Browse › Miscellaneous › Malware Classification › Microsoft Malware Classification Challenge
Microsoft Malware Classification Challenge Benchmark (Malware Classification)
Malware Classification is the process of assigning a malware sample to a specific malware family. Malware within a family shares similar properties that can be used to create signatures for detection and classification. Signatures can be categorized as static or dynamic based on how they are extracted. A static signature can be based on a byte-code sequence, binary assembly instruction, or an imported Dynamic Link Library (DLL). Dynamic signatures can be based on file system activities, terminal commands, network communications, or function and system call sequences.
Source: Behavioral Malware Classification using Convolutional Recurrent Neural Networks
The archive carries no text for this table; the description above is the archive's text for the task Malware Classification. archive 2025-07-28
Over time archive 2025-07-28
The chart needs JavaScript; the table below carries every value.
Direction inferred from the metric name, not from the archive: Accuracy (10-fold) (higher is better), Macro F1 (10-fold) (higher is better), Accuracy (5-fold) (higher is better), F1 score (5-fold) (higher is better), Accuracy (higher is better). Not inferred (points only, no best-so-far line): LogLoss. Points are placed at the row's paper date; 29 of 29 rows carry one.
Results archive 2025-07-28
Archive rows end at the archive snapshot, 2025-07-28: no result published after that date is in this table. Rank is the archive's row order at that snapshot; not re-ranked here. Metric values are the archive's strings. Column headers sort the table in your browser; each row keeps its archive rank.
| Paper | Code | Ran Syntology | Report | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1 | Ahmadi et al. (2016): ENT, Bytes 1-G, STR, IMG1, IMG2, MD1, MISC, OPC, SEC, REG, DP, API, SYM, MD2 IMG and Opcode N-Grams + Ensemble Learning (XGBoost) | 0.9976 | 0.9931 | – | Paper | Code | 2020 | linked, not harvested | report | ||||
| 2 | HYDRA | 0.9975 | 0.9951 | – | Paper | Code | 2020 | linked, not harvested | report | ||||
| 3 | Zhang et al. (2016): Total lines of each Section, Operation Code Count, API Usage, Special Symbols Count, Asm File Pixel Intensity Feature, Bytes File Block Size Distribution, Bytes File N-Gram + Ensemble Learning (XGBoost) | 0.9974 | 0.9938 | – | Paper | Code | 2020 | linked, not harvested | report | ||||
| 4 | Orthrus | 0.9924 | 0.9872 | – | Paper | Code | 2020 | linked, not harvested | report | ||||
| 5 | Opcode-based Shallow CNN | 0.9917 | 0.0244 | 0.9856 | – | Paper | Code | 2017 | linked, not harvested | report | |||
| 6 | Hierarchical Convolutional Network | 0.9913 | 0.0419 | 0.9830 | – | Paper | – | 2019 | no code linked | report | |||
| 7 | SEA | 0.9912 | 0.0431 | 0.9908 | – | Paper | Code | 2023 | linked, not harvested | report | |||
| 8 | Dynamic Time Wrapping + K-NN | 0.9894 | 0.367724 | 0.9813 | – | Paper | Code | 2018 | linked, not harvested | report | |||
| 9 | Ahmadi et al. (2016): API feature vector + XGBoost | 0.9868 | 0.9638 | – | Paper | Code | 2020 | linked, not harvested | report | ||||
| 10 | Autoencoders+Residual Network | 0.9861 | 0.106343 | 0.9719 | – | Paper | – | 2018 | no code linked | report | |||
| 11 | Multiresolution CNN | 0.9828 | 0.124431 | 0.9636 | – | Paper | Code | 2018 | linked, not harvested | report | |||
| 12 | CNN+BiLSTM | 0.9820 | 0.0744 | 0.9605 | – | Paper | – | 2019 | no code linked | report | |||
| 13 | Scaled bytes sequence + CNN & Bidirectional LSTM | 0.9814 | 0.9662 | – | Paper | Code | 2020 | linked, not harvested | report | ||||
| 14 | Grayscale images + Opcode N-grams (Feature selection for malware classification) | 0.9770 | – | Paper | Code | 2020 | linked, not harvested | report | |||||
| 15 | DeepConv | 0.9756 | 0.1602 | 0.9071 | – | Paper | – | 2019 | no code linked | report | |||
| 16 | Gray-scale IMG CNN | 0.9750 | 0.184483 | 0.9400 | 0.973 | – | Paper | Code | 2018 | linked, not harvested | report | ||
| 17 | Hierarchical Attention Network | 0.9742 | 0.0933 | 0.9468 | – | Paper | – | 2019 | no code linked | report | |||
| 18 | Structural entropy CNN | 0.9708 | 0.134624 | 0.9314 | – | Paper | Code | 2018 | linked, not harvested | report | |||
| 19 | Narayanan et al. (2016): PCA features + 1-NN | 0.9660 | 0.9102 | – | Paper | Code | 2020 | linked, not harvested | report | ||||
| 20 | Deep Transferred Generative Adversarial Networks | 0.9639 | – | Paper | Code | 2020 | linked, not harvested | report | |||||
| 21 | Zero Rule Classifier | 0.2707 | – | Paper | Code | 2020 | linked, not harvested | report | |||||
| 22 | Random Guess Classifier | 0.1755 | – | Paper | Code | 2020 | linked, not harvested | report | |||||
| 23 | Multiresolution CNN + Bagging | 0.075081 | – | Paper | Code | 2018 | linked, not harvested | report | |||||
| 24 | MalConv | 0,9641 | 0.3071 | 0.8902 | – | Paper | – | 2019 | no code linked | report | |||
| 25 | TPOT Classifier | 98.94 | – | Paper | Code | 2021 | linked, not harvested | report | |||||
| 26 | CNN BiLSTM - Reb Sampl | 98.20 | 96.05 | – | Paper | Code | 2018 | linked, not harvested | report | ||||
| 27 | Haralick features + XGBoost | 0.9550 | – | Paper | Code | 2018 | linked, not harvested | report | |||||
| 28 | LBP features + XGBoost | 0.951 | – | Paper | Code | 2018 | linked, not harvested | report | |||||
| 29 | GA Designed Deep CNN | 0.9307 | – | Paper | – | 2022 | no code linked | report |
All 29 rows shown. 29 link to a paper page on this site; 0 are marked as using additional training data in the archive. No GitHub stars are tracked; "Code" is the first repository the archive lists for the row. The archive carries no row tags, review links or community-submitted rows for this table; none are shown. archive 2025-07-28
Syntology Ran reads "N of M ran · U unverified": of the M code samples Syntology harvested from repositories linked to that row's paper (joined by arXiv id), N executed on a synthesized input and the other U = M−N are unverified (harvested, no recorded run). It counts code from repositories linked to that row's paper, not this result: the row's number was not reproduced and nothing here is a correctness claim. The other cell texts mean no graph line for the row: "linked, not harvested" (the archive links code, Syntology has not harvested it), "no code linked" (no code link in the archive), "not matched" (the row's paper URL matched no paper on this site). 0 rows have a graph line, from 0 distinct papers; 0 rows (0 papers) have at least one sample that ran. Counting each paper once: Syntology ran 0 of 0 samples; 0 unverified. Separately, 0 of those 0 are pointer-only (licence): the site points at that code rather than redistributing it, a licence property recorded for ran and unverified samples alike; each cell's tooltip carries the row's own pointer-only count. Read from the graph 2026-09-24. Per-sample status is on the paper page.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections