{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/transfer-learning-for-image-based-malware","title":"Transfer Learning for Image-Based Malware Classification","arxiv_id":"1903.11551","date":"2019-01-21","proceeding":null,"authors":["Niket Bhodia","Pratikkumar Prajapati","Fabio Di Troia","Mark Stamp"],"abstract":"In this paper, we consider the problem of malware detection and\nclassification based on image analysis. We convert executable files to images\nand apply image recognition using deep learning (DL) models. To train these\nmodels, we employ transfer learning based on existing DL models that have been\npre-trained on massive image datasets. We carry out various experiments with\nthis technique and compare its performance to that of an extremely simple\nmachine learning technique, namely, k-nearest neighbors (\\kNN). For our k-NN\nexperiments, we use features extracted directly from executables, rather than\nimage analysis. While our image-based DL technique performs well in the\nexperiments, surprisingly, it is outperformed by k-NN. We show that DL models\nare better able to generalize the data, in the sense that they outperform k-NN\nin simulated zero-day experiments.","url_abs":"http://arxiv.org/abs/1903.11551v1","url_pdf":"http://arxiv.org/pdf/1903.11551v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"transfer-learning-for-image-based-malware","repo_url":"https://github.com/pratikpv/malware_classification","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":null}],"tasks":[{"task_slug":"classification-1","task_name":"Classification"},{"task_slug":"classification","task_name":"General Classification"},{"task_slug":"malware-classification","task_name":"Malware Classification"},{"task_slug":"malware-detection","task_name":"Malware Detection"},{"task_slug":"transfer-learning","task_name":"Transfer Learning"}],"methods":[{"method_slug":"k-nn","method_name":"k-NN"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}