KB (4.72%)

184.25 / 984.73 (18.71%)

2605.26 / 7370.87 (35.34%)

3-Grams

26.20KB / 300.87KB (8.70%)

201.15 / 1047.60 (19.20%)

3580.21 / 7713.63 (46.41%)

GAT

Malconv

47.23KB / 758.74KB (6.22%)

698.95 / 1778.20 (39.30%)

9535.90 / 9971.70 (95.62%)

1-Grams

30.95KB / 472.66KB (6.54%)

554.22 / 1124.00 (49.30%)

7282.00 / 7041.55 (103.41%)

2-Grams

24.52KB / 532.52KB (4.60%)

817.00 / 2570.00 (31.78%)

2113.43 / 5162.66 (40.93%)

3-Grams

2.16KB / 830.48KB (2.16%)

299.09 / 1141.26 (26.20%)

3666.21 / 8490.55 (43.17%)

DGCNN

Malconv

212.88KB / 956.11KB (22.26%)

1115.75 / 1301.25 (85.72%)

13128.50 / 10837.50 (121.13%)

1-Grams

27.65KB / 148.85KB (18.57%)

3545.53 / 1748.23 (202.68%)

40002.43 / 8899.26 (449.51%)

2-Grams

370.74KB / 859.59KB (43.12%)

133.00 / 1327.66 (10.01%)

3797.66 / 5973.00 (63.58%)

3-Grams

21.06KB / 443.94KB (4.74%)

344.57 / 1574.42 (21.88%)

5310.42 / 8532.57 (62.23%)

Average

72.23KB / 561.16KB (12.87%)

688.20 / 1444.33 (47.64%)

9126.86 / 7933.82 (115.03%)