cd /news/machine-learning/replicant-learning-policies-for-evad… · home topics machine-learning article
[ARTICLE · art-116223] src=machinebrief.com ↗ pub= topic=machine-learning verified=true sentiment=· neutral

REPLICANT: Learning Policies for Evading and Hardening Malware Detectors

Researchers introduced Replicant, a deep reinforcement learning framework that learns to evade Android malware detectors under a strict label-only black-box threat model, achieving a mean attack success rate of 78.8% across seven detectors and three feature spaces, a relative improvement of 20.9%-39.2% over state-of-the-art attacks. The framework also outperforms existing methods in adversarial training, producing detectors with more generalizable robustness, demonstrating that learning evasion provides a better signal for hardening malware detectors.

read1 min views1 publishedAug 31, 2026

arXiv:2608.28499v1 Announce Type: new Abstract: To determine the real-world effectiveness of machine learning based malware detection, it is vital to evaluate its robustness against highly capable adversaries. However, state-of-the-art attacks do not effectively model realistic adversaries, as they often assume access to privileged information such as the training data, feature space, or confidence scores of the target. In this work, we present Replicant, a deep reinforcement learning framework that learns the realistic task of evasion under a strict label-only black-box threat model. Replicant learns a reusable policy on how to modify a malware sample and when to query the target, which transfers across samples, detectors, and feature spaces. Across seven Android malware detectors and three feature spaces, Replicant is the strongest and most query-efficient approach achieving a mean attack success rate of 78.8%, a relative improvement of 20.9%-39.2% over the state-of-the-art. Furthermore, when used for adversarial training, Replicant also outperforms the state-of-the art by producing detectors with more generalizable robustness. With Replicant we demonstrate that learning the task of evasion not only results in stronger attack performance but, crucially, provides a better signal for hardening malware detectors.

── more in #machine-learning 4 stories · sorted by recency
── more on @replicant 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/replicant-learning-p…] indexed:0 read:1min 2026-08-31 ·