Skip to content
Open access

Deep Learning for Malware Detection: TransformerBased Analysis of Windows Executables

Aug 2026 · “Kibertəhlükəsizlik və rəqəmsal kriminalistikanın aktual problemləri” respublika elmi-praktiki konfransı · 0 citations

TL;DR

A Transformerbased deep learning approach for detecting malicious Windows Portable Executable files is presented, significantly outperforming baseline methods including LightGBM, MalConv, and LSTM.

Abstract

Malware detection is challenged by unprecedented threats exceeding 560,000 new variants daily. A Transformerbased deep learning approach for detecting malicious Windows Portable Executable files is presented. Raw byte sequences are processed using self-attention mechanisms, eliminating manual feature engineering. A multi-modal framework combining raw bytes, PE metadata, and entropy features is implemented. Through experimental evaluation on EMBER2024 (3.2M samples) and SOREL-20M (20M samples), 95.1% accuracy with 0.4% false positive rate is demonstrated, significantly outperforming baseline methods including LightGBM (92.7%), MalConv (93.4%), and LSTM approaches (91.8%). Explainability for forensic analysis is provided through attention visualization.

Read PDF

Similar papers

Open access Jul 2026

A Robust Deep Learning Framework for Intelligent Malware Detection

Malware has become one of the biggest threats to computer systems and digital networks, affecting individuals, businesses, and government organizations. Traditional malware detection methods mainly depend on signatures and predefined rules, making them less effective against newly developed and constantly evolving atta...

S.Srikar, G.Rajini · 0 citations
Open access Aug 2026

XEnDroid: Explainable Stacking Ensemble Learning for Dynamic Android Malware Detection

XEnDroid (Xplainable Ensemble Droid), an advanced stacking ensemble approach for detecting malware on Android phones by combining random forest, convolution neural network, and transformer models under a logistic regression model is proposed.

M. B., V. R, Surjith K. et al. · 0 citations
Open access 2026

MalBERT-Temporal: Transformer-Based Zero-Day Malware Detection in Windows Executable Binaries Under Strict Temporal Isolation

A Transformer-based malware detection approach named MalBERT-Temporal that reshapes the 2,381-dimensional BODMAS PE feature vector into 16 contiguous feature-group tokens and then processes these tokens with Transformer encoder layers employing multi-head self-attention to model interactions among all tokens is introdu...

Manar Alanazi, Israa Alsiyat · 0 citations
Review Open access Aug 2026

A Survey on Deep Learning Approaches for Malware Detection and Classification

Malware is a serious threat in the cybersecurity area because of its dynamic nature, the variety of malware families, stealth, propagation and the capability of evading traditional security products. Therefore, proper malware detection and classification are crucial for detecting malicious software and for securing com...

Shivani Jain · 0 citations
Open access Jul 2026

Intelligent Android Malware Classification Using Equilibrium Optimizer and Deep LearningModel

An intelligent Android malware detection framework that combines deep learning with the Equilibrium Optimizer to improve detection performance is presented, providing an effective and reliable solution for securing Android devices against evolving malware threats.

Aishwarya Eklar, G.Rajini · 0 citations
Conference Aug 2026

Comparative Performance Analysis of Machine Learning Models for Binary Classification of Fileless Malwares Using Volatile Memory Forensics

Fileless Malware is one of the fastest-evolving and hardest-to-detect types of malware. The malware resides solely within System Memory and never uses typical files as its payload. Fileless malware can utilize legitimate software like PowerShell and WMI, along with LOLBins to remain completely hidden in System Memory,...

S. R., G. S, Hriday Kumar Gupta et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.