{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:44:19Z","timestamp":1782848659788,"version":"3.54.5"},"reference-count":71,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001809","name":"the National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["625B2139, 62572377, 62302362"],"award-info":[{"award-number":["625B2139, 62572377, 62302362"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Shaanxi Province Natural Science Basic Research Program","award":["2025SYS-SYSZD-081"],"award-info":[{"award-number":["2025SYS-SYSZD-081"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>Machine learning (ML)\u2013based static malware detectors are widely deployed for Portable Executable (PE) files due to their scalability and efficiency, yet they remain vulnerable to carefully crafted adversarial perturbations. Existing black-box evasion methods either rely on transfer attacks, which break down when surrogate and target decision boundaries diverge, or on query-driven searches, which require impractically many queries. We present Flash, a two-phase adversarial framework tailored for static PE malware detection that integrates the strengths of both approaches. In the first phase, a generative adversarial network is trained against heterogeneous surrogate detectors to generate function-preserving PE modifications with inherent evasiveness. In the second phase, an evolutionary optimizer refines these sequences directly against the target model with a dual-objective fitness that balances evasion success and minimal perturbation cost. Experiments on 12,039 VirusShare PE files and six state-of-the-art static detectors demonstrate that Flash reduces query counts by 86% while maintaining bypass rates above 95.8%. Furthermore, adversarial training with Flash-generated samples reduces attack success rates by 82.4%, highlighting Flash\u2019s utility for both exposing vulnerabilities and strengthening the robustness of static PE malware detectors.<\/jats:p>","DOI":"10.1145\/3797132","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"810-831","source":"Crossref","is-referenced-by-count":0,"title":["Flash: Query-Efficient Black-Box Static Malware Evasion through Transferable GAN-Guided Modification Sequences"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0006-3265-4078","authenticated-orcid":false,"given":"Anyuan","family":"Sang","sequence":"first","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0003-2750-7031","authenticated-orcid":false,"given":"Li","family":"Yang","sequence":"additional","affiliation":[{"name":"Xidian University, Shaanxi Key Laboratory of Network and System Security, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-5201-5074","authenticated-orcid":false,"given":"Lu","family":"Zhou","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0009-4286-4003","authenticated-orcid":false,"given":"Junbo","family":"Jia","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0004-1975-8062","authenticated-orcid":false,"given":"Huipeng","family":"Yang","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1801"},{"key":"e_1_2_1_2_1","volume-title":"Evading machine learning malware detection. black Hat 2017","author":"Anderson Hyrum S","year":"2017","unstructured":"Hyrum S Anderson, Anant Kharkar, Bobby Filar, and Phil Roth. 2017. Evading machine learning malware detection. black Hat 2017 (2017), 1-6. https:\/\/2.zoppoz.workers.dev:443\/https\/api.semanticscholar.org\/CorpusID:26406954"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1804.04637"},{"key":"e_1_2_1_4_1","volume-title":"Avast: Free antivirus is your first step to online freedom. https:\/\/2.zoppoz.workers.dev:443\/https\/www.avast.com\/en-in. Accessed: 2025-05-20.","author":"Software Avast","year":"2025","unstructured":"Avast Software. 2025. Avast: Free antivirus is your first step to online freedom. https:\/\/2.zoppoz.workers.dev:443\/https\/www.avast.com\/en-in. Accessed: 2025-05-20."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3664649"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3711899"},{"key":"e_1_2_1_7_1","unstructured":"Ero Carrera. 2025. pefile. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/erocarrera\/pefile. Accessed: 2025-05-20."},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00040"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2022.3142820"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3385003.3410925"},{"key":"e_1_2_1_11_1","unstructured":"Cisco. 2025. ClamAV. https:\/\/2.zoppoz.workers.dev:443\/https\/www.clamav.net\/. Accessed: 2025-05-20."},{"key":"e_1_2_1_12_1","unstructured":"Corvus Forensics. 2025. VirusShare.com -Because Sharing is Caring. https:\/\/2.zoppoz.workers.dev:443\/https\/virusshare.com\/. Accessed: 2025-05-20."},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597926.3598054"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133978"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","unstructured":"Luca Demetrio and Battista Biggio. 2021. secml-malware: A Python Library for Adversarial Robustness Evaluation of Windows Malware Classifiers. arXiv:2104.12848 [cs.CR] doi:10.48550\/arXiv.2104.12848 10.48550\/arXiv.2104.12848","DOI":"10.48550\/arXiv.2104.12848"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1901.03583"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3082330"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3473039"},{"key":"e_1_2_1_19_1","volume-title":"28th USENIX security symposium (USENIX security 19). 321-338. