Skip to content
Conference Open access

Packed and Unpacked Malware Detection by Means of Explainable Federated Machine Learning

2026 · International Conference on Security and Cryptography · pp. 775-786 · 0 citations · 20 references
Computer Science

TL;DR

A malware detection method based on Federated Machine Learning using a publicly available dataset of Portable Executable and Object Linking and Embedding files from the Windows environment and the Gradient-weighted Class Activation Mapping++ algorithm to highlight the image regions that influenced the classification results.

Abstract

: The number of cybersecurity attacks has drastically increased in the last few decades. Although researchers and experts have proposed several methods to curb them, malicious actors continue to develop new techniques to perpetrate attacks. Among these techniques, attackers often use software known as a packer to obfuscate or compress executable code. Thus, it allows us to obtain a different file representation, making the analysis process more difficult. Given the widespread use of malware in companies and the need to avoid sharing sensitive data, this research article proposes a malware detection method based on Federated Machine Learning. In detail, we trained several models leveraging a publicly available dataset of Portable Executable and Object Linking and Embedding files from the Windows environment, which we converted into images using a Python script. To enhance the privacy and security of the model, we employed the zeroing norm aggregator, which zeroes to mitigate the risk of gradient leakage attacks. Moreover, we employed non-Independent and Iden-tically Distributed data to represent a real-world scenario better. Once we concluded the training phase, we also evaluated the best model on original samples and on samples processed with three state-of-the-art packers (MPRESS, BEP, and GZexe) to assess its robustness. Specifically, the baseline accuracy of 0.881 increased slightly with MPRESS (+0.003) and GZexe (+0.004). However, the BEP-packed samples showed the greatest improvement, achieving an accuracy of 0.972. Finally, we applied the Gradient-weighted Class Activation Mapping++ algorithm to highlight the image regions that influenced the classification results.

Read PDF

Similar papers

Open access Aug 2026

DYNAMIC RANSOMWARE DETECTION USING TIME-BASED API CALLING ANALYSIS

The findings show that ensemble learning techniques, especially XGBoost, are very successful in classifying multi-class malware and can be used in practical cybersecurity systems.

Juveriya Rasheed, Umar Farooq · 0 citations
Conference Jul 2026

Obfuscated Malware Detection Through Ensemble Learning

Modern malwares utilize different obfuscation techniques to hide their behaviors and overcome traditional signature-based detection methods. This paper investigates the use of machine learning techniques to detect obfuscated malware in the Windows operating system trained on memory-based features. This research conside...

Ahmad Rasheed, K. Sabri · 0 citations
#machine learning Preprint Aug 2026

REPLICANT: Learning Policies for Evading and Hardening Malware Detectors

This work presents Replicant, a deep reinforcement learning framework that learns the realistic task of evasion under a strict label-only black-box threat model and demonstrates that learning the task of evasion not only results in stronger attack performance but provides a better signal for hardening malware detectors...

Shae McFadden, Ilias Tsingenopoulos, Mario D'Onghia et al. · 0 citations
Open access Aug 2026

Analyzing Malware Behavior Using Generative Neural Networks

The results demonstrate that GNN-based malware detection not only addresses the limitations of conventional approaches in terms of scalability but also provides a more robust and adaptable framework that could be integrated into future real-time threat intelligence and automated defense systems.

Wurood A. Jbara, N. A. Hussein · 0 citations
Open access Aug 2026

Malware detection via memory dump images: investigating the role of uneven kernel filters in CNNs with visual explainability

This paper proposes a novel CNN architecture with uneven kernel sizes that outperforms existing malware detection and classification models and compares its performance against well-known CNN architectures, all trained and tested on malware image datasets.

M. Alaeiyan, Pooria Lakzian · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.