{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/115674"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/115674","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Machine learning in the hands of a malicious adversary: A study on ML-driven malware","abstract":"Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2024-05-01","abstract_html":"Submission published under a 24 month embargo labeled &#x27;Closed Access&#x27;, the embargo will last until 2024-05-01","abstract_has_math":false,"creators":["Chung, Keywhan"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Iyer, Ravishankar K","Kalbarczyk, Zbigniew T","Nicol, David M","Bailey, Michael D","Bates, Adam","Wang, Gang"],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2022,"date_issued":"2022-05","date_published":"2022-05","updated_at":"2026-07-22T22:24:54Z","subjects":["cyber security","machine learning","malware"],"languages":["en","eng"],"rights":["Copyright 2022 Keywhan Chung"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/2142/115674","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Iyer, Ravishankar K","Kalbarczyk, Zbigniew T","Nicol, David M","Bailey, Michael D","Bates, Adam","Wang, Gang"]},{"key":"dc:creator","label":"Author","values":["Chung, Keywhan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2022-05","2022-03-31"]},{"key":"dc:type","label":"Dc Type","values":["text","Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["cyber security","machine learning","malware"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en","eng"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2022 Keywhan Chung"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["https://hdl.handle.net/2142/115674"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2024-05-01","The student, Keywhan Chung, accepted the attached license on 2022-03-28 at 15:36.","The student, Keywhan Chung, submitted this Dissertation for approval on 2022-03-28 at 15:45.","This Dissertation was approved for publication on 2022-03-31 at 13:21.","DSpace SAF Submission Ingestion Package generated from Vireo submission #17550 on 2022-11-11 at 12:18:47","Targeted and sophisticated cyber threats are on the rise. To maximize efficiency, attackers spend significant amounts of time preparing attacks (e.g., reconnaissance, weaponization, and exploitation). However, an extended foothold into a system often leaves a trace that a well-prepared security team can use to track the attacker. Furthermore, unlike malware which automatically spread across systems (even systems that are air-gapped from the public network), targeted attacks were restricted by their need of remote access to the victim system (i.e., so that the attacker can investigate the target system and customize the attack accordingly). In this dissertation, we describe an unforeseen class of threat, ML-driven malware, and demonstrate its impact on variations of critical cyber infrastructure (e.g., smart building automation system, medical robot, or large computing infrastructure). At the early research stage, we showcased two analytics-driven malware that were machine-controlled but human-driven. By gradually increasing the level of automation, we demonstrated that our malware, substantially independent of the attacker, can autonomously monitor the victim, develop the function to infer an attack strategy, and execute the payload at its most opportune time. In enabling this threat, we deployed an ensemble of learning methods to adapt to the dynamics of the victim system and fine-tune the malware. As a result, our malware achieved its malicious intent of accelerating data exfiltration while remaining under the radar of monitoring systems. Furthermore, we evaluated the impact of the attack payload inferred by the ML-driven malware in either a simulated environment or a testbed running inside a production system. To make things worse, our experiments showed that attackers can alter the learning algorithms to reduce traces introduced by adopting such sophisticated techniques. With ML-driven malware installed, an attacker might no longer need to maintain a foothold in a target system, but can let malware automatically reconnoiter the victim and internally weaponize the attack while leaving minimal traces. Also, as we demonstrate in variations of critical computing infrastructure, such an ML-driven malware can benefit from intelligence collected from other victims, and morph its form and adjust behavior to fit to the details of each victim. No document yet report the existence of a real-threat with such capability. However, the results from our research show that it is feasible to implement ML-driven malware which can operate under the radar of a security monitoring system with minimal resource usage, and is self-learning to a significant degree. In addition to demonstrating this new threat, we share our insights on ML-driven malware and its limitation to promote further research on this new problem, and, hence, be prepared when this becomes a reality."]},{"key":"dc:format","label":"Dc Format","values":["application/pdf"]},{"key":"dc:title","label":"Title","values":["Machine learning in the hands of a malicious adversary: A study on ML-driven malware"]}]}],"canonical_facts":{"dc:contributor":["Iyer, Ravishankar K","Kalbarczyk, Zbigniew T","Nicol, David M","Bailey, Michael D","Bates, Adam","Wang, Gang"],"dc:creator":["Chung, Keywhan"],"dc:date":["2022-05","2022-03-31"],"dc:description":["Submission published under a 24 month embargo labeled 'Closed Access', the embargo will last until 2024-05-01","The student, Keywhan Chung, accepted the attached license on 2022-03-28 at 15:36.","The student, Keywhan Chung, submitted this Dissertation for approval on 2022-03-28 at 15:45.","This Dissertation was approved for publication on 2022-03-31 at 13:21.","DSpace SAF Submission Ingestion Package generated from Vireo submission #17550 on 2022-11-11 at 12:18:47","Targeted and sophisticated cyber threats are on the rise. To maximize efficiency, attackers spend significant amounts of time preparing attacks (e.g., reconnaissance, weaponization, and exploitation). However, an extended foothold into a system often leaves a trace that a well-prepared security team can use to track the attacker. Furthermore, unlike malware which automatically spread across systems (even systems that are air-gapped from the public network), targeted attacks were restricted by their need of remote access to the victim system (i.e., so that the attacker can investigate the target system and customize the attack accordingly). In this dissertation, we describe an unforeseen class of threat, ML-driven malware, and demonstrate its impact on variations of critical cyber infrastructure (e.g., smart building automation system, medical robot, or large computing infrastructure). At the early research stage, we showcased two analytics-driven malware that were machine-controlled but human-driven. By gradually increasing the level of automation, we demonstrated that our malware, substantially independent of the attacker, can autonomously monitor the victim, develop the function to infer an attack strategy, and execute the payload at its most opportune time. In enabling this threat, we deployed an ensemble of learning methods to adapt to the dynamics of the victim system and fine-tune the malware. As a result, our malware achieved its malicious intent of accelerating data exfiltration while remaining under the radar of monitoring systems. Furthermore, we evaluated the impact of the attack payload inferred by the ML-driven malware in either a simulated environment or a testbed running inside a production system. To make things worse, our experiments showed that attackers can alter the learning algorithms to reduce traces introduced by adopting such sophisticated techniques. With ML-driven malware installed, an attacker might no longer need to maintain a foothold in a target system, but can let malware automatically reconnoiter the victim and internally weaponize the attack while leaving minimal traces. Also, as we demonstrate in variations of critical computing infrastructure, such an ML-driven malware can benefit from intelligence collected from other victims, and morph its form and adjust behavior to fit to the details of each victim. No document yet report the existence of a real-threat with such capability. However, the results from our research show that it is feasible to implement ML-driven malware which can operate under the radar of a security monitoring system with minimal resource usage, and is self-learning to a significant degree. In addition to demonstrating this new threat, we share our insights on ML-driven malware and its limitation to promote further research on this new problem, and, hence, be prepared when this becomes a reality."],"dc:format":["application/pdf"],"dc:identifier":["https://hdl.handle.net/2142/115674"],"dc:language":["en","eng"],"dc:rights":["Copyright 2022 Keywhan Chung"],"dc:subject":["cyber security","machine learning","malware"],"dc:title":["Machine learning in the hands of a malicious adversary: A study on ML-driven malware"],"dc:type":["text","Thesis"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:24:54Z"}