{"about":{"non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","site":"https://codewithpapers.app","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page","syntology":{"site":"https://syntology.ai","developers":"https://syntology.ai/developers","mcp":{"server":"https://syntology.ai/mcp","transport":"streamable-http","server_card":"https://syntology.ai/.well-known/mcp/server-card.json","auth":{"type":"trial token, no account","trial_token":"https://syntology.ai/api/oauth/trial/token","method":"POST","docs":"https://syntology.ai/developers"}},"have":"https://syntology.ai/api/graph/have?x=<method, arXiv id or title> (free, answers coverage only)","paper_base":"https://syntology.ai/paper/","atlas_base":"https://app.syntology.ai/?focus="},"machine_readable":[{"url":"https://codewithpapers.app/llms.txt","what":"the machine catalog: every machine-readable file, counted"},{"url":"https://codewithpapers.app/index/manifest.json","what":"paper-to-code index by arXiv id, with Syntology's counts"},{"url":"https://codewithpapers.app/search/manifest.json","what":"site search index (titles, authors) and its files"},{"url":"https://codewithpapers.app/download","what":"bulk files: Syntology's layer, described there"},{"url":"https://codewithpapers.app/build_manifest.json","what":"the build record: inputs, counts, exclusions, probes"}]},"url":"/task/malware-classification/papers/2","list_of":"/task/malware-classification","task":"Malware Classification","archive":{"snapshot":"2025-07-28"},"key_notes":{"n_ran_checked":"legacy name, kept unchanged so existing readers do not break: it counts the samples that ran with no instrument failure (honoured, violated, and ran with no contract checked); it does not mean a contract was checked, and the pages print it as 'K with no instrument failure', not 'K checked'","n_constructed":"a sub-count of the samples that ran, never subtracted from them and never a failure: an executed sample whose run returned an instance of its own class (fixture_out_type equals the entry name): the run built an object and did not compute a result (Syntology's RAN record, counts.constructed)"},"syntology_read_at":"2026-09-28T10:30:06+00:00","order":"archive","order_definition":"repositories listed in the archive (most first), then date (newest first), then slug","page":2,"pages_in_order":2,"rows_per_page":100,"rows":[101,146],"of":146,"counts":{"archive_papers_tagged":146,"with_a_code_link":47,"where_syntology_ran_a_sample":5,"not_listed_spam_title":0,"listed":146,"listed_where_code_ran":5,"where_syntology_ran_a_sample_split":{"with_a_run_with_no_instrument_failure":4,"every_run_a_failure_of_syntologys_instrument":1,"listed_with_a_run_with_no_instrument_failure":4,"listed_every_run_a_failure_of_syntologys_instrument":1,"filter":{"states":["a run with no instrument failure","any run, instrument failures included"],"default":"a run with no instrument failure","note":"on the 'only where code ran' pages the default hides, in the browser, the rows where every run was a failure of Syntology's instrument; the second state shows them again. Rows are hidden, never re-ordered; these twins list every row"}},"definition":"distinct papers the archive tags; 'where Syntology ran a sample' counts papers with at least one harvested sample that ran, which is not a correctness claim"},"first_page":"/task/malware-classification","prev":"/task/malware-classification","next":null,"papers":[{"url":null,"slug":"cnn-vs-elm-for-image-based-malware","title":"CNN vs ELM for Image-Based Malware Classification","date":"2021-03-24","arxiv_id":"2103.13820","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-comparison-of-word2vec-hmm2vec-and-pca2vec","title":"A Comparison of Word2Vec, HMM2Vec, and PCA2Vec for Malware Classification","date":"2021-03-07","arxiv_id":"2103.05763","repositories_listed":0,"syntology":null},{"url":null,"slug":"malware-classification-using-long-short-term","title":"Malware Classification Using Long Short-Term Memory Models","date":"2021-03-03","arxiv_id":"2103.02746","repositories_listed":0,"syntology":null},{"url":null,"slug":"malware-classification-with-gmm-hmm-models","title":"Malware Classification with GMM-HMM Models","date":"2021-03-03","arxiv_id":"2103.02753","repositories_listed":0,"syntology":null},{"url":null,"slug":"malware-classification-with-word-embedding","title":"Malware Classification with Word Embedding Features","date":"2021-03-03","arxiv_id":"2103.02711","repositories_listed":0,"syntology":null},{"url":null,"slug":"universal-adversarial-perturbations-for-1","title":"Realizable Universal Adversarial Perturbations for Malware","date":"2021-02-12","arxiv_id":"2102.06747","repositories_listed":0,"syntology":null},{"url":null,"slug":"classifying-malware-using-function","title":"Classifying Malware Using Function Representations in a Static Call Graph","date":"2020-12-01","arxiv_id":"2012.01939","repositories_listed":0,"syntology":null},{"url":null,"slug":"classifying-malware-images-with-convolutional","title":"Classifying Malware Images with Convolutional Neural Network Models","date":"2020-10-30","arxiv_id":"2010.16108","repositories_listed":0,"syntology":null},{"url":null,"slug":"malware-traffic-classification-evaluation-of","title":"Malware Traffic Classification: Evaluation of Algorithms and an Automated Ground-truth Generation Pipeline","date":"2020-10-22","arxiv_id":"2010.11627","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-survey-of-machine-learning-methods-and","title":"A Survey of Machine Learning Methods and Challenges for Windows Malware Classification","date":"2020-06-15","arxiv_id":"2006.09271","repositories_listed":0,"syntology":null},{"url":null,"slug":"provable-trade-offs-between-private-robust","title":"Trade-offs between membership privacy & adversarially robust learning","date":"2020-06-08","arxiv_id":"2006.04622","repositories_listed":0,"syntology":null},{"url":null,"slug":"high-accuracy-malware-classification-with-a","title":"Exploring Optimal Deep Learning Models for Image-based Malware Variant Classification","date":"2020-04-10","arxiv_id":"2004.05258","repositories_listed":0,"syntology":null},{"url":null,"slug":"deep-learning-and-open-set-malware","title":"Deep Learning and Open Set Malware Classification: A Survey","date":"2020-04-08","arxiv_id":"2004.04272","repositories_listed":0,"syntology":null},{"url":null,"slug":"feature-level-malware-obfuscation-in-deep","title":"Feature-level Malware Obfuscation in Deep Learning","date":"2020-02-10","arxiv_id":"2002.05517","repositories_listed":0,"syntology":null},{"url":null,"slug":"cant-boil-this-frog-robustness-of-online","title":"Can't Boil This Frog: Robustness of Online-Trained Autoencoder-Based Anomaly Detectors to Adversarial Poisoning Attacks","date":"2020-02-07","arxiv_id":"2002.02741","repositories_listed":0,"syntology":null},{"url":"/paper/a-hierarchical-convolutional-neural-network","slug":"a-hierarchical-convolutional-neural-network","title":"A Hierarchical Convolutional Neural Network for Malware Classification","date":"2019-09-30","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"effectiveness-of-adversarial-examples-and","title":"Effectiveness of Adversarial Examples and Defenses for Malware Classification","date":"2019-09-10","arxiv_id":"1909.04778","repositories_listed":0,"syntology":null},{"url":null,"slug":"intelligent-systems-design-for-malware","title":"Intelligent Systems Design for Malware Classification Under Adversarial Conditions","date":"2019-07-06","arxiv_id":"1907.03149","repositories_listed":0,"syntology":null},{"url":null,"slug":"to-believe-or-not-to-believe-validating","title":"To believe or not to believe: Validating explanation fidelity for dynamic malware analysis","date":"2019-04-30","arxiv_id":"1905.00122","repositories_listed":0,"syntology":null},{"url":null,"slug":"short-paper-creating-adversarial-malware","title":"Generation & Evaluation of Adversarial Examples for Malware Obfuscation","date":"2019-04-09","arxiv_id":"1904.04802","repositories_listed":0,"syntology":null},{"url":null,"slug":"malware-detection-using-machine-learning-and","title":"Malware Detection using Machine Learning and Deep Learning","date":"2019-04-04","arxiv_id":"1904.02441","repositories_listed":0,"syntology":null},{"url":null,"slug":"190410504","title":"Understanding the efficacy, reliability and resiliency of computer vision techniques for malware detection and future research directions","date":"2019-04-03","arxiv_id":"1904.10504","repositories_listed":0,"syntology":null},{"url":null,"slug":"detection-of-advanced-malware-by-machine","title":"Detection of Advanced Malware by Machine Learning Techniques","date":"2019-03-07","arxiv_id":"1903.02966","repositories_listed":0,"syntology":null},{"url":null,"slug":"examining-adversarial-learning-against-graph","title":"Examining Adversarial Learning against Graph-based IoT Malware Detection Systems","date":"2019-02-12","arxiv_id":"1902.04416","repositories_listed":0,"syntology":null},{"url":null,"slug":"rnnsecurenet-recurrent-neural-networks-for","title":"RNNSecureNet: Recurrent neural networks for Cyber security use-cases","date":"2019-01-05","arxiv_id":"1901.04281","repositories_listed":0,"syntology":null},{"url":null,"slug":"projecting-better-than-randomly-how-to-reduce","title":"Projecting \"better than randomly\": How to reduce the dimensionality of very large datasets in a way that outperforms random projections","date":"2019-01-03","arxiv_id":"1901.00630","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-short-review-on-applications-of-deep","title":"A