Browse State-of-the-Art › Malware Analysis
Malware Analysis
27 papers with code · 0 benchmarks · 3 datasets archive 2025-07-28
Benchmarks archive 2025-07-28
No benchmark for this task in the archive.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
3 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
No subtask under this task in the archive's task tree.
Most implemented papers archive 2025-07-28
27 shown of 27 papers with code (89 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
13 Nov 2018 3 repositories listed Syntology ran 0 of 4 samples · 4 unverified · 1 pointer-only (licence)We report the results from a quantitative and qualitative analysis that show how SAFE provides a noticeable performance improvement with respect to previous solutions.
-
5 Jun 2025 2 repositories listedA lack of accessible data has historically restricted malware analysis research, and practitioners have relied heavily on datasets provided by industry sources to advance.
-
15 Jun 2021 2 repositories listedThe use of Machine Learning has become a significant part of malware detection efforts due to the influx of new malware, an ever changing threat landscape, and the ability of Machine Learning methods to discover…
-
17 Jul 2019 2 repositories listedIn this paper, we propose a novel and low-cost feature extraction approach, and an effective deep neural network architecture for accurate and fast malware detection.
-
16 May 2025 1 repository listedDecompilers are fundamental tools for critical security tasks, from vulnerability discovery to malware analysis, yet their evaluation remains fragmented.
-
12 Mar 2025 1 repository listedIn our primary example, we rigorously assess the safety of fine-tuned models using the OWASP top 10 framework, finding that fine-tuning reduces safety resilience across all tested LLMs and every adversarial attack (e.
-
30 Oct 2024 1 repository listed Syntology ran 1 of 1 samples · 0 unverifiedBinary analysis is a core component of many critical security tasks, including reverse engineering, malware analysis, and vulnerability detection.
-
18 Sep 2024 1 repository listedIn order to foster adoption and improvements, we open source Magika under an Apache 2 license on GitHub and make our model and training pipeline publicly available.
-
2 Jun 2024 1 repository listedBinary code similarity detection is an important problem with applications in areas such as malware analysis, vulnerability research and license violation detection.
-
8 May 2024 1 repository listed Syntology ran 3 of 3 samples · 0 unverifiedOverall, our survey provides a comprehensive overview of the current state-of-the-art in LLM4Security and identifies several promising directions for future research.
-
16 Apr 2024 1 repository listedAs such, analysts often resort to text search techniques to identify existing malware reports based on the symptoms they observe, exploiting the fact that malware samples share a lot of similarity, especially those from…
-
19 Sep 2023 1 repository listedDynamic analysis enables detecting Windows malware by executing programs in a controlled environment and logging their actions.
-
10 Aug 2023 1 repository listedAlthough feature attribution (FA) methods can be used to explain deep learning, the underlying classifier is still blind to what behavior is suspicious, and the generated explanation cannot adapt to downstream tasks,…
-
7 Apr 2023 1 repository listedUnfortunately, the lack of semantic information like variable types makes comprehending binaries difficult.
-
3 Nov 2022 1 repository listedNext, we compare the different TDA techniques (i.
-
6 Sep 2022 1 repository listedThe benefit of using dynamic sandboxes is the realistic simulation of file execution in the target machine and obtaining a log of such execution.
-
20 Aug 2022 1 repository listedThe detection heuristic in contemporary machine learning Windows malware classifiers is typically based on the static properties of the sample since dynamic analysis through virtualization is challenging for vast…
-
9 Jul 2021 1 repository listedIn response to such attacks, both academia and industry have investigated techniques to model and reconstruct these attacks and to defend against them.
-
7 Mar 2021 1 repository listedOur common framework and empirical results are an effort to bring some sense of order to the chaos that is evident in the evolving field of ensemble learning -- both within the narrow confines of the malware analysis…
-
14 Dec 2020 1 repository listedRecently, deep learning-based static anti-malware detectors have achieved success in identifying unseen attacks without requiring feature engineering and dynamic analysis.
-
27 Jan 2020 1 repository listedThis is because the models are complex, and most of them work as a black-box.
-
24 Dec 2019 1 repository listedIn this paper, we combine static and dynamic analysis features with deep neural networks for Windows malware classification.
-
24 Oct 2019 1 repository listedThe proposed DLMD technique uses both the byte and ASM files for feature engineering, thus classifying malware families.
-
1 Aug 2019 1 repository listedN-grams have been a common tool for information retrieval and machine learning applications for decades.
-
1 Jan 2019 1 repository listedThis is typically applied to protect intellectual property in benign apps, or to hinder the process of extracting actionable information in the case malware.
-
23 Dec 2018 1 repository listedAs a showcase, we apply the model to resolving one of the most fundamental problems for binary code similarity comparison---semantics-based basic block comparison, and the solution outperforms the code statistics based…
-
16 Oct 2018 1 repository listedIn order to early identify APT related malware, a semi-automatic approach for malware samples analysis is needed.
Syntology lines on 3 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections