Trust Under Siege: Label Spoofing Attacks against Machine Learning for Android Malware Detection
Label-spoofing attacks on crowd-sourced AV platforms like VirusTotal can poison ML-based Android malware classifiers, turning a widely trusted data source into an adversarial supply-chain weakness.
Summary written by editorial AI · Source link below
arXiv:2503.11841v2 Announce Type: replace Abstract: Machine Learning (ML) malware detectors rely heavily on crowd-sourced AntiVirus (AV) labels, with platforms like VirusTotal serving as trusted sources of malware annotations. But what if attackers could manipulate these labels to classify benign software as malicious? We introduce label spoofing attacks, a new threat that contaminates crowd-sourced datasets by embedding minimal and undetectable malicious patterns into benign samples. These pat
Editorial Analysis
SOC teams and vendors who train malware classifiers on crowd-sourced AV labels face a supply-chain integrity risk: if adversaries can flip labels at scale, detection accuracy degrades silently.
Audit the label provenance of your malware-detection training data and implement multi-source validation for AV annotations.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the Research Desk
- 39 New Methods That Compromise Passkey Authentication3d
- Security Vulnerability in a Voting System3d
- Selfie-Capture Dynamics as an Auxiliary Signal Against Deepfakes and Injection Attacks for Mobile Identity Verification4d
- How Reliable Is the Multi-Input Heuristic for Bitcoin Address Clustering in Law Enforcement Contexts?4d
- Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks4d