Disagreement-Aware Multi-View Stacking for Robust Malware Classification
Abstract
Static malware family classification can use evidence from raw byte content, disassembly, and Portable Executable metadata. Each representation captures different characteristics of a malware sample. We propose a multi-view stacking framework for Microsoft BIG 2015 that represents each sample through seven static feature views and combines their predictions at the meta level. Nine base, or Level-0, XGBoost and LightGBM classifiers generate 81 out-of-fold class probabilities. We augment these probabilities with statistics describing central tendency, inter-model dispersion, and predictive entropy, resulting in 126 disagreement-aware meta-features. Two meta-level, or Level-1, classifiers then produce predictions that are combined through constrained weight optimization. On an 80/20 train-test split, the framework achieves 99.86% accuracy, 99.83% weighted F1-score, an MCC of 0.9984, and a multiclass log loss of 0.00555. When trained on the full labeled dataset, it obtains private and public leaderboard log losses of 0.00467 and 0.00805, respectively. These results indicate that explicitly representing agreement and disagreement among heterogeneous static classifiers can improve multi-view stacking within the BIG 2015 evaluation setting.