Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageResearch Desk
Research

PhantomCall: Evading ML Malware Detectors via Function Call Graph Perturbation

PhantomCall exploits an overlooked adversarial surface — function call graph manipulation — to bypass ML-based Windows malware classifiers, challenging assumptions about graph-feature robustness.

Summary written by editorial AI · Source link below

Filed by arXiv Crypto & Security1 min readRead at source ↗

arXiv:2609.00705v1 Announce Type: new Abstract: Prior adversarial attacks on Windows PE malware detectors target raw bytes, PE headers, or intra-function control-flow graphs, leaving the function call graph (FCG) unexplored as an attack surface. Yet the FCG structure is an important feature in graph-based malware detectors. We present Phan- tomCall, a black-box attack that perturbs the FCG of Windows PE malware by injecting fully executable dummy functions at targeted call sites, adding new nod

Editorial Analysis

Why it matters

Enterprises investing in ML-driven endpoint detection must account for adversarial evasion techniques that target the very graph structures these detectors rely on.

What to do

Request from your EDR vendor an adversarial-robustness assessment specifically covering function-call-graph perturbation attacks.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at arXiv Crypto & Security

External link — opens at arXiv Crypto & Security in a new tab.

§
Continue with

More from the Research Desk