Skip to content
Preprint

PhantomCall: Evading ML Malware Detectors via Function Call Graph Perturbation

Sep 2026 · 0 citations · 81 references
Computer Science

TL;DR

Phan- tomCall is presented, a black-box attack that perturbs the FCG of Windows PE malware by injecting fully executable dummy functions at targeted call sites, adding new nodes and edges to both the CFG and FCG while preserving program semantics.

Abstract

Prior adversarial attacks on Windows PE malware detectors target raw bytes, PE headers, or intra-function control-flow graphs, leaving the function call graph (FCG) unexplored as an attack surface. Yet the FCG structure is an important feature in graph-based malware detectors. We present Phan- tomCall, a black-box attack that perturbs the FCG of Windows PE malware by injecting fully executable dummy functions at targeted call sites, adding new nodes and edges to both the CFG and FCG while preserving program semantics. We pair this structural perturbation with classifier-guided search and tunable injection parameters, effective across three archi- tecturally distinct classifiers. Evaluated on a 2025-collected Windows malware corpus against MalConv (raw-byte CNN), MalGraph (graph-based GNN), and SAFE+GNN (pure FCG GNN trained from scratch on a 2024 corpus) at two FPR thresholds, the best PhantomCall variant achieves 85-100% attack success rate across all configurations, exceeding prior state-of-the-art by up to 14.78 percentage points on MalGraph and 95.5 percentage points on SAFE+GNN, and generating evasive variants up to 2.9x faster on average across all targets. For MalConv and MalGraph, the majority of evasions require only a single call site modification, and 86-97% of evaluated evasive variants preserve the original malicious behavior in sandbox-based semantic testing across all configurations.

View source

Similar papers

Open access Sep 2026

Metamorphic Malware Detection via Graph-Augmented Neural Semantics and Adversarial Hardening: A Comprehensive Framework

Background: Metamorphic malware is among the most persistent adversarial challenges in cybersecurity: it rewrites its own instruction stream on every propagation, preserving functional semantics while presenting a syntactically distinct binary that defeats signature-based and many learning-based detectors. Methods: We...

Víctor Manuel González-Gorrín, Josep Prieto-Blázquez · 0 citations
#machine learning Preprint Sep 2026

Delphi Scanner: efficient and interpretable static malware detection via API sequence modeling

Static malware detection for Windows Portable Executable files demands a careful balance between detection effectiveness, computational efficiency, and analytical interpretability. This paper introduces Delphi Scanner, a static malware detection system for Windows PE files that balances efficiency with behavioral inter...

Bijied Brahimi, Vincent Cohadon, Gabriel Glazman et al. · 0 citations
Conference Open access Sep 2026

GRASP: Hard-Label Black-Box Malware Evasion with Higher Success, Fewer Queries, and Smaller Perturbations

Gradient-seeded Reinforcement Learning And Stealthy Pruning (GRASP), a three-stage framework that tackles challenges of adversarial attacks on machine learning-based malware detectors, and out-performs baselines, achieving higher attack success with fewer queries and smaller file-size inflation.

Yu-Tong Liu, Jian-Ting Ning, Qi Feng et al. · 1 citation
Preprint Sep 2026

Breaking Windows Malware Detection: A Comprehensive Evaluation of Problem-Space Adversarial Robustness

Problem-space evasion attacks have exposed critical weaknesses in machine learning-based malware detectors; yet, their evaluation remains fragmented across models, datasets, and attack methodologies, often neglecting domain-specific requirements such as executability and functionality preservation. We address this gap...

Mashal Zainab, Salijona Dyrmishi, Hamid Bostani et al. · 0 citations
#machine learning Preprint Aug 2026

REPLICANT: Learning Policies for Evading and Hardening Malware Detectors

This work presents Replicant, a deep reinforcement learning framework that learns the realistic task of evasion under a strict label-only black-box threat model and demonstrates that learning the task of evasion not only results in stronger attack performance but provides a better signal for hardening malware detectors...

Shae McFadden, Ilias Tsingenopoulos, Mario D'Onghia et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.