ResearchPod Summary
Machine-learning-based Android malware detectors are increasingly vulnerable to adversarial attacks. While previous research has attempted to craft adversarial APKs by modifying their components (problem-space attacks), these methods often suffer from significant practical limitations. Many techniques rely on coarse-grained software transplantation, which injects large, unnecessary code segments that frequently cause build-time failures or introduce unintended side effects. Other, more fine-grained methods often produce syntactically valid but semantically broken applications. Furthermore, prior studies have often overestimated their success rates by using inadequate testing procedures that fail to verify whether the modified malware actually retains its original malicious functionality.
To address these challenges, the authors introduce DroidBreaker, a framework designed to produce practical and functional adversarial APKs. The framework is built on three core pillars:
The authors evaluated DroidBreaker against four distinct machine-learning detectors and a suite of commercial scanners on VirusTotal. The results demonstrate that DroidBreaker consistently achieves high evasion rates while maintaining the intended malicious behavior of the original applications. By minimizing side effects and ensuring semantic preservation, the framework provides a more realistic and scalable approach to testing the robustness of Android malware detection systems.
AI-generated third-party summary by ResearchPod. Not official content or an endorsement by the paper authors or affiliated organizations.