TY - GEN
T1 - Black-box Attacks Against Neural Binary Function Detection
AU - Bundt, Joshua
AU - Davinroy, Michael
AU - Agadakos, Ioannis
AU - Oprea, Alina
AU - Robertson, William
N1 - Publisher Copyright:
© 2023 Copyright held by the owner/author(s).
PY - 2023/10/16
Y1 - 2023/10/16
N2 - Binary analyses based on deep neural networks (DNNs), or neural binary analyses (NBAs), have become a hotly researched topic in recent years. DNNs have been wildly successful at pushing the performance and accuracy envelopes in the natural language and image processing domains. Thus, DNNs are highly promising for solving binary analysis problems that are hard due to a lack of complete information resulting from the lossy compilation process. Despite this promise, it is unclear that the prevailing strategy of repurposing embeddings and model architectures originally developed for other problem domains is sound given the adversarial contexts under which binary analysis often operates. In this paper,we empirically demonstrate that the current state of the art in neural function boundary detection is vulnerable to both inadvertent and deliberate adversarial attacks.We proceed from the insight that current generation NBAs are built upon embeddings and model architectures intended to solve syntactic problems. We devise a simple, reproducible, and scalable black-box methodology for exploring the space of inadvertent attacks - instruction sequences that could be emitted by common compiler toolchains and configurations - that exploits this syntactic design focus. We then show that these inadvertent misclassifications can be exploited by an attacker, serving as the basis for a highly effective black-box adversarial example generation process.We evaluate this methodology against two state-of-the-art neural function boundary detectors: XDA and DeepDi. We conclude with an analysis of the evaluation data and recommendations for how future research might avoid succumbing to similar attacks.
AB - Binary analyses based on deep neural networks (DNNs), or neural binary analyses (NBAs), have become a hotly researched topic in recent years. DNNs have been wildly successful at pushing the performance and accuracy envelopes in the natural language and image processing domains. Thus, DNNs are highly promising for solving binary analysis problems that are hard due to a lack of complete information resulting from the lossy compilation process. Despite this promise, it is unclear that the prevailing strategy of repurposing embeddings and model architectures originally developed for other problem domains is sound given the adversarial contexts under which binary analysis often operates. In this paper,we empirically demonstrate that the current state of the art in neural function boundary detection is vulnerable to both inadvertent and deliberate adversarial attacks.We proceed from the insight that current generation NBAs are built upon embeddings and model architectures intended to solve syntactic problems. We devise a simple, reproducible, and scalable black-box methodology for exploring the space of inadvertent attacks - instruction sequences that could be emitted by common compiler toolchains and configurations - that exploits this syntactic design focus. We then show that these inadvertent misclassifications can be exploited by an attacker, serving as the basis for a highly effective black-box adversarial example generation process.We evaluate this methodology against two state-of-the-art neural function boundary detectors: XDA and DeepDi. We conclude with an analysis of the evaluation data and recommendations for how future research might avoid succumbing to similar attacks.
KW - binary analysis
KW - deep neural network
KW - disassembly
KW - function boundary detection
UR - https://www.scopus.com/pages/publications/85175715850
U2 - 10.1145/3607199.3607200
DO - 10.1145/3607199.3607200
M3 - Conference contribution
AN - SCOPUS:85175715850
T3 - ACM International Conference Proceeding Series
SP - 1
EP - 16
BT - Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2023
PB - Association for Computing Machinery
T2 - 26th International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2023
Y2 - 16 October 2023 through 18 October 2023
ER -