Intriguing Properties of Adversarial ML Problem-Space Attacks


  • May 2020: We'll be presenting the work at IEEE S&P on May 20th ~9am PDT, "see" you there!
  • Mar 2020: Paper accepted at IEEE Symp. Security & Privacy (Oakland) 2020


We are hosting the attack code on a private Bitbucket repository. To get access to the repository, please complete the following form: For ethical reasons, we will only be sharing the code with verified academic researchers.

Universal Adversarial Perturbations for Malware
Raphael Labaca-Castro, Luis Muñoz-González, Feargus Pendlebury, Gabi Dreo Rodosek, Fabio Pierazzi, Lorenzo Cavallaro
CoRR · arXiv CoRR, 2021
Intriguing Properties of Adversarial ML Attacks in the Problem Space
Fabio Pierazzi*, Feargus Pendlebury*, Jacopo Cortellazzi, Lorenzo Cavallaro
IEEE S&P · 41st IEEE Symposium on Security and Privacy, 2020
Feargus Pendlebury presents the work at IEEE Security & Privacy (Oakland) 2020.
Teaser trailer for our presentation at IEEE Security & Privacy (Oakland) 2020.


  • Fabio Pierazzi, Lecturer (Assistant Professor), King's College London.
  • Feargus Pendlebury, Ph.D. Student, King's College London & Royal Holloway, University of London & The Alan Turing Institute
  • Jacopo Cortellazzi, Ph.D. Student, King's College London
  • Lorenzo Cavallaro, Full Professor of Computer Science, Chair in Cybersecurity (Systems Security), King's College London