{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/activation-analysis-of-a-byte-based-deep","title":"Activation Analysis of a Byte-Based Deep Neural Network for Malware Classification","arxiv_id":"1903.04717","date":"2019-03-12","proceeding":null,"authors":["Scott E. Coull","Christopher Gardner"],"abstract":"Feature engineering is one of the most costly aspects of developing effective\nmachine learning models, and that cost is even greater in specialized problem\ndomains, like malware classification, where expert skills are necessary to\nidentify useful features. Recent work, however, has shown that deep learning\nmodels can be used to automatically learn feature representations directly from\nthe raw, unstructured bytes of the binaries themselves. In this paper, we\nexplore what these models are learning about malware. To do so, we examine the\nlearned features at multiple levels of resolution, from individual byte\nembeddings to end-to-end analysis of the model. At each step, we connect these\nbyte-oriented activations to their original semantics through parsing and\ndisassembly of the binary to arrive at human-understandable features. Through\nour results, we identify several interesting features learned by the model and\ntheir connection to manually-derived features typically used by traditional\nmachine learning models. Additionally, we explore the impact of training data\nvolume and regularization on the quality of the learned features and the\nefficacy of the classifiers, revealing the somewhat paradoxical insight that\nbetter generalization does not necessarily result in better performance for\nbyte-based malware classifiers.","url_abs":"http://arxiv.org/abs/1903.04717v2","url_pdf":"http://arxiv.org/pdf/1903.04717v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"activation-analysis-of-a-byte-based-deep","repo_url":"https://github.com/pralab/toucanstrike","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"unanswered"}}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"feature-engineering","task_name":"Feature Engineering"},{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"malware-classification","task_name":"Malware Classification"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}