DOI: https://doi.org/10.1007/s44257-025-00053-2
تاريخ النشر: 2026-01-08
المؤلف: Roise Uddin وآخرون
الموضوع الرئيسي: تقنيات الكشف المتقدمة عن البرمجيات الخبيثة
نظرة عامة
إن الانتشار المستمر للبرمجيات الضارة يقدم تحديات كبيرة للبنية التحتية الرقمية، مع ظهور ملايين من المتغيرات الجديدة كل عام. تواجه أنظمة الكشف التقليدية، وخاصة أدوات مكافحة الفيروسات المعتمدة على التوقيع، صعوبة في مواكبة ذلك بسبب تقنيات التهرب المتطورة التي تستخدمها هذه البرامج الضارة، مثل التعتيم والتعددية الشكل. بينما يتم استخدام طرق التحليل الثابت والديناميكي بشكل شائع، فإنها تواجه قيودًا في القابلية للتوسع والفعالية ضد تكتيكات التهرب المتقدمة.
النموذج المقترح، ParaECA-LSTMNet، يدمج فروع شبكة عصبية تلافيفية متوازية (CNN)، واهتمام القناة الفعال (ECA)، ورأس ذاكرة قصيرة وطويلة الأمد (LSTM) لالتقاط الأنماط المكانية متعددة المقاييس والاعتمادات الشبيهة بالتسلسل في صور البرمجيات الضارة بشكل فعال. حقق دقة مثيرة للإعجاب تبلغ 99.23% على مجموعة بيانات Malimg، التي تتكون من 9,339 صورة عبر 25 عائلة، ويظهر النموذج مقاييس أداء قوية، بما في ذلك 99.23% دقة، 99.20% استرجاع، و99.20% نتيجة F1. يركز تصميمه على العملية، مع فروع متوازية ضحلة تسهل التكامل في سير العمل الحالي، مما يجعله مناسبًا للاستخدام كمرشح مسبق ثابت في عمليات مركز العمليات الأمنية (SOC) وكمعجل للتحليل الديناميكي. ستتركز الأعمال المستقبلية على تعزيز القوة من خلال التدريب العدائي، واستكشاف الدمج متعدد الوسائط مع البيانات الثابتة والديناميكية، وضمان قابلية النقل من خلال تقنيات التحسين. بالإضافة إلى ذلك، ستدعم أدوات الشرح وآليات الحوكمة تنفيذ الأداء المستمر للنموذج وقابليته للتكيف في مواجهة تهديدات البرمجيات الضارة المتطورة.
الطرق
في هذا القسم، يوضح المؤلفون إعداد التجارب لتقييم بنية ParaECA-LSTMNet، مع التركيز على إمكانية إعادة الإنتاج ومعايير الأداء. تم إجراء التجارب في بيئة مسيطر عليها باستخدام Python 3.10 وTensorFlow 2.14، مع واجهة برمجة التطبيقات Keras لتطوير النموذج. تضمنت تكوين الأجهزة بطاقة رسومات NVIDIA RTX 3090، و128 جيجابايت من الذاكرة العشوائية، ومعالج Intel Xeon Gold 6326، مما يسهل عمليات التدريب الفعالة. تم تدريب النموذج باستخدام مُحسِّن Adam بمعدل تعلم ثابت قدره 0.001 وحجم دفعة قدره 32 على مدى 100 دورة، مع استخدام معدل تسرب قدره 0.3 لتخفيف الإفراط في التكيف. تم تطبيق دالة خسارة الانتروبيا المتقاطعة الفئوية لمهمة تصنيف البرمجيات الضارة ذات 25 فئة، مع تقسيم مجموعة بيانات Malimg إلى مجموعات تدريب (70%)، والتحقق (15%)، والاختبار (15%) باستخدام أخذ عينات مصنفة.
لتحسين تعميم النموذج، تم تنفيذ تقنيات تعزيز البيانات في الوقت الحقيقي مثل التدوير العشوائي، والانقلابات الأفقية، والتكبير، والترجمات. تم تقييم أداء النموذج باستخدام الدقة العامة، ودقة الفئة، والاسترجاع، ونتيجة F1، مع التركيز على متوسط نتيجة F1 الماكرو لمعالجة عدم توازن الفئات. تم استخدام مصفوفات الارتباك لتحليل أنماط التصنيف الخاطئ، بينما تم حساب مقاييس ROC-AUC للمقارنات الثنائية خلال دراسات الإزالة. تأكد المؤلفون من إمكانية إعادة الإنتاج من خلال استخدام بذور عشوائية ثابتة لتقسيم البيانات وتهيئة الأوزان، مما أسس إطارًا قويًا لتقييم ParaECA-LSTMNet في مهام تصنيف صور البرمجيات الضارة.
النتائج
يقدم قسم النتائج تقييمًا مفصلًا لنموذج ParaECA-LSTMNet المقترح مقابل عدة هياكل تعلم عميقة رائدة باستخدام مجموعة بيانات Malimg. تم استخدام مقاييس الأداء مثل الدقة، والدقة، والاسترجاع، ونتيجة F1 لتقييم النماذج. من الجدير بالذكر أن ParaECA-LSTMNet حقق أعلى دقة تصنيف تبلغ 99.23%، متجاوزًا جميع النماذج الأخرى، بما في ذلك DenseNet169 وEfficientNetB0، اللتين حققتا تقريبًا 97%. بالمقابل، أظهرت VGG16 أدنى أداء بدقة تبلغ 81%، ويعزى ذلك إلى قدراتها المحدودة في استخراج الميزات لصور البرمجيات الضارة المعتمدة على القوام.
كشفت التحليلات الإضافية من خلال مصفوفات الارتباك أن ParaECA-LSTMNet حافظ على أداء قوي مع الحد الأدنى من التصنيفات الخاطئة، خاصة في أنماط البرمجيات الضارة المتشابهة بصريًا. بالمقارنة، عرض ResNet50 توزيعًا أوسع من الأخطاء، خاصة في فئات معينة مثل Autorun وVBKrypt، مما أدى إلى دقة أقل تبلغ حوالي 96%. أشارت منحنيات دقة التدريب والتحقق لـ ParaECA-LSTMNet إلى تقارب سريع وأداء متسق، متجاوزة 99% دون علامات على الإفراط في التكيف، بينما استقرت منحنيات الخسارة بالقرب من الصفر، مما يؤكد الحد الأدنى من خطأ التعميم. بشكل عام، تؤكد النتائج على فعالية النماذج الأعمق التي تدمج الانتباه في تصنيف صور البرمجيات الضارة.
المناقشة
في مناقشة الأعمال ذات الصلة، يتم تسليط الضوء على مجموعة متنوعة من الأساليب العميقة لتصنيف البرمجيات الضارة باستخدام تمثيلات الصور للثنائيات. من الجدير بالذكر أن نموذج DTMIC حقق معدلات دقة مثيرة للإعجاب بلغت 98.92% و93.19% على مجموعتي بيانات MalImg وMicrosoft BIG، على التوالي، من خلال استخدام الشبكات العصبية التلافيفية (CNNs) المدربة مسبقًا وتقنيات الإيقاف المبكر لتخفيف الإفراط في التكيف. وبالمثل، أظهر إطار IMCFN أداءً قويًا بدقة بلغت 98.82% و97.35% على مجموعتي بيانات MalImg وIoT-Android، على التوالي، من خلال الاستفادة من تعزيز البيانات والشبكات العصبية التلافيفية المعدلة. عززت نماذج أخرى، مثل DeepMalware وMIRACLE، فعالية الكشف عن البرمجيات الضارة المعتمدة على الصور، محققة دقة تقترب من 99% عبر مجموعات بيانات متعددة.
تؤكد المناقشة أيضًا على أهمية معالجة عدم توازن الفئات وتقنيات التعتيم في تصنيف البرمجيات الضارة. استخدمت العديد من الدراسات نماذج هجينة وهياكل متقدمة، مثل التعلم الجماعي وآليات الانتباه، لتعزيز قوة التصنيف والتعميم. على سبيل المثال، حقق إطار SE-AGM دقة تبلغ 99.43% على مجموعة بيانات MalImg من خلال دمج مشفرات تلقائية وGRUs، بينما حققت استراتيجية التجميع IMCEC دقة تزيد عن 99% على البرمجيات الضارة المعبأة. تؤكد النتائج مجتمعة على إمكانيات نماذج التعلم العميق، وخاصة تلك التي تستخدم تمثيلات قائمة على الصور، لتصنيف البرمجيات الضارة بشكل فعال مع التكيف مع مشهد التهديدات المتطور والحفاظ على الأداء عبر مجموعات بيانات متنوعة.
DOI: https://doi.org/10.1007/s44257-025-00053-2
Publication Date: 2026-01-08
Author(s): Roise Uddin et al.
Primary Topic: Advanced Malware Detection Techniques
Overview
The ongoing proliferation of malware presents significant challenges to digital infrastructure, with millions of new variants emerging each year. Traditional detection systems, particularly signature-based antivirus tools, struggle to keep pace due to the sophisticated evasion techniques employed by these malicious programs, such as obfuscation and polymorphism. While static and dynamic analysis methods are commonly utilized, they face limitations in scalability and effectiveness against advanced evasion tactics.
