Systematic Denial-of-Service Attacks Against Dynamic Malware Analysis

Investigate whether evasion of both the signature-based and static machine-learning levels of a Compound AI System for Windows malware detection can be systematically exploited to mount Denial-of-Service attacks that overload the dynamic analysis level and convert a robustness weakness into an availability vulnerability.

Background

The paper shows that adversarial Windows executable modifications that bypass the signature and static-analysis levels are more likely to reach the dynamic analysis stage, which is the most computationally expensive component of the OBELISK Compound AI System. Such attacks increase inference time even when they do not fully evade the system’s final decision.

The authors identify a possible availability consequence: an attacker might deliberately force a sufficiently large number of samples through dynamic analysis and thereby overload the emulator or associated computational resources. Whether this behavior can be exploited systematically as a Denial-of-Service attack is left unresolved and is explicitly identified as future work.

References

We will investigate whether this behavior can be exploited systematically to mount Denial-of-Service (DoS) attacks that overload the dynamic level, turning a robustness weakness into an availability one.

Windows Malware Detector as a Compound AI System: Trade-Offs in Accuracy, Efficiency, and Adversarial Robustness  (2609.08394 - Ponte et al., 8 Sep 2026) in Section “Future Work and Conclusions,” subsection “Future Work”