A Hybrid CNN–LSTM Deep Learning Framework for Automated Malware Classification using Spatial–Sequential Feature Fusion
Abstract
The high rate of growth of advanced and highly obfuscated malware has made the use of conventional signature detection mechanisms less viable. In order to overcome this problem, this paper suggests a hybrid framework for malware classification based on the combination of Convolutional Neural Networks (CNNs) and Long Short-Term Memory (LSTM) networks to learn spatial and temporal features simultaneously. The given model converts malware feature vectors into structured grayscale representations from which CNN layers extract spatial features, and sequential opcode-related patterns are learned by an LSTM branch. Aspects of both domains are combined into a single embedding and used to classify nine malware families. Tests that have been carried out with a benchmark dataset show that the hybrid CNN-LSTM model attains a classification accuracy of 97.27% which is very high compared to baseline LSTM-only and CNN-only frameworks. The model demonstrates strong generalization, with weighted precision, recall, and F1-score values above 97% and highly discriminative ROC-AUC scores (reaching 1.000 for major classes). An in-depth analysis, such as confusion matrix analysis, precision-recall curves, and a comparison with the state-of-the-art methodologies demonstrate that the proposed architecture achieves performance comparable to that of leading malware detection models reported in recent literature. These findings validate the power of hybrid feature fusion to capture both static and dynamic behavioral traits of malware to provide a powerful, scalable, and highly accurate solution for next-generation cybersecurity systems.