Skip to content
Open access

Malware detection via memory dump images: investigating the role of uneven kernel filters in CNNs with visual explainability

Aug 2026 · Journal of Computer Virology and Hacking Techniques · Vol 22 · 0 citations · 34 references

TL;DR

This paper proposes a novel CNN architecture with uneven kernel sizes that outperforms existing malware detection and classification models and compares its performance against well-known CNN architectures, all trained and tested on malware image datasets.

Abstract

With the Internet becoming more accessible, protecting our digital identities has become more crucial than ever. Our devices are always online, sharing data, and exposed to numerous threats. Traditional methods of detecting malware are no longer adequate due to the rapid advancement and complexity of malware. To address these challenges, researchers have started using artificial intelligence, especially machine learning and deep learning techniques, with encouraging outcomes. One emerging approach involves converting malware binaries or memory dumps into images. However, these malware images are not recognizable to the human eye and, therefore, need to be explained in terms of how the CNNs perceive this data type. This paper applies the Grad-CAM technique to malware images collected from memory dumps to understand sufficiently how black-box CNN models make predictions with this data. Based on insights from the Grad-CAM analysis, we propose a novel CNN architecture with uneven kernel sizes that outperforms existing malware detection and classification models. We compare its performance against well-known CNN architectures, all trained and tested on malware image datasets such as Malimg, Dumpware10, MaleVis, and MalBen. Our proposed architecture achieved an impressive accuracy of 99.58% on the Malimg dataset with fewer training parameters, surpassing previous models, which achieved a maximum accuracy of 99.26% on the same dataset.

Read PDF

Similar papers

Review Open access Aug 2026

A Survey on Deep Learning Approaches for Malware Detection and Classification

Malware is a serious threat in the cybersecurity area because of its dynamic nature, the variety of malware families, stealth, propagation and the capability of evading traditional security products. Therefore, proper malware detection and classification are crucial for detecting malicious software and for securing com...

Shivani Jain · 0 citations
Conference Open access 2026

Packed and Unpacked Malware Detection by Means of Explainable Federated Machine Learning

A malware detection method based on Federated Machine Learning using a publicly available dataset of Portable Executable and Object Linking and Embedding files from the Windows environment and the Gradient-weighted Class Activation Mapping++ algorithm to highlight the image regions that influenced the classification re...

Giovanni Ciaramella, Fabio Martinelli, Antonella Santone et al. · 0 citations
Open access Aug 2026

Intelligent malware detection on Android smartphones via a hybrid approach using gradient boosting and convolutional neural network

Evaluation using metrics such as accuracy, precision, F1 score, and false positive rate indicates that CNN-GBM outperforms existing deep learning models, and enhancements stem from the effective integration of CNN feature extraction with GBM’s boosting capabilities.

C. Chimeleze, Norziana Jamil, Z. M. Zain et al. · 0 citations
Conference Jul 2026

A Performance Comparison of Convolutional Neural Networks and Vision Transformers for Malware Detection

The detection of malware is a great challenge in cybersecurity because the threat environment keeps on changing. Convolutional Neural Networks (CNNs) are frequently applied to conduct image-based malware detection. On the other hand, Vision Transformers (ViTs) that leverage self-attention mechanisms have emerged as a n...

Zhi-Siang Lim, Shing-Chiang Tan · 0 citations
Open access Aug 2026

Lightweight CNN with Multi-Head Attention for Image-Based Malware Classification

This paper introduces a compact convolutional neural network (CNN) architecture integrated with a multi-head attention mechanism to enhance feature discrimination in malware family classification. The novelty lies in combining attention-based refinement within a lightweight framework that achieves comparable accuracy t...

Mohammed Kasem Al-Bayati · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.