Skip to main content
Evaluating the Robustness of a Production Malware Detection System to Transferable Adversarial Attacks
  1. publications
  2. ai

Evaluating the Robustness of a Production Malware Detection System to Transferable Adversarial Attacks

Available Media Publication (PDF)
Conference ACM SIGSAC Conference on Computer and Communications Security (CCS) - 2025
Authors Milad Nasr , Yanick Fratantonio , Luca Invernizzi ,
Citation BibTeX
BibTeX
@inproceedings{Nasr2025Evaluating,
  title = {Evaluating the Robustness of a Production Malware Detection System to Transferable Adversarial Attacks},
  author = {Milad Nasr and Yanick Fratantonio and Luca Invernizzi and Ange Albertini and Loua Farah and Alex Petit-Bianco and Andreas Terzis and Kurt Thomas and Elie Bursztein and Nicholas Carlini},
  booktitle = {ACM SIGSAC Conference on Computer and Communications Security},
  year = {2025},
  organization = {ACM}
}

A machine-learning component can become a weak point in a larger security system even when other components continue to work as designed. This paper studies that risk in Gmail, where Magika identifies attachment types and routes files to specialized malware detectors.

Adversarial changes to the file-type model can send a malicious attachment to an unsuitable scanner. The paper evaluates this system-level failure mode, develops a defense and measures its effect on attack success. The resulting mitigation was deployed in Gmail.

See also Magika, the file-type detection model examined in this study.

newsletter signup
newsletter signup