Skip to content

A hybrid graph- and sequence-based deep learning framework for behavioral analysis of metamorphic malware

Sep 2026 · Telecommunications Systems · Vol 89 · 0 citations · 30 references

TL;DR

This paper investigates a unified behavioral analysis framework that combines temporal and structural representations of Windows API call sequences: a sequential view based on learned API n-gram representations and a Bidirectional LSTM (BiLSTM) encoder, a structural view derived from the API transition graph, and a multi-head attention fusion of the two.

View source

Similar papers

Open access Sep 2026

Metamorphic Malware Detection via Graph-Augmented Neural Semantics and Adversarial Hardening: A Comprehensive Framework

Background: Metamorphic malware is among the most persistent adversarial challenges in cybersecurity: it rewrites its own instruction stream on every propagation, preserving functional semantics while presenting a syntactically distinct binary that defeats signature-based and many learning-based detectors. Methods: We...

Víctor Manuel González-Gorrín, Josep Prieto-Blázquez · 0 citations
Open access Aug 2026

Hybrid Gce Cnn–Bilstm For Advanced Malware Detection Using Behavioral And Sequential Features

The study introduces an innovative approach of deep learning-based hybrid system to classify malware  based on its real-time detection using a novel architecture called “Gated Convolutional Embedded Convolutional Network - Bidirectional Long Short-Term Memory (GCE-CNN-BiLSTM)” that integrates both static and dynamic se...

Nishok Kumar S, L. Sheela · 0 citations
Conference Aug 2026

DeepGuard: Explainable Behavioral Malware Detection Using Hybrid CNN-BiLSTM-Attention Deep Learning on Dynamic API Call Sequences

Recent rapid increases in sophisticated malware have severely challenged traditional signature-based security systems, particularly in their ability to recognize zero-day and polymorphic threats. This paper introduces “DeepGuard,” an AI/Machine-Learning-powered behavioral malware detection framework built around the an...

Vidya Gavekar, Amar Anant Shinde, S. Lodha et al. · 0 citations
#machine learning Preprint Sep 2026

HYDRA: Proactive Android Malware Drift Adaptation via Hierarchical Graph Contrastive Learning

Concept drift, driven by the rapid evolution of Android malware, severely degrades the performance of machine learning detectors. Current adaptation strategies are often reactive, responding only after performance has dropped and imposing a significant manual annotation burden, or they are proactive but rely on unstabl...

Han Chen, Han-Chen Wang, Hong-Mei Chen et al. · 0 citations
Open access Aug 2026

An Explainable Deep Learning Pipeline for Malware Family Classification: GAF Image Encoding and API-Grounded LLM Interpretation

Signature-based malware detection is undermined by obfuscation and packing, motivating dynamic analysis of Application Programming Interface (API) call sequences. Existing image-based classifiers reach high accuracy but rarely explain why a sample belongs to a given family. In this paper, our goal is not to maximize cl...

Youji Fukuta, Yoshiaki Shiraishi, Masanori Hirotomo et al. · 0 citations
Open access 2026

MalBERT-Temporal: Transformer-Based Zero-Day Malware Detection in Windows Executable Binaries Under Strict Temporal Isolation

A Transformer-based malware detection approach named MalBERT-Temporal that reshapes the 2,381-dimensional BODMAS PE feature vector into 16 contiguous feature-group tokens and then processes these tokens with Transformer encoder layers employing multi-head self-attention to model interactions among all tokens is introdu...

Manar Alanazi, Israa Alsiyat · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.