{"url":"/task/malware-analysis","name":"Malware Analysis","slug":"malware-analysis","description_markdown":null,"categories":[],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":89,"papers_with_code":27,"benchmarks":0,"benchmark_tables_in_archive":0,"benchmark_tables_shown":0,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":3,"subtasks":0,"parent_tasks":0},"benchmarks":[],"datasets":[{"url":"/dataset/malimg","name":"Malimg","full_name":"","num_papers_in_archive":6},{"url":"/dataset/bodmas","name":"BODMAS","full_name":"Blue Hexagon Open Dataset for Malware AnalysiS","num_papers_in_archive":1},{"url":"/dataset/autorobust","name":"AutoRobust","full_name":"","num_papers_in_archive":0}],"subtasks":[],"parent_tasks":[],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":27,"of":27,"tagged_in_all":89,"items":[{"url":"/paper/safe-self-attentive-function-embeddings-for","title":"SAFE: Self-Attentive Function Embeddings for Binary Similarity","date":"2018-11-13","arxiv_id":"1811.05296","repositories_listed":3,"syntology":{"n":4,"n_ran":0,"n_unverified":4,"n_pointer_only":1}},{"url":"/paper/ember2024-a-benchmark-dataset-for-holistic","title":"EMBER2024 -- A Benchmark Dataset for Holistic Evaluation of Malware Classifiers","date":"2025-06-05","arxiv_id":"2506.05074","repositories_listed":2,"syntology":null},{"url":"/paper/evading-malware-classifiers-via-monte-carlo","title":"Evading Malware Classifiers via Monte Carlo Mutant Feature Discovery","date":"2021-06-15","arxiv_id":"2106.07860","repositories_listed":2,"syntology":null},{"url":"/paper/dynamic-malware-analysis-with-feature","title":"Dynamic Malware Analysis with Feature Engineering and Feature Learning","date":"2019-07-17","arxiv_id":"1907.07352","repositories_listed":2,"syntology":null},{"url":"/paper/decompilebench-a-comprehensive-benchmark-for","title":"DecompileBench: A Comprehensive Benchmark for Evaluating Decompilers in Real-World Scenarios","date":"2025-05-16","arxiv_id":"2505.11340","repositories_listed":1,"syntology":null},{"url":"/paper/cyberllminstruct-a-new-dataset-for-analysing","title":"CyberLLMInstruct: A New Dataset for Analysing Safety of Fine-Tuned LLMs Using Cyber Security Data","date":"2025-03-12","arxiv_id":"2503.09334","repositories_listed":1,"syntology":null},{"url":"/paper/is-function-similarity-over-engineered","title":"Is Function Similarity Over-Engineered? Building a Benchmark","date":"2024-10-30","arxiv_id":"2410.22677","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/magika-ai-powered-content-type-detection","title":"Magika: AI-Powered Content-Type Detection","date":"2024-09-18","arxiv_id":"2409.13768","repositories_listed":1,"syntology":null},{"url":"/paper/know-your-neighborhood-general-and-zero-shot","title":"Know Your Neighborhood: General and Zero-Shot Capable Binary Function Search Powered by Call Graphlets","date":"2024-06-02","arxiv_id":"2406.02606","repositories_listed":1,"syntology":null},{"url":"/paper/large-language-models-for-cyber-security-a","title":"Large Language Models for Cyber Security: A Systematic Literature Review","date":"2024-05-08","arxiv_id":"2405.04760","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/threat-behavior-textual-search-by-attention","title":"Threat Behavior Textual Search by Attention Graph Isomorphism","date":"2024-04-16","arxiv_id":"2404.10944","repositories_listed":1,"syntology":null},{"url":"/paper/nebula-self-attention-for-dynamic-malware","title":"Nebula: Self-Attention for Dynamic Malware Analysis","date":"2023-09-19","arxiv_id":"2310.10664","repositories_listed":1,"syntology":null},{"url":"/paper/finer-enhancing-state-of-the-art-classifiers","title":"FINER: Enhancing State-of-the-art Classifiers with Feature Attribution to Facilitate Security Analysis","date":"2023-08-10","arxiv_id":"2308.05362","repositories_listed":1,"syntology":null},{"url":"/paper/revisiting-deep-learning-for-variable-type","title":"Revisiting Deep Learning for Variable Type Recovery","date":"2023-04-07","arxiv_id":"2304.03854","repositories_listed":1,"syntology":null},{"url":"/paper/reliable-malware-analysis-and-detection-using","title":"Reliable Malware Analysis and Detection using Topology Data Analysis","date":"2022-11-03","arxiv_id":"2211.01535","repositories_listed":1,"syntology":null},{"url":"/paper/avast-ctu-public-cape-dataset","title":"Avast-CTU Public CAPE Dataset","date":"2022-09-06","arxiv_id":"2209.03188","repositories_listed":1,"syntology":null},{"url":"/paper/quo-vadis-hybrid-machine-learning-meta-model","title":"Quo Vadis: Hybrid Machine Learning Meta-Model based on Contextual and Behavioral Malware Representations","date":"2022-08-20","arxiv_id":"2208.12248","repositories_listed":1,"syntology":null},{"url":"/paper/scrutinizer-detecting-code-reuse-in-malware","title":"SCRUTINIZER: Detecting Code Reuse in Malware via Decompilation and Machine Learning","date":"2021-07-09","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/on-ensemble-learning","title":"On Ensemble Learning","date":"2021-03-07","arxiv_id":"2103.12521","repositories_listed":1,"syntology":null},{"url":"/paper/binary-black-box-evasion-attacks-against-deep","title":"Binary Black-box Evasion Attacks Against Deep Learning-based Static Malware Detectors with Adversarial Byte-Level Language Model","date":"2020-12-14","arxiv_id":"2012.07994","repositories_listed":1,"syntology":null},{"url":"/paper/interpreting-machine-learning-malware-1","title":"Interpreting Machine Learning Malware Detectors Which Leverage N-gram Analysis","date":"2020-01-27","arxiv_id":"2001.10916","repositories_listed":1,"syntology":null},{"url":"/paper/integration-of-static-and-dynamic-analysis","title":"Integration of Static and Dynamic Analysis for Malware Family Classification with Composite Neural Network","date":"2019-12-24","arxiv_id":"1912.11249","repositories_listed":1,"syntology":null},{"url":"/paper/malware-classification-using-deep-learning","title":"Malware Classification using Deep Learning based Feature Extraction and Wrapper based Feature Selection Technique","date":"2019-10-24","arxiv_id":"1910.10958","repositories_listed":1,"syntology":null},{"url":"/paper/kilograms-very-large-n-grams-for-malware","title":"KiloGrams: Very Large N-Grams for Malware Classification","date":"2019-08-01","arxiv_id":"1908.00200","repositories_listed":1,"syntology":null},{"url":"/paper/androdet-an-adaptive-android-obfuscation","title":"AndrODet: An Adaptive Android Obfuscation Detector","date":"2019-01-01","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/a-cross-architecture-instruction-embedding","title":"A Cross-Architecture Instruction Embedding Model for Natural Language Processing-Inspired Binary Code Analysis","date":"2018-12-23","arxiv_id":"1812.09652","repositories_listed":1,"syntology":null},{"url":"/paper/malware-triage-for-early-identification-of","title":"Malware triage for early identification of Advanced Persistent Threat activities","date":"2018-10-16","arxiv_id":"1810.07321","repositories_listed":1,"syntology":null}],"syntology_records":3,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}