Page 297 - 《软件学报》2026年第4期
P. 297
1738 软件学报 2026 年第 37 卷第 4 期
[43] Xu WL, Qi YJ, Evans D. Automatically evading classifiers: A case study on PDF malware classifiers. In: Proc. of the 2016 NDSS. San
Diego: Internet Society, 2016. [doi: 10.14722/ndss.2016.23115]
[44] Vi BN, Nguyen HN, Nguyen NT, Tran CT. Adversarial examples against image-based malware classification systems. In: Proc. of the
11th Int’l Conf. on Knowledge and Systems Engineering (KSE). Da Nang: IEEE, 2019. 1–5. [doi: 10.1109/KSE.2019.8919481]
[45] Darwaish A, Naït-Abdesselam F, Titouna C, Sattar S. Robustness of image-based Android malware detection under adversarial attacks.
In: Proc. of the 2021 IEEE Int’l Conf. on Communications. Montreal: IEEE, 2021. 1–6. [doi: 10.1109/ICC42927.2021.9500425]
[46] Naeem H, Ullah F, Krejcar O, Alsirhani A, Zhao Y. Adversarial malware detection on consumer devices using optimized image-based
ensembles. IEEE Consumer Electronics Magazine, 2024. 1–10. [doi: 10.1109/MCE.2024.3507282]
[47] Tan K, Zhan DY, Ye L, Zhang HL, Fang BX. A practical adversarial attack against sequence-based deep learning malware classifiers.
IEEE Trans. on Computers, 2024, 73(3): 708–721. [doi: 10.1109/TC.2023.3339955]
[48] Zhang F, Feng RT, Xie XF, Li XH, Shi LS. SeqAdver: Automatic payload construction and injection in sequence-based Android
adversarial attack. In: Proc. of the 2023 IEEE Int’l Conf. on Data Mining Workshops (ICDMW). Shanghai: IEEE, 2023. 1342–1351. [doi:
10.1109/ICDMW60847.2023.00172]
[49] Li H, Cheng Z, Wu B, Yuan LH, Gao CY, Yuan W, Luo XP. Black-box adversarial example attack towards FCG based Android malware
detection under incomplete feature information. In: Proc. of the 32nd USENIX Security Symp. Anaheim: USENIX Association, 2023.
1181–1198.
[50] He P, Xia YF, Zhang XH, Ji SL. Efficient query-based attack against ML-based Android malware detection under zero knowledge
setting. In: Proc. of the 2023 ACM SIGSAC Conf. on Computer and Communications Security. Copenhagen: ACM, 2023. 90–104. [doi:
10.1145/3576915.3623117]
[51] Machado GR, Silva E, Goldschmidt RR. Adversarial machine learning in image classification: A survey toward the defender’s
perspective. ACM Computing Surveys, 2021, 55(1): 8. [doi: 10.1145/3485133]
[52] Xu H, Ma Y, Liu HC, Deb D, Liu H, Tang JL, Jain AK. Adversarial attacks and defenses in images, graphs and text: A review. Int’l
Journal of Automation and Computing, 2020, 17(2): 151–178. [doi: 10.1007/s11633-019-1211-x]
[53] Akhtar N, Mian A. Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access, 2018, 6: 14410–14430.
[doi: 10.1109/ACCESS.2018.2807385]
[54] Papernot N, McDaniel P, Wu X, Jha S, Swami A. Distillation as a defense to adversarial perturbations against deep neural networks. In:
Proc. of the 2016 IEEE Symp. on Security and Privacy (SP). San Jose: IEEE, 2016. 582–597. [doi: 10.1109/SP.2016.41]
[55] Ross A, Doshi-Velez F. Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input
gradients. In: Proc. of the 32nd AAAI Conf. on Artificial Intelligence. New Orleans: AAAI, 2018. 1660–1669. [doi: 10.1609/aaai.v32i1.
11504]
[56] Madry A, Makelov A, Schmidt L, Tsipras D, Vladu A. Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083,
2019.
[57] Vasan D, Alazab M, Wassan S, Naeem H, Safaei B, Zheng Q. IMCFN: Image-based malware classification using fine-tuned
convolutional neural network architecture. Computer Networks, 2020, 171: 107138. [doi: 10.1016/j.comnet.2020.107138]
[58] Yan JQ, Yan GH, Jin D. Classifying malware represented as control flow graphs using deep graph convolutional neural network. In: Proc.
of the 49th Annual IEEE/IFIP Int’l Conf. on Dependable Systems and Networks (DSN). Portland: IEEE, 2019. 52–63. [doi: 10.1109/DSN.
2019.00020]
[59] Ling X, Wu LF, Deng W, Qu ZQ, Zhang JY, Zhang S, Ma TF, Wang B, Wu CM, Ji SL. MalGraph: Hierarchical graph neural networks
for robust windows malware detection. In: Proc. of the 2022 IEEE Conf. on Computer Communications. London: IEEE, 2022.
1998–2007. [doi: 10.1109/INFOCOM48880.2022.9796786]
[60] Belguendouz H, Guerid H, Kaddour M. Static classification of IoT malware using grayscale image representation and lightweight
convolutional neural networks. In: Proc. of the 5th Int’l Conf. on Advanced Communication Technologies and Networking (CommNet).
Marrakech: IEEE, 2022. 1–8. [doi: 10.1109/CommNet56067.2022.9993956]
[61] Jung J, Choi J, Cho S, Han S, Park M, Hwang Y. Android malware detection using convolutional neural networks and data section
images. In: Proc. of the 2018 Conf. on Research in Adaptive and Convergent Systems. Honolulu: ACM, 2018. 149–153. [doi: 10.1145/
3264746.3264780]
[62] He KM, Zhang XY, Ren SQ, Sun J. Deep residual learning for image recognition. In: Proc. of the 2016 IEEE Conf. on Computer Vision
and Pattern Recognition (CVPR). Las Vegas: IEEE, 2016. 770–778. [doi: 10.1109/CVPR.2016.90]
[63] Hochreiter S, Schmidhuber J. Long short-term memory. Neural Computation, 1997, 9(8): 1735–1780. [doi: 10.1162/neco.1997.9.8.1735]
[64] Ling X, Wu LF, Wu CM, Ji SL. Graph neural networks: Graph matching. In: Wu LF, Cui P, Pei J, Zhao L, eds. Graph Neural Networks:

