arrow
Return

Adaptive malware detection using sequential feature selection: A dueling double deep Q-Network framework for intelligent classification

delete2026-02-19
delete0
delete
OA
AI
N
Naseem Ahmad Khan
A
Aref Al-Tamimi
A
Amine Bermak
I
Issa Khalil
DOI:10.1016/j.jisa.2026.104407delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
• Formulates malware classification as a Markov Decision Process with episodic feature acquisition, achieving superior performance across diverse datasets: 99.20% F1-score on Microsoft Big2015, 98.64% on BODMAS, and 85.07% on EMBER 2018 using reinforcement learning. • Demonstrates systematic superiority over traditional approaches through comprehensive ablation studies, where static feature selection methods exhibit severe performance degradation (up to 10.40% F1-score reduction) while D3QN maintains consistent improvements across all evaluation scenarios. • Validates robust transferability with 76.08% average recall on unseen EMBER 2024 malware variants across six diverse file formats, demonstrating 27.55% relative improvement over traditional methods and effective zero-day threat detection capabilities. • Introduces quantitative intelligence assessment framework proving strategic learning behavior with 62.5% categorical preference deviation from random baselines, 57.7% feature specialization, and autonomous discovery of domain-aligned cybersecurity patterns without explicit supervision.
Keywords:
Malware classification
Machine learning
Reinforcement learning
Sequential feature selection
Dueling double deep Q-Network
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Journal of Information Security and Applications cover
Journal of Information Security and Applications
IF:
3.7
Papers:
1.9K
Citations:
4.9K

Organization

H
hamad bin khalifa university
Scholars:
186
Papers: 109
Citations: 0