PhantomCall: Evading ML Malware Detectors via Function Call Graph Perturbation
PhantomCall exploits an overlooked adversarial surface — function call graph manipulation — to bypass ML-based Windows malware classifiers, challenging assumptions about graph-feature robustness.
Summary written by editorial AI · Source link below
arXiv:2609.00705v1 Announce Type: new Abstract: Prior adversarial attacks on Windows PE malware detectors target raw bytes, PE headers, or intra-function control-flow graphs, leaving the function call graph (FCG) unexplored as an attack surface. Yet the FCG structure is an important feature in graph-based malware detectors. We present Phan- tomCall, a black-box attack that perturbs the FCG of Windows PE malware by injecting fully executable dummy functions at targeted call sites, adding new nod
Editorial Analysis
Enterprises investing in ML-driven endpoint detection must account for adversarial evasion techniques that target the very graph structures these detectors rely on.
Request from your EDR vendor an adversarial-robustness assessment specifically covering function-call-graph perturbation attacks.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the Research Desk
- 39 New Methods That Compromise Passkey Authentication3d
- Security Vulnerability in a Voting System3d
- Selfie-Capture Dynamics as an Auxiliary Signal Against Deepfakes and Injection Attacks for Mobile Identity Verification4d
- How Reliable Is the Multi-Input Heuristic for Bitcoin Address Clustering in Law Enforcement Contexts?4d
- Privacy Leakage in Federated Learning: Gradient-Based Client Identity Inference and Defenses for Inertial Sensing in Vehicular Edge Networks4d