Papers › HYDRA: A multimodal deep learning framework for malware classification
HYDRA: A multimodal deep learning framework for malware classification
Daniel Gibert, Carles Mateu, Jordi Planes
While traditional machine learning methods for malware detection largely depend on hand-designed features, which are based on experts’ knowledge of the domain, end-to-end learning approaches take the raw executable as input, and try to learn a set of descriptive features from it. Although the latter might behave badly in problems where there are not many data available or where the dataset is imbalanced. In this paper we present HYDRA, a novel framework to address the task of malware detection and classification by combining various types of features to discover the relationships between distinct modalities. Our approach learns from various sources to maximize the benefits of multiple feature types to reflect the characteristics of malware executables. We propose a baseline system that consists of both hand-engineered and end-to-end components to combine the benefits of feature engineering and deep learning so that malware characteristics are effectively represented. An extensive analysis of state-of-the-art methods on the Microsoft Malware Classification Challenge benchmark shows that the proposed solution achieves comparable results to gradient boosting methods in the literature and higher yield in comparison with deep learning approaches.
Code
Repository list and official/mentioned flags are the archive's, frozen 2025-07-28. Reachability, where shown, is from one Syntology probe window (2026-09-16 to 2026-09-18); repositories not probed show nothing. GitHub stars are not tracked.
Code Syntology ran Syntology
Not run by Syntology. Nothing on this page verifies that the listed code works.
Tasks
Results from the paper archive 2025-07-28
| Task | Dataset | Model | Metric | Value | Rank at snapshot | Leaderboard | Report |
|---|---|---|---|---|---|---|---|
| Malware Classification | Microsoft Malware Classification Challenge | Ahmadi et al. (2016): ENT, Bytes 1-G, STR, IMG1, IMG2, MD1, MISC, OPC, SEC, REG, DP, API, SYM, MD2 IMG and Opcode N-Grams + Ensemble Learning (XGBoost) | Accuracy (10-fold) | 0.9976 | #1 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Ahmadi et al. (2016): ENT, Bytes 1-G, STR, IMG1, IMG2, MD1, MISC, OPC, SEC, REG, DP, API, SYM, MD2 IMG and Opcode N-Grams + Ensemble Learning (XGBoost) | Macro F1 (10-fold) | 0.9931 | #1 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | HYDRA | Accuracy (10-fold) | 0.9975 | #2 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | HYDRA | Macro F1 (10-fold) | 0.9951 | #2 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Zhang et al. (2016): Total lines of each Section, Operation Code Count, API Usage, Special Symbols Count, Asm File Pixel Intensity Feature, Bytes File Block Size Distribution, Bytes File N-Gram + Ensemble Learning (XGBoost) | Accuracy (10-fold) | 0.9974 | #3 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Zhang et al. (2016): Total lines of each Section, Operation Code Count, API Usage, Special Symbols Count, Asm File Pixel Intensity Feature, Bytes File Block Size Distribution, Bytes File N-Gram + Ensemble Learning (XGBoost) | Macro F1 (10-fold) | 0.9938 | #3 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Ahmadi et al. (2016): API feature vector + XGBoost | Accuracy (10-fold) | 0.9868 | #9 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Ahmadi et al. (2016): API feature vector + XGBoost | Macro F1 (10-fold) | 0.9638 | #9 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Scaled bytes sequence + CNN & Bidirectional LSTM | Accuracy (10-fold) | 0.9814 | #13 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Scaled bytes sequence + CNN & Bidirectional LSTM | Macro F1 (10-fold) | 0.9662 | #13 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Narayanan et al. (2016): PCA features + 1-NN | Accuracy (10-fold) | 0.9660 | #19 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Narayanan et al. (2016): PCA features + 1-NN | Macro F1 (10-fold) | 0.9102 | #19 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Zero Rule Classifier | Accuracy (10-fold) | 0.2707 | #21 of 29 | Archive leaderboard | report |
| Malware Classification | Microsoft Malware Classification Challenge | Random Guess Classifier | Accuracy (10-fold) | 0.1755 | #22 of 29 | Archive leaderboard | report |
Ranks are positions in the archive's leaderboards as they stood at the 2025-07-28 snapshot. Results published since then are not among these rows, so a rank here is not a current standing.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections