Weaponizing Ground Truth: Data Poisoning Attacks by Exploiting Boundary Misalignment Between Antivirus Software and Learning-Based Detectors
cs.CR
Submitted: 2026-09-25
Updated: 2026-09-25
Code: https://github.com/erocarrera/pefile
Project page: https://virustotal.github.io/yara
Terminology
Sources
- EMBER: An Open Dataset for Training Static PE Malware Machine Learning Models
- SOREL-20M: A Large Scale Benchmark Dataset for Malicious PE Detection
- MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral Models
- Microsoft Malware Classification Challenge
- Malware Detection by Eating a Whole EXE
- The "Beatrix'' Resurrections: Robust Backdoor Detection via Gram Matrices
- Deep Partition Aggregation: Provable Defense against General Poisoning Attacks
- Being Single Has Benefits. Instance Poisoning to Deceive Malware Classifiers
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs