Live data from Hacker News

Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

vice.com

1–10 of 60 posts

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#4
The featured article links to an article from Cylance that _does_ actually claim their model could've _theoretically_ detected and flagged malware before its creation.

_"...before the cybercriminals set up the crypto-system, the payment details of the campaign, the C2 infrastructure and before anything else was readied, our model was fully able to predict and prevent that campaign’s malware."_

They claim that a 2015 version of their product _could have_ detected malware that was written in 2016. This conjecture seems plausible but on closer inspection seems to be... speculative. Especially if something like this could undermine it.

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#6
post #3

I literally make customers disable cylance on their servers or we are not guaranteeing servers operations. Too many buggy conflicts.

I can only imagine how completely unreproducible that would make the outcome of literally any operation on client machines.

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#7
The idea that some brogrammers can come along and bang out a disruptor in this area - which has a few decades of extremely complex learning, patents, and optimisation - just because they can cobble together some ML...

It'd be sad if it wasn't so naive.

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#8

The featured article links to an article from Cylance that _does_ actually claim their model could've _theoretically_ detected and flagged malware before its creation. _"...before the cybercriminals set up the crypto-system, the payment details of the campaign, the C2 infrastructure and before anything else was readied, our model was fully able to predict and prevent that campaign’s malware."_ They claim that a 2015…

Old school antiviruses also has heuristics so they could make the same claim.

It wouldn't be true in practice because malware authors would just test their malware against common antiviruses and tweak it before shipping so that the heuristics don't pick it up.

Just like these researches did against their "AI". AI really just meaning "generated heuristics", doesn't it?

If it becomes a problem for malware authors they will make their own "AI" obfuscation generators soon if they haven't already.

They still have the advantage since the "AI" antivirus runs locally, so they can just run tests against it until it doesn't detect, without having to send a large amount of malware samples to the defenders.

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#9
The advertisement take about this product being able to detect the malware two years before it's even written is discernibly turgid. Chuckled well off that.

When will companies selling ML stop making these statements in attempts to whoa people? Like, the claim is ridiculous, how did they even come up with this, ans moreover, what's the possible basis for such a statement? How do they verify that and how would they prove it to anyone asking? It's hugely apparent that it's not even physically possible to pull that move off.

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#10
post #7

The idea that some brogrammers can come along and bang out a disruptor in this area - which has a few decades of extremely complex learning, patents, and optimisation - just because they can cobble together some ML... It'd be sad if it wasn't so naive.

Many ML successes look exactly like that.
Post reply on HN