It is indicated that integrating static and dynamic features at the representation level can improve robustness and classification performance in image-based malware detection, particularly under variations in feature availability.
Abstract
Image-based malware detection has emerged as an alternative to high-dimensional handcrafted feature representations; however, most existing approaches rely primarily on static features or encode multiple features from a single analysis domain, which may limit robustness under code obfuscation and incomplete feature extraction. This paper proposes Hybrid Feature Image Mapping (HFIM), a multi-channel malware visualization technique that integrates structural (binary content), semantic (opcode transitions), and behavioral (API activity) information into a unified RGB representation. HFIM is designed as a representation-level approach that encodes complementary static and dynamic characteristics within a single image, allowing convolutional neural networks (CNNs) to exploit complementary cross-domain patterns while maintaining classification performance when certain feature streams are partially unavailable. HFIM is evaluated against three representative malware imaging methods, HIT4Mal, MC-ISA, and MTV, using seven CNN architectures under identical training conditions to ensure fair comparison and isolate the impact of feature representation. Experimental results based on 10-fold cross-validation demonstrate consistent improvements across multiple evaluation metrics, including accuracy, precision, recall, and F1-score. Additional analyses, including ablation and family-aware evaluation, further indicate that multi-domain integration provides a more discriminative and stable representation than single-domain approaches, particularly under variations in feature availability. These results indicate that integrating static and dynamic features at the representation level can improve robustness and classification performance in image-based malware detection.
Recent studies have shown that binary-to-image representations can enable effective machine learning-based results for malware detection and classification. However, performance can vary significantly, depending on the technique used to convert binaries to images. Furthermore, the explainability and interpretability of...
A compact convolutional neural network architecture integrated with a multi-head attention mechanism to enhance feature discrimination in malware family classification that attains high weighted Precision, Recall, and F1 scores and enhanced macro-averaged performance, particularly enhancing classification for minority...
Mohammed Kasem Al-Bayati· Zanco Journal of Pure and Ap...· 0 citations
A novel hybrid CNN-Hopfield Neural Network (CNN-HNN) framework that replaces traditional dense classification heads with continuous Modern Hopfield associative memory layers is proposed, achieving top-tier accuracy and reducing classification-head parameter counts while reducing floating-point operations (FLOPs) and ac...
Uma Kannan, Rajendran Swamidurai· International journal of res...· 0 citations
The study introduces an innovative approach of deep learning-based hybrid system to classify malware based on its real-time detection using a novel architecture called “Gated Convolutional Embedded Convolutional Network - Bidirectional Long Short-Term Memory (GCE-CNN-BiLSTM)” that integrates both static and dynamic se...
Nishok Kumar S, L. Sheela· Adolescência e Saúde· 0 citations
The findings indicate that combining deep representation learning with ensemble classification can improve dynamic malware detection and reduce dependence on static signatures.
Karthick Ganapathy· Journal of Computer and Fore...· 0 citations