{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/learning-the-pe-header-malware-detection-with","title":"Learning the PE Header, Malware Detection with Minimal Domain Knowledge","arxiv_id":"1709.01471","date":"2017-09-05","proceeding":null,"authors":["Edward Raff","Jared Sylvester","Charles Nicholas"],"abstract":"Many efforts have been made to use various forms of domain knowledge in\nmalware detection. Currently there exist two common approaches to malware\ndetection without domain knowledge, namely byte n-grams and strings. In this\nwork we explore the feasibility of applying neural networks to malware\ndetection and feature learning. We do this by restricting ourselves to a\nminimal amount of domain knowledge in order to extract a portion of the\nPortable Executable (PE) header. By doing this we show that neural networks can\nlearn from raw bytes without explicit feature construction, and perform even\nbetter than a domain knowledge approach that parses the PE header into explicit\nfeatures.","url_abs":"http://arxiv.org/abs/1709.01471v2","url_pdf":"http://arxiv.org/pdf/1709.01471v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"learning-the-pe-header-malware-detection-with","repo_url":"https://github.com/jaketae/deep-malware-detection","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}},{"paper_slug":"learning-the-pe-header-malware-detection-with","repo_url":"https://github.com/jaketae/pytorch-malware-detection","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok","spdx":"MIT"}}],"tasks":[{"task_slug":"malware-detection","task_name":"Malware Detection"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1709.01471","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}