Browse › Miscellaneous › Malware Detection › MalNet
MalNet Benchmark (Malware Detection)
Malware Detection is a significant part of endpoint security including workstations, servers, cloud instances, and mobile devices. Malware Detection is used to detect and identify malicious activities caused by malware. With the increase in the variety of malware activities on CMS based websites such as malicious malware redirects on WordPress site (Aka, WordPress Malware Redirect Hack) where the site redirects to spam, being the most widespread, the need for automatic detection and classifier amplifies as well. The signature-based Malware Detection system is commonly used for existing malware that has a signature but it is not suitable for unknown malware or zero-day malware
Source: The Threat of Adversarial Attacks on Machine Learning in Network Security - A Survey
The archive carries no text for this table; the description above is the archive's text for the task Malware Detection. archive 2025-07-28
Over time archive 2025-07-28
The chart needs JavaScript; the table below carries every value.
Direction inferred from the metric name, not from the archive: F1 score (higher is better). Points are placed at the row's paper date; 3 of 3 rows carry one.
Results archive 2025-07-28
Archive rows end at the archive snapshot, 2025-07-28: no result published after that date is in this table. Rank is the archive's row order at that snapshot; not re-ranked here. Metric values are the archive's strings. Column headers sort the table in your browser; each row keeps its archive rank.
| Paper | Code | Ran Syntology | Report | |||||
|---|---|---|---|---|---|---|---|---|
| 1 | SHERLOCK (family) | 0.878 | – | Paper | Code | 2022 | 4 of 8 ran · 4 unverified | report |
| 2 | SHERLOCK (type) | 0.876 | – | Paper | Code | 2022 | 4 of 8 ran · 4 unverified | report |
| 3 | SHERLOCK | 0.854 | – | Paper | Code | 2022 | 4 of 8 ran · 4 unverified | report |
All 3 rows shown. 3 link to a paper page on this site; 0 are marked as using additional training data in the archive. No GitHub stars are tracked; "Code" is the first repository the archive lists for the row. The archive carries no row tags, review links or community-submitted rows for this table; none are shown. archive 2025-07-28
Syntology Ran reads "N of M ran · U unverified": of the M code samples Syntology harvested from repositories linked to that row's paper (joined by arXiv id), N executed on a synthesized input and the other U = M−N are unverified (harvested, no recorded run). It counts code from repositories linked to that row's paper, not this result: the row's number was not reproduced and nothing here is a correctness claim. The other cell texts mean no graph line for the row: "linked, not harvested" (the archive links code, Syntology has not harvested it), "no code linked" (no code link in the archive), "not matched" (the row's paper URL matched no paper on this site). 3 rows have a graph line, from 1 distinct papers; 3 rows (1 papers) have at least one sample that ran. Counting each paper once: Syntology ran 4 of 8 samples; 4 unverified. Separately, 0 of those 8 are pointer-only (licence): the site points at that code rather than redistributing it, a licence property recorded for ran and unverified samples alike; each cell's tooltip carries the row's own pointer-only count. Read from the graph 2026-09-24. Per-sample status is on the paper page.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections