arrow
Return

Signal-based malware classification using 1D CNNs

delete2026-03-01
delete0
delete
OA
AI
J
Jack Wilkie *
H
Hanan Hindy
I
Ivan Andonović
C
Christos Tachtatzis
R
Robert Atkinson
DOI:10.1186/s42400-025-00454-6delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Malware classification is a contemporary and ongoing challenge in cyber-security: modern obfuscation techniques are able to evade traditional static analysis, while dynamic analysis is too resource intensive to be deployed at a large-scale. One prominent line of research addresses these limitations by converting malware binaries into 2D images by heuristically reshaping them into a 2D grid before resizing using Lanczos resampling. These images can then be classified based on their textural information using computer vision approaches. While this approach can detect obfuscated malware more effectively than static analysis; the process of converting files into 2D images results in significant information loss due to both quantisation noise, caused by rounding to integer pixel values, and the introduction of 2D dependencies which do not exist in the original data. This loss of signal limits the classification performance of the downstream model. This work addresses these weaknesses by instead resizing the files into 1D signals which avoids the need for heuristic reshaping, additionally these signals do not suffer from quantisation noise due to being stored in a floating-point format. It is shown that existing 2D CNN architectures can be readily adapted to classify these 1D signals for improved performance. Furthermore, a bespoke 1D convolutional neural network, based on the ResNet architecture and squeeze-and-excitation layers, was developed to classify these signals and evaluated on the MalNet dataset. It was found to achieve state-of-the-art performance on binary, type, and family level classification with F1 scores of 0.874, 0.503, and 0.507, respectively, paving the way for future models to operate on the proposed signal modality.
Keywords:
Malware classification
Malware detection
Machine learning
Convolutional neural networks
Neural networks
Computer vision
MalNet
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Cybersecurity
IF:
3.7
Papers:
575
Citations:
1.0K

Organization

A
ain shams university
Scholars:
2.3K
Papers: 1.1K
Citations: 0
U
University of Strathclyde
Scholars:
1.3K
Papers: 689
Citations: 1.3W