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity19\/ presentation\/demontis","author":"Demontis Ambra","unstructured":"Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019. Why do adversarial attacks transfer? explaining transferability of evasion and poisoning attacks. In 28th USENIX security symposium (USENIX security 19). 321-338. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity19\/ presentation\/demontis"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00957"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00021"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623116"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3638552"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3623320"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103595"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW59978.2023.00052"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103703"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3099122"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2012.07634"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639141"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-19-8991-9_29"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1611.01144"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3711896.3737431"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/NAECON.2017.8268747"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.23919\/EUSIPCO.2018.8553214"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-50127-7_11"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1802.04528"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-86514-6_3"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3003571"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3484491"},{"key":"e_1_2_1_41_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Li Huiying","year":"2022","unstructured":"Huiying Li, Shawn Shan, Emily Wenger, Jiayun Zhang, Haitao Zheng, and Ben Y Zhao. 2022. Blacklight: Scalable defense for neural networks against {Query-Based} {Black-Box} attacks. In 31st USENIX Security Symposium (USENIX Security 22). 2117-2134. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/li-huiying"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00072"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102118"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103134"},{"key":"e_1_2_1_45_1","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Lucas Keane","year":"2023","unstructured":"Keane Lucas, Samruddhi Pai, Weiran Lin, Lujo Bauer, Michael K Reiter, and Mahmood Sharif. 2023. Adversarial training for {Raw-Binary} malware classifiers. In 32nd USENIX Security Symposium (USENIX Security 23). 1163-1180. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/lucas"},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453086"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3547301"},{"key":"e_1_2_1_48_1","unstructured":"Vitaly Morgunov. 2023. IoT-Threat-Report. https:\/\/2.zoppoz.workers.dev:443\/https\/securelist.com\/iot-threat-report-2023\/110644\/. Accessed: 2025-05- 20."},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"e_1_2_1_50_1","volume-title":"Workshops at the thirty-second AAAI conference on artificial intelligence.","author":"Raff Edward","year":"2018","unstructured":"Edward Raff, Jon Barker, Jared Sylvester, Robert Brandon, Bryan Catanzaro, and Charles K Nicholas. 2018. Malware detection by eating a whole exe. In Workshops at the thirty-second AAAI conference on artificial intelligence."},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i11.17131"},{"key":"e_1_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3293959"},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427230"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2025.3556075"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924286"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3497768"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00015"},{"key":"e_1_2_1_58_1","unstructured":"Romain Thomas. 2020. A Command line tool for launching attacks against Machine Learning Malware detectors. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/pralab\/toucanstrike\/. Accessed: 2025-05-20."},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3453047"},{"key":"e_1_2_1_60_1","unstructured":"VirusTotal. 2025. VirusTotal. https:\/\/2.zoppoz.workers.dev:443\/https\/www.virustotal.com\/gui\/home\/upload. Accessed: 2025-05-20."},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/DAC56929.2023.10247858"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/3510003.3510146"},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.3233\/FAIA200388"},{"key":"e_1_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102643"},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103103"},{"key":"e_1_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104280"},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3691620.3695008"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2023.3236901"},{"key":"e_1_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179372"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3797132","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:50:33Z","timestamp":1782845433000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3797132"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":71,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3797132"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3797132","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}