In What Ways Can Artificial Intelligence Improve Malware Detection?

Authors

  • Chen Chen

DOI:

https://doi.org/10.61173/26b40m82

Keywords:

malware detection, deep learning, feature selection, convolutional neural network

Abstract

Based on 58,942 malware and benign software samples (55.6% malicious), this study systematically evaluated the performance of support vector machines (SVM), random forests (RF), convolutional neural networks (CNN), and recurrent neural networks (RNN) in malware detection. Data preprocessing (Z-score standardization, SMOTE oversampling) and feature selection (random forest screening Top200 features) were implemented through the Weka platform, and the model performance was compared using ten-fold cross validation. The results showed that CNN had the best overall performance, with an accuracy of 92% (F1 value of 0.92), and still maintained an accuracy of 80% in unknown malware detection; RF and RNN were second, and SVM was relatively weak. Feature importance analysis showed that API call frequency (0.35) and byte entropy value (0.25) were key discriminant features. Our study confirmed the advantages of deep learning models (DLM) in malware detection and provided a basis for feature selection for optimizing detection systems.

References

Akhtar, M. S., & Feng, T. (2022). Detection of Malware by Deep Learning as CNN-LSTM Machine Learning Techniques in Real Time. Symmetry, 14(11), 2308.

Avci, C., Tekinerdogan, B., & Catal, C. (2023). Analyzing the performance of long short-term memory architectures for malware detection models. Concurrency and Computation: Practice and Experience, 35(6), 1–1.

Chen, H., Chen, J., & Ding, J. (2021). Data evaluation and enhancement for quality improvement of machine learning. IEEE Transactions on Reliability, 70(2), 831–847. Fan, Z., & Liu, R. (2017, August). Investigation of machine learning based network traffic classification. 2017 International Symposium on Wireless Communication Systems (ISWCS). 2017 International Symposium on Wireless Communication Systems (ISWCS), Bologna. https://doi.org/10.1109/ iswcs.2017.8108090

Ferdous, J., Islam, R., Mahboubi, A., & Islam, M. Z. (2023). A review of state-of-the-art malware attack trends and defense mechanisms. IEEE Access: Practical Innovations, Open Solutions, 11, 121118–121141.

Hamza, M., & Larocque, D. (2005). An empirical comparison of ensemble methods based on classification trees. Journal of Statistical Computation and Simulation. https://doi.org/10.1080/ 00949650410001729472 Hossain Faruk, M. J., Shahriar, H., Valero, M., Barsha, F. L., Sobhan, S., Khan, M. A., Whitman, M., Cuzzocrea, A., Lo, D., Rahman, A., & Wu, F. (2021, December 15). Malware detection and prevention using artificial intelligence techniques. 2021 IEEE International Conference on Big Data (Big Data). 2021 IEEE International Conference on Big Data (Big Data), Orlando, FL, USA. https://doi.org/10.1109/bigdata52589.2021.9671434

Kumar, R., Peng, S.-L., Jain, P., & Elngar, A. A. (2025). Deep Learning Innovations for Securing Critical Infrastructures. IGI Global.

Li, Q., Mi, J., Li, W., Wang, J., & Cheng, M. (2021). CNN-based malware variants detection method for internet of things. IEEE Internet of Things Journal, 8(23), 16946–16962.

Montasari, R., & Jahankhani, H. (2021). Artificial Intelligence in Cyber Security: Impact and Implications: Security Challenges, Technical and Ethical Issues, Forensic Investigative Challenges. Springer Nature. Moti, Z., Hashemi, S., & Namavar, A. (2019, October). Discovering future malware variants by generating new malware samples using generative adversarial network. 2019 9th International Conference on Computer and Knowledge Engineering (ICCKE). 2019 9th International Conference on Computer and Knowledge Engineering (ICCKE), Mashhad, Iran. https://doi.org/10.1109/iccke48569.2019.8964913 Narra, U., Troia, F. D., Corrado, V. A., Austin, T. H., & Stamp, M. (2015). Clustering versus SVM for malware detection. Journal of Computer Virology and Hacking Techniques, 12(4), 213–224.

Neira, A. B. de, Araujo, A. M. de, & Nogueira, M. (2023). An intelligent system for DDoS attack prediction based on early warning signals. IEEE Transactions on Network and Service Management, 20(2), 1254–1266. Okoli, U. I., Obi, O. C., Adewusi, A. O., & Abrahams, T. O. (2024). Machine learning in cybersecurity: A review of threat detection and defense mechanisms. World Journal of Advanced Research and Reviews, 21(1), 2286–2295. Patil, S., Varadarajan, V., Walimbe, D., Gulechha, S., Shenoy,

S., Raina, A., & Kotecha, K. (2021). Improving the Robustness of AI-Based Malware Detection Using Adversarial Machine Learning. Algorithms, 14(10), 297.

Pokhariyal, P., Patel, A., & Pandey, S. (2024). AI and Emerging Technologies: Automated Decision-Making, Digital Forensics, Dean&Francis Chen Chen and Ethical Considerations. CRC Press.

Qiao, Q., Feng, R., Chen, S., Zhang, F., & Li, X. (2024). Multilabel classification for android malware based on active learning. IEEE Transactions on Dependable and Secure Computing, 1–18.

Redhu, A., Choudhary, P., Srinivasan, K., & Das, T. K. (2024). Deep learning-powered malware detection in cyberspace: a contemporary review. Frontiers in Physics, 12, 1349463.

Reis, J., Cohen, Y., Melão, N., Costa, J., & Jorge, D. (2021). High-Tech Defense Industries: Developing Autonomous Intelligent Systems. Applied Sciences, 11(11), 4920.

Sarker, I. H. (2023). Multi-aspects AI-based modeling and adversarial learning for cybersecurity intelligence and robustness: A comprehensive overview. Security and Privacy, 6(5), e295.

Shen, Z., & Chen, S. (2020). A Survey of Automatic Software Vulnerability Detection, Program Repair, and Defect Prediction Techniques. Security and Communication Networks, 2020(1), 8858010.

Sotiropoulos, J. (2024). Adversarial AI Attacks, Mitigations, and Defense Strategies: A cybersecurity professional’s guide to AI attacks, threat modeling, and securing AI with MLSecOps. Packt Publishing Ltd.

Stamp, M., Alazab, M., & Shalaginov, A. (2020). Malware Analysis Using Artificial Intelligence and Deep Learning. Springer Nature. Tobiyama, S., Yamaguchi, Y., Shimada, H., Ikuse, T., & Yagi, T. (2016, June). Malware detection with deep neural network using process behavior. 2016 IEEE 40th Annual Computer Software and Applications Conference (COMPSAC). 2016 IEEE 40th Annual Computer Software and Applications Conference (COMPSAC), Atlanta, GA, USA. https://doi.org/10.1109/ compsac.2016.151

Yang, J., Zhang, Z., Zhang, H., & Fan, J. (2022). Android malware detection method based on highly distinguishable static features and DenseNet. PloS One, 17(11), e0276332. Zhang, Z., Hamadi, H. A., Damiani, E., Yeun, C. Y., & Taher, F. (2022). Explainable artificial intelligence applications in cyber security: State-of-the-art in research. IEEE Access: Practical Innovations, Open Solutions, 10, 93104–93139.

Downloads

Published

2025-12-19