short review on Applications of Deep learning for Cyber security","date":"2018-12-15","arxiv_id":"1812.06292","repositories_listed":0,"syntology":null},{"url":null,"slug":"behavioral-malware-classification-using","title":"Behavioral Malware Classification using Convolutional Recurrent Neural Networks","date":"2018-11-19","arxiv_id":"1811.07842","repositories_listed":0,"syntology":null},{"url":null,"slug":"exploring-adversarial-examples-in-malware","title":"Exploring Adversarial Examples in Malware Detection","date":"2018-10-18","arxiv_id":"1810.08280","repositories_listed":0,"syntology":null},{"url":null,"slug":"deep-net-deep-neural-network-for-cyber-1","title":"Deep-Net: Deep Neural Network for Cyber Security Use Cases","date":"2018-10-12","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"rnnsecurenet-recurrent-neural-networks-for-1","title":"RNNSecureNet: Recurrent neural networks for Cybersecurity use-cases","date":"2018-10-12","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":"/paper/an-end-to-end-deep-learning-architecture-for-1","slug":"an-end-to-end-deep-learning-architecture-for-1","title":"An End-to-End Deep Learning Architecture for Classification of Malware’s Binary Content","date":"2018-09-27","arxiv_id":null,"repositories_listed":0,"syntology":null},{"url":null,"slug":"hashtran-dnn-a-framework-for-enhancing","title":"HashTran-DNN: A Framework for Enhancing Robustness of Deep Neural Networks against Adversarial Malware Samples","date":"2018-09-18","arxiv_id":"1809.06498","repositories_listed":0,"syntology":null},{"url":null,"slug":"comparison-of-deep-learning-and-the-classical","title":"Comparison of Deep Learning and the Classical Machine Learning Algorithm for the Malware Detection","date":"2018-09-16","arxiv_id":"1809.05889","repositories_listed":0,"syntology":null},{"url":null,"slug":"tesseract-eliminating-experimental-bias-in","title":"TESSERACT: Eliminating Experimental Bias in Malware Classification across Space and Time","date":"2018-07-20","arxiv_id":"1807.07838","repositories_listed":0,"syntology":null},{"url":null,"slug":"defending-malware-classification-networks","title":"Defending Malware Classification Networks Against Adversarial Perturbations with Non-Negative Weight Restrictions","date":"2018-06-23","arxiv_id":"1806.09035","repositories_listed":0,"syntology":null},{"url":null,"slug":"generative-models-for-spear-phishing-posts-on","title":"Generative Models for Spear Phishing Posts on Social Media","date":"2018-02-14","arxiv_id":"1802.05196","repositories_listed":0,"syntology":null},{"url":null,"slug":"computer-activity-learning-from-system-call","title":"Computer activity learning from system call time series","date":"2017-11-06","arxiv_id":"1711.02088","repositories_listed":0,"syntology":null},{"url":null,"slug":"on-the-statistical-detection-of-adversarial","title":"On the (Statistical) Detection of Adversarial Examples","date":"2017-02-21","arxiv_id":"1702.06280","repositories_listed":0,"syntology":null},{"url":null,"slug":"sok-applying-machine-learning-in-security-a","title":"SoK: Applying Machine Learning in Security - A Survey","date":"2016-11-10","arxiv_id":"1611.03186","repositories_listed":0,"syntology":null},{"url":null,"slug":"a-multi-task-learning-model-for-malware","title":"A multi-task learning model for malware classification with useful file access pattern from API call sequence","date":"2016-10-19","arxiv_id":"1610.05945","repositories_listed":0,"syntology":null},{"url":null,"slug":"one-class-svm-with-privileged-information-and","title":"One-Class SVM with Privileged Information and its Application to Malware Detection","date":"2016-09-26","arxiv_id":"1609.08039","repositories_listed":0,"syntology":null},{"url":null,"slug":"random-forest-for-malware-classification","title":"Random Forest for Malware Classification","date":"2016-09-25","arxiv_id":"1609.07770","repositories_listed":0,"syntology":null},{"url":null,"slug":"n-opcode-analysis-for-android-malware","title":"N-opcode Analysis for Android Malware Classification and Categorization","date":"2016-07-27","arxiv_id":"1607.08149","repositories_listed":0,"syntology":null},{"url":null,"slug":"adversarial-perturbations-against-deep-neural","title":"Adversarial Perturbations Against Deep Neural Networks for Malware Classification","date":"2016-06-14","arxiv_id":"1606.04435","repositories_listed":0,"syntology":null},{"url":null,"slug":"detection-under-privileged-information","title":"Detection under Privileged Information","date":"2016-03-31","arxiv_id":"1603.09638","repositories_listed":0,"syntology":null}],"record_sha256":"f96a466d469e7d0eb96e13086c842ffb79df8792e0f6aabfd7d54b6d3302321b","record_changed_at":"2026-09-28","record_changed_at_basis":"first_hashed"}