Ítem
Acceso Abierto
Using Generative Adversarial Networks (GAN) to detect Cyber Threats
Título de la revista
Autores
Posada, Ariel
Sepulveda, Juan Nicolás
Alférez, Santiago
Díaz López, Daniel Orlando
Fecha
2024-04-26
Directores
ISSN de la revista
Título del volumen
Editor
Universidad del Rosario
Buscar en:
Métricas alternativas
Resumen
En esta presentación se explora el uso de redes neuronales y GAN para detectar amenazas cibernéticas, especificamente malware ofuscado. La propuesta descrita transforma archivos binarios en imágenes en escala de grises y emplea modelos convolucionales como ResNet y EfficientNet para clasificarlas como goodware o malware. Posteriormente, se construyen conjuntos de datos con programas legítimos de Microsoft Store y muestras de VirusShare, incluyendo variantes ofuscadas mediante XOR y Shikata Ga Nai. También se presenta una GAN condicional cuyo generador crea imágenes sintéticas de distintas clases, mientras un discriminador basado en ResNet-18 evalúa si son reales o falsas y si corresponden a software benigno o malicioso. Los resultados muestran precisiones similares entre el entrenamiento tradicional y el basado en GAN, sin embargo, las imágenes generadas aumentan la diversidad del conjunto de datos aumentando así la consistencia de los resultados. Como trabajo futuro se propone incorporar malware contextualizado, ampliar la generación sintética y fortalecer la detección de amenazas avanzadas.
Abstract
This presentation explores the use of neural networks and GANs to detect cyber threats, particularly obfuscated malware. The proposed method converts binary files into grayscale images and uses convolutional models such as ResNet and EfficientNet to classify them as goodware or malware. The datasets include legitimate applications from the Microsoft Store and malware samples from VirusShare, with obfuscated variants created using XOR and Shikata Ga Nai. A conditional GAN is also introduced: its generator produces synthetic images from different classes, while a ResNet-18-based discriminator determines whether they are real or fake and benign or malicious. The results show similar accuracy between traditional and GAN-based training; however, the generated images increase the diversity of the dataset, thus improving the consistency of the results. Future work includes collecting context-specific malware, expanding synthetic image generation, and improving the detection of advanced threats designed to evade security systems.
Palabras clave
Redes neuronales convolucionales , CNN , Ciber amenazas , Redes adversariales generativas , GAN , Ciberseguridad
Keywords
Convolutional neural networks , CNNs , Cyber threats , Generative adversarial networks , GANs , Cybersecurity




