From: LSGAN-AT: enhancing malware detector robustness against adversarial examples
Combination | GM1 (LSGAN) as Attack Model | GM2 (MalGAN) as Attack Model | GM3 (PGD) as Attack Model | ||||||
---|---|---|---|---|---|---|---|---|---|
(Ours) GM1 + RMD1 | GM1 + RMD2 | GM1 + RMD3 | GM2 + RMD1 | GM2 + RMD2 | GM2 + RMD3 | GM3 + RMD1 | GM3 + RMD2 | GM3 + RMD3 | |
Train REC | 65.90 | 38.66 | 52.59 | 56.49 | 51.09 | 52.25 | 71.27 | 65.76 | 68.42 |
Test REC | 65.33 | 40.88 | 51.75 | 52.20 | 51.46 | 51.90 | 69.45 | 64.89 | 68.50 |