The proposed model, ParaECA-LSTMNet, integrates parallel convolutional neural network (CNN) branches, Efficient Channel Attention (ECA), and a Long Short-Term Memory (LSTM) head to effectively capture both multi-scale spatial patterns and sequence-like dependencies in malware images. Achieving an impressive accuracy of 99.23% on the Malimg dataset, which comprises 9,339 images across 25 families, the model demonstrates strong performance metrics, including 99.23% precision, 99.20% recall, and 99.20% F1 score. Its design emphasizes practicality, with shallow parallel branches that facilitate integration into existing workflows, making it suitable for use as a static pre-filter in Security Operations Center (SOC) processes and as an accelerator for dynamic analysis. Future work will focus on enhancing robustness through adversarial training, exploring multimodal fusion with static and dynamic data, and ensuring portability through optimization techniques. Additionally, the implementation of explainability tools and governance mechanisms will support ongoing model performance and adaptability in the face of evolving malware threats.
Methods
In this section, the authors detail the experimental setup for evaluating the ParaECA-LSTMNet architecture, emphasizing reproducibility and performance benchmarking. The experiments were conducted in a controlled environment using Python 3.10 and TensorFlow 2.14, with the Keras API for model development. The hardware configuration included an NVIDIA RTX 3090 GPU, 128 GB of RAM, and an Intel Xeon Gold 6326 CPU, facilitating efficient training processes. The model was trained with the Adam optimizer at a fixed learning rate of 0.001 and a batch size of 32 over 100 epochs, employing a dropout rate of 0.3 to mitigate overfitting. The categorical cross-entropy loss function was applied for a 25-class malware classification task, with the Malimg dataset split into training (70%), validation (15%), and testing (15%) sets using stratified sampling.
To enhance model generalization, real-time data augmentation techniques such as random rotations, horizontal flips, zooming, and translations were implemented. Model performance was assessed using overall accuracy, class-wise precision, recall, and F1-score, with a focus on the macro-averaged F1-score to address class imbalance. Confusion matrices were utilized to analyze misclassification patterns, while ROC-AUC metrics were calculated for binary comparisons during ablation studies. The authors ensured reproducibility by using fixed random seeds for data splitting and weight initialization, establishing a robust framework for evaluating the ParaECA-LSTMNet in malware image classification tasks.
Results
The results section provides a detailed evaluation of the proposed ParaECA-LSTMNet model against several leading deep learning architectures using the Malimg dataset. Performance metrics such as accuracy, precision, recall, and F1-score were employed to assess the models. Notably, ParaECA-LSTMNet achieved the highest classification accuracy of 99.23%, surpassing all other models, including DenseNet169 and EfficientNetB0, which both achieved approximately 97%. In contrast, VGG16 exhibited the lowest performance with an accuracy of 81%, attributed to its limited feature extraction capabilities for texture-based malware images.
Further analysis through confusion matrices revealed that ParaECA-LSTMNet maintained robust performance with minimal misclassifications, particularly in visually similar malware patterns. In comparison, ResNet50 displayed a wider distribution of errors, especially in specific classes like Autorun and VBKrypt, resulting in a lower accuracy of around 96%. The training and validation accuracy curves for ParaECA-LSTMNet indicated rapid convergence and consistent performance, exceeding 99% without signs of overfitting, while the loss curves stabilized near zero, confirming minimal generalization error. Overall, the findings underscore the effectiveness of deeper, attention-integrated models in malware image classification.
Discussion
In the discussion of related work, various deep learning approaches for malware classification using image representations of binaries are highlighted. Notably, the DTMIC model achieved impressive accuracy rates of 98.92% and 93.19% on the MalImg and Microsoft BIG datasets, respectively, by employing pre-trained convolutional neural networks (CNNs) and early stopping techniques to mitigate overfitting. Similarly, the IMCFN framework demonstrated strong performance with accuracies of 98.82% and 97.35% on the MalImg and IoT-Android datasets, respectively, by leveraging data augmentation and fine-tuned CNNs. Other models, such as DeepMalware and MIRACLE, further reinforced the efficacy of visual-based malware detection, achieving accuracies nearing 99% across multiple datasets.
The discussion also emphasizes the importance of addressing class imbalance and obfuscation techniques in malware classification. Several studies employed hybrid models and advanced architectures, such as ensemble learning and attention mechanisms, to enhance classification robustness and generalization. For instance, the SE-AGM framework achieved 99.43% accuracy on the MalImg dataset by integrating autoencoders and GRUs, while the IMCEC ensemble strategy yielded over 99% accuracy on packed malware. The findings collectively underscore the potential of deep learning models, particularly those utilizing image-based representations, to effectively classify malware while adapting to evolving threat landscapes and maintaining performance across diverse datasets.
