Skip to content
Open access

Hybrid Gce Cnn–Bilstm For Advanced Malware Detection Using Behavioral And Sequential Features

Aug 2026 · Adolescência e Saúde · 0 citations

Abstract

The study introduces an innovative approach of deep learning-based hybrid system to classify malware  based on its real-time detection using a novel architecture called “Gated Convolutional Embedded Convolutional Network - Bidirectional Long Short-Term Memory (GCE-CNN-BiLSTM)” that integrates both static and dynamic sequences of malware (malware)..This system combines two data types for use with malware detection: the first is static characteristics (opcode) and n-grams of the static data (extracted from Portable Executable - PE - files) while the second is log data dynamically created in an environment where the malware was run (i.e., using the Cuckoo Sandbox). The log files contain information on dynamic activities performed by an executable file during execution (such as API calls, changing the registry, performing file system activity) and the static characteristics of the executable binary itself. The proposed system uses a one-dimensional (1D) CNN for localized, binary opcodes to create input sequences containing embedded opcode sequences which will be used by the LSTM to perform binary classification of malware execution; furthermore, a Bidirectional LSTM will be used to capture long-term (temporal) dependencies associated with executable files executed in the malware (opcode) execution flow and execution behaviour. The output from both channels (CNN and Bidirectional LSTM) will be combined and fused together for robustness purposes against obfuscated executables, packed executables, and polymorphic executables. The performance metrics were evaluated using a total of 10,000 labelled malware data samples from the Malimg datasets and 7,500 labelled executable behaviours generated by Cuckoo Sandbox. The accuracy for GCE-CNN-BiLSTM using these datasets was found to be at 98.3% accuracy, 97.8% precision, and 98.1% recall, demonstrating the efficacy of using a hybrid approach for advanced malware detection.

Read PDF

Similar papers

Review Open access Aug 2026

A Survey on Deep Learning Approaches for Malware Detection and Classification

Malware is a serious threat in the cybersecurity area because of its dynamic nature, the variety of malware families, stealth, propagation and the capability of evading traditional security products. Therefore, proper malware detection and classification are crucial for detecting malicious software and for securing com...

Shivani Jain · 0 citations
Open access Jul 2026

AI-Based Adaptive Malware Detection Using Portable Executable (PE) Header Analysis and Hybrid Machine Learning

Experimental results demonstrate that the proposed approach achieves high classification performance while improving transparency in malware detection decisions, making it suitable for practical cybersecurity applications.

V. Padmapriya, S. Uma, S. Sumathi et al. · 0 citations
Sep 2026

A hybrid graph- and sequence-based deep learning framework for behavioral analysis of metamorphic malware

This paper investigates a unified behavioral analysis framework that combines temporal and structural representations of Windows API call sequences: a sequential view based on learned API n-gram representations and a Bidirectional LSTM (BiLSTM) encoder, a structural view derived from the API transition graph, and a mul...

Parisa Golabvand, N. Mikaeilvand, Abbas Mirzaei et al. · 0 citations
Open access Aug 2026

Intelligent malware detection on Android smartphones via a hybrid approach using gradient boosting and convolutional neural network

Evaluation using metrics such as accuracy, precision, F1 score, and false positive rate indicates that CNN-GBM outperforms existing deep learning models, and enhancements stem from the effective integration of CNN feature extraction with GBM’s boosting capabilities.

C. Chimeleze, Norziana Jamil, Z. M. Zain et al. · 0 citations
Jul 2026

Enhanced static analysis framework for multi-class Android malware detection using machine learning

The results have shown how well-engineered static features coupled with overfitting-aware ensemble design can give robust results of multi-class malware classification in the absence of dynamic traces, to develop additional resilience from obfuscation and runtime-evasive threats.

H. Lamkuche, Mannat Pal · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.