arXiv:2607. 01445v1 Announce Type: cross Abstract: Malware poses a critical and ever-evolving threat, and robust and effective systems for detecting and classifying malware are of essential importance.
By Derek Everett, Edward Raff, James Holt
arXiv:2606. 02834v1 Announce Type: cross Abstract: Malware analysis starts with the raw bytes of an executable program, and tools to "lift" these to higher-level representations, such as assembly, are expensive and subject to error.
By Florian St\"ortz, Catalin-Andrei Stan, Alexandru Dinu, Sandra Servia-Rodr\'iguez, Mihaela Gaman, Calin Miron, Edward Raff
Most corporate workplace environments enforce policies and technical controls that limit the storage of sensitive data on client endpoints. Consequently, ransomware operators have evolved variants that expand their attack surface from local systems to network drives and shared storage resources.
arXiv:2606. 03432v1 Announce Type: cross Abstract: The number of malware (either variant or novel) is rapidly increasing, making malware detection and mitigation a complex problem.
By Raja Khurram Shahzad, Muhammad Mustaqeem, Haroon Elahi
The paper presents a lightweight machine‑learning approach for multi‑class malware detection on resource‑constrained devices. Using a LightGBM classifier with SMOTE oversampling, SOM‑US undersampling, and Genetic‑Algorithm feature selection, the authors achieve 89.1 % accuracy on four malware families and 76 % on 16 individual malware types. A second Random‑Forest model further improves family classification to 91.2 % and individual classification to 78.7 %.
By Abdul Khalek Alve, Alif Rahman, Saadman Zaman, Sazzad Hossen Himel, Muhammad Iqbal Hossain
arXiv:2608. 02671v1 Announce Type: cross Abstract: Malware detection using Hardware Performance Counters (HPC) has emerged as a promising solution to improve the security of computing systems as a complement to antivirus software.
By Alireza Abolhasani Zeraatkar, Parnian Shabani Kamran, Inderpreet Kaur, Nagabindu Ramu, Tyler Sheaves, Hussain Al-Asaad
arXiv:2606. 30586v1 Announce Type: cross Abstract: Most corporate workplace environments enforce policies and technical controls that limit the storage of sensitive data on client endpoints.
By Gervais Hatungimana, Abdun Naser Mahmood, Mohammad Jabed Morshed Chowdhury
arXiv:2610.01949v1 Announce Type: cross
Abstract: Ransomware has emerged as a major cybersecurity threat, with incidents increasing in frequency and impact across critical sectors. These attacks are...
By Emmanuela Andam, Yasir Abbas Zaidi, Abdelali Hadir, Emmanuel Grant, Naima Kaabouch
The paper discusses how any lossless compression algorithm can be transformed into a machine learning method using Normalized Compression Distance or the Minimum Description Length principle, and conversely how any auto‑regressive model can become a lossless compressor via entropy coding. It surveys and formalizes these strategies, introduces a design framework for compression‑based ML, and empirically validates that such methods can match conventional baselines and outperform them on malware detection, achieving accuracy gains up to 0.62 by varying design choices.
By John Hurwitz, Edward Raff, Charles K. Nicholas
arXiv:2606. 16072v1 Announce Type: cross Abstract: Compared with binaries and decompiled code, malware source code more directly reflects the attackers' original intent.
By Bojing Li, Duo Zhong, Prajna Bhandary, Raguvir S, Charles Maxa, Robert J Joyce, Charles Nicholas
Delphi Scanner is a static malware detection system for Windows PE files that balances efficiency and interpretability. It employs a convolutional neural network to model Windows API sequences and a rule‑based interpretation layer to map APIs to high‑level malicious capabilities. Tested on over 190,000 PE files, it achieves 95.35% accuracy with a 1.53 MB model, and demonstrates robustness against out‑of‑distribution samples and adversarial manipulations.
By Bijied Brahimi, Vincent Cohadon, Gabriel Glazman, Rayan Al Mohaize, Omran Berjawi, Rida Khatoun
arXiv:2606. 20436v1 Announce Type: cross Abstract: Malware analysts often inspect compiled binaries through decompiled pseudo-C, when source code is unavailable.
By Bercan Turkmen, Vyas Raina