{"url":"/task/malware-detection","name":"Malware Detection","slug":"malware-detection","description_markdown":"**Malware Detection** is a significant part of endpoint security including workstations, servers, cloud instances, and mobile devices. Malware Detection is used to detect and identify malicious activities caused by malware. With the increase in the variety of malware activities on CMS based websites such as [malicious malware redirects on WordPress site](https://secure.wphackedhelp.com/blog/wordpress-malware-redirect-hack-cleanup/) (Aka, WordPress Malware Redirect Hack) where the site redirects to spam, being the most widespread, the need for automatic detection and classifier amplifies as well. The signature-based Malware Detection system is commonly used for existing malware that has a signature but it is not suitable for unknown malware or zero-day malware\r\n\r\n\r\n<span class=\"description-source\">Source: [The Threat of Adversarial Attacks on Machine Learning in Network Security - A Survey ](https://arxiv.org/abs/1911.02621)</span>","categories":[{"name":"Miscellaneous","url":"/area/miscellaneous"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":431,"papers_with_code":108,"benchmarks":2,"benchmark_tables_in_archive":2,"benchmark_tables_shown":2,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":5,"subtasks":0,"parent_tasks":1},"benchmarks":[{"leaderboard":"/sota/malware-detection-on-android-malware-dataset","slug":"malware-detection-on-android-malware-dataset","dataset":"Android Malware Dataset","dataset_url":null,"rows_in_archive":4,"metrics":["Accuracy"],"first_row_in_archive_order":{"model":"Graph2Vec","paper_title":"graph2vec: Learning Distributed Representations of Graphs","paper_url":"/paper/graph2vec-learning-distributed","paper_date":"2017-07-17","arxiv_id":"1707.05005","code_links":[{"title":"benedekrozemberczki/karateclub","url":"https://github.com/benedekrozemberczki/karateclub"},{"title":"benedekrozemberczki/graph2vec","url":"https://github.com/benedekrozemberczki/graph2vec"},{"title":"MLDroid/graph2vec_tf","url":"https://github.com/MLDroid/graph2vec_tf"},{"title":"paulmorio/geo2dr","url":"https://github.com/paulmorio/geo2dr"},{"title":"compnet/pang","url":"https://github.com/compnet/pang"},{"title":"soumavaghosh/graph2vec","url":"https://github.com/soumavaghosh/graph2vec"}],"syntology":{"n":2,"n_ran":2,"n_unverified":0,"n_pointer_only":2}}},{"leaderboard":"/sota/malware-detection-on-malnet","slug":"malware-detection-on-malnet","dataset":"MalNet","dataset_url":"/dataset/malnet","rows_in_archive":3,"metrics":["F1 score"],"first_row_in_archive_order":{"model":"SHERLOCK (family)","paper_title":"Self-Supervised Vision Transformers for Malware Detection","paper_url":"/paper/self-supervised-vision-transformers-for","paper_date":"2022-08-15","arxiv_id":"2208.07049","code_links":[{"title":"sachith500/sherlock","url":"https://github.com/sachith500/sherlock"}],"syntology":{"n":8,"n_ran":4,"n_unverified":4,"n_pointer_only":0}}}],"datasets":[{"url":"/dataset/ember","name":"EMBER","full_name":"","num_papers_in_archive":115},{"url":"/dataset/malnet","name":"MalNet","full_name":"","num_papers_in_archive":17},{"url":"/dataset/bodmas","name":"BODMAS","full_name":"Blue Hexagon Open Dataset for Malware AnalysiS","num_papers_in_archive":1},{"url":"/dataset/iot-23","name":"IoT-23","full_name":"IoT-23: A labeled dataset with malicious and benign IoT network traffic","num_papers_in_archive":1},{"url":"/dataset/autorobust","name":"AutoRobust","full_name":"","num_papers_in_archive":0}],"subtasks":[],"parent_tasks":[{"url":"/task/malware-classification","name":"Malware Classification"}],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":108,"tagged_in_all":431,"items":[{"url":"/paper/malware-detection-by-eating-a-whole-exe","title":"Malware Detection by Eating a Whole EXE","date":"2017-10-25","arxiv_id":"1710.09435","repositories_listed":7,"syntology":{"n":7,"n_ran":0,"n_unverified":7,"n_pointer_only":0}},{"url":"/paper/deep-k-nearest-neighbors-towards-confident","title":"Deep k-Nearest Neighbors: Towards Confident, Interpretable and Robust Deep Learning","date":"2018-03-13","arxiv_id":"1803.04765","repositories_listed":4,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/generating-adversarial-malware-examples-for","title":"Generating Adversarial Malware Examples for Black-Box Attacks Based on GAN","date":"2017-02-20","arxiv_id":"1702.05983","repositories_listed":4,"syntology":null},{"url":"/paper/smart-semantic-malware-attribute-relevance","title":"Automatic Malware Description via Attribute Tagging and Similarity Embedding","date":"2019-05-15","arxiv_id":"1905.06262","repositories_listed":3,"syntology":null},{"url":"/paper/deepxplore-automated-whitebox-testing-of-deep","title":"DeepXplore: Automated Whitebox Testing of Deep Learning Systems","date":"2017-05-18","arxiv_id":"1705.06640","repositories_listed":3,"syntology":null},{"url":"/paper/subgraph2vec-learning-distributed","title":"subgraph2vec: Learning Distributed Representations of Rooted Sub-graphs from Large Graphs","date":"2016-06-29","arxiv_id":"1606.08928","repositories_listed":3,"syntology":null},{"url":"/paper/ember2024-a-benchmark-dataset-for-holistic","title":"EMBER2024 -- A Benchmark Dataset for Holistic Evaluation of Malware Classifiers","date":"2025-06-05","arxiv_id":"2506.05074","repositories_listed":2,"syntology":null},{"url":"/paper/continuous-learning-for-android-malware","title":"Continuous Learning for Android Malware Detection","date":"2023-02-08","arxiv_id":"2302.04332","repositories_listed":2,"syntology":null},{"url":"/paper/rs-del-edit-distance-robustness-certificates-1","title":"RS-Del: Edit Distance Robustness Certificates for Sequence Classifiers via Randomized Deletion","date":"2023-01-31","arxiv_id":"2302.01757","repositories_listed":2,"syntology":{"n":14,"n_ran":5,"n_unverified":9,"n_pointer_only":0}},{"url":"/paper/evading-malware-classifiers-via-monte-carlo","title":"Evading Malware Classifiers via Monte Carlo Mutant Feature Discovery","date":"2021-06-15","arxiv_id":"2106.07860","repositories_listed":2,"syntology":null},{"url":"/paper/adversarial-exemples-a-survey-and","title":"Adversarial EXEmples: A Survey and Experimental Evaluation of Practical Attacks on Machine Learning for Windows Malware Detection","date":"2020-08-17","arxiv_id":"2008.07125","repositories_listed":2,"syntology":null},{"url":"/paper/probabilistic-jacobian-based-saliency-maps","title":"Probabilistic Jacobian-based Saliency Maps Attacks","date":"2020-07-12","arxiv_id":"2007.06032","repositories_listed":2,"syntology":null},{"url":"/paper/sparse-rs-a-versatile-framework-for-query","title":"Sparse-RS: a versatile framework for query-efficient sparse black-box adversarial attacks","date":"2020-06-23","arxiv_id":"2006.12834","repositories_listed":2,"syntology":null},{"url":"/paper/dynamic-malware-analysis-with-feature","title":"Dynamic Malware Analysis with Feature Engineering and Feature Learning","date":"2019-07-17","arxiv_id":"1907.07352","repositories_listed":2,"syntology":null},{"url":"/paper/dont-paint-it-black-white-box-explanations","title":"Evaluating Explanation Methods for Deep Learning in Security","date":"2019-06-05","arxiv_id":"1906.02108","repositories_listed":2,"syntology":null},{"url":"/paper/efficient-formal-safety-analysis-of-neural","title":"Efficient Formal Safety Analysis of Neural Networks","date":"2018-09-19","arxiv_id":"1809.08098","repositories_listed":2,"syntology":null},{"url":"/paper/deepsign-deep-learning-for-automatic-malware","title":"DeepSign: Deep Learning for Automatic Malware Signature Generation and Classification","date":"2017-11-21","arxiv_id":"1711.08336","repositories_listed":2,"syntology":null},{"url":"/paper/learning-the-pe-header-malware-detection-with","title":"Learning the PE Header, Malware Detection with Minimal Domain Knowledge","date":"2017-09-05","arxiv_id":"1709.01471","repositories_listed":2,"syntology":null},{"url":"/paper/a-learning-model-to-detect-maliciousness-of","title":"A learning model to detect maliciousness of portable executable using integrated feature set","date":"2017-01-31","arxiv_id":null,"repositories_listed":2,"syntology":null},{"url":"/paper/lamda-a-longitudinal-android-malware","title":"LAMDA: A Longitudinal Android Malware Benchmark for Concept Drift Analysis","date":"2025-05-24","arxiv_id":"2505.18551","repositories_listed":1,"syntology":null},{"url":"/paper/evaluating-the-robustness-of-adversarial","title":"Evaluating the Robustness of Adversarial Defenses in Malware Detection Systems","date":"2025-05-14","arxiv_id":"2505.09342","repositories_listed":1,"syntology":null},{"url":"/paper/cyber-security-data-science-machine-learning","title":"Cyber Security Data Science: Machine Learning Methods and their Performance on Imbalanced Datasets","date":"2025-05-07","arxiv_id":"2505.04204","repositories_listed":1,"syntology":null},{"url":"/paper/imbalanced-malware-classification-an-approach","title":"Imbalanced malware classification: an approach based on dynamic classifier selection","date":"2025-03-30","arxiv_id":"2504.00041","repositories_listed":1,"syntology":null},{"url":"/paper/cyberllminstruct-a-new-dataset-for-analysing","title":"CyberLLMInstruct: A New Dataset for Analysing Safety of Fine-Tuned LLMs Using Cyber Security Data","date":"2025-03-12","arxiv_id":"2503.09334","repositories_listed":1,"syntology":null},{"url":"/paper/malware-detection-based-on-api-calls","title":"Malware Detection based on API calls","date":"2025-02-18","arxiv_id":"2502.12863","repositories_listed":1,"syntology":null},{"url":"/paper/crystal-ball-from-innovative-attacks-to","title":"Crystal ball: From innovative attacks to attack effectiveness classifier","date":"2024-12-24","arxiv_id":null,"repositories_listed":1,"syntology":null},{"url":"/paper/maskdroid-robust-android-malware-detection","title":"MASKDROID: Robust Android Malware Detection with Masked Graph Representations","date":"2024-09-29","arxiv_id":"2409.19594","repositories_listed":1,"syntology":null},{"url":"/paper/accelerating-malware-classification-a-vision","title":"Accelerating Malware Classification: A Vision Transformer Solution","date":"2024-09-28","arxiv_id":"2409.19461","repositories_listed":1,"syntology":{"n":1,"n_ran":0,"n_unverified":1,"n_pointer_only":0}},{"url":"/paper/detectbert-towards-full-app-level","title":"DetectBERT: Towards Full App-Level Representation Learning to Detect Android Malware","date":"2024-08-29","arxiv_id":"2408.16353","repositories_listed":1,"syntology":null},{"url":"/paper/improving-adversarial-robustness-in-android","title":"Improving Adversarial Robustness in Android Malware Detection by Reducing the Impact of Spurious Correlations","date":"2024-08-27","arxiv_id":"2408.16025","repositories_listed":1,"syntology":null}],"syntology_records":4,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}