DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
The existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen’s...
| Autores: | , , , , , , , , |
|---|---|
| Tipo de recurso: | artículo |
| Fecha de publicación: | 2025 |
| País: | España |
| Institución: | Universitat Politècnica de Catalunya (UPC) |
| Repositorio: | UPCommons. Portal del coneixement obert de la UPC |
| Idioma: | inglés |
| OAI Identifier: | oai:upcommons.upc.edu:2117/429903 |
| Acceso en línea: | https://hdl.handle.net/2117/429903 https://dx.doi.org/10.1186/s42400-025-00396-z |
| Access Level: | acceso abierto |
| Palabra clave: | Malware detection Malware obfuscation Computer vision Transfer learning Deep learning Networking system of artificial intelligence Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica |
| id |
ES_22932f3a04e78d6c8598365b83f86d6b |
|---|---|
| oai_identifier_str |
oai:upcommons.upc.edu:2117/429903 |
| network_acronym_str |
ES |
| network_name_str |
España |
| repository_id_str |
|
| spelling |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware frameworkCastillo Camargo, RodrigoMurcia Nieto, JuanRojas, NicolásDíaz López, DanielAlférez Baquero, Edwin Santiago|||0000-0001-8661-1096Perales Gómez, Angel LuisNespoli, PantaleoneGómez Mármol, FélixKarabiyik, UmitMalware detectionMalware obfuscationComputer visionTransfer learningDeep learningNetworking system of artificial intelligenceÀrees temàtiques de la UPC::Informàtica::Seguretat informàticaThe existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen’s device and reaching critical information systems. To detect malware families, Machine Learning and Deep Learning techniques have been employed recently, demonstrating promising results. However, these techniques lack in detecting more advanced malware that employs obfuscation techniques. In this paper, we present DEFENDIFY, a novel framework, empowered by Computer Vision, Deep Learning, and Transfer Learning techniques, that is able to detect completely obfuscated malware with high performance in terms of accuracy and computational consumption. DEFENDIFY comprises three modules: Dataset Creation, Binary Obfuscation, and Model Generation. These modules work together to detect both obfuscated and nonobfuscated malware. The core module, i.e., the Model Generation, employs an entropy tester that determines whether a sample is obfuscated or not. Then, a Deep Learning model powered by Transfer Learning is employed to determine if it is malware or goodware. We validated our framework using real data gathered from malware repositories and legitimate software. The proposed framework was configured to test four Convolutional Neural Network architectures: ResNet18, ResNet34, EfficientNetB3, and EfficientNetV2S. Among them, the ResNet18 architecture obtained the best performance in detecting both non-obfuscated and obfuscated samples with an F1-score of 99.34% and 97.5%, respectively.This work has been partially funded by the School of Engineering, Science and Technology at Universidad del Rosario (Colombia) through a “Beca de Estancia de Docencia e Investigación ‑ EDI 2022‑1”, by MCIN/AEI/ 10.13039/501100011033, NextGenerationEU/PRTR, UE, under Grant TED 2021129300B‑I00, by MCIN / AEI / 10.13039 / 501100011033 / FEDER, UE, under Grant PID2021 ‑ 122466OB ‑ I00, the strategic project DEFENDER from the Spanish National Institute of Cybersecurity (INCIBE), by the Recovery, Transformation and Resilience Plan, Next Generation EU, and by the Spanish Ministry of Universities linked to the European Union through the NextGenerationEU program, under Margarita Salas postdoctoral fellowship (172/MSJD/22). This work has also been partially funded by the Nvidia Academic Grant Program through GPU instances provided by Saturn Cloud.Peer ReviewedSpringer20252025-12-0120252025-05-20journal articlehttp://purl.org/coar/resource_type/c_6501VoRhttp://purl.org/coar/version/c_970fb48d4fbd8a85info:eu-repo/semantics/articleapplication/pdfhttps://hdl.handle.net/2117/429903https://dx.doi.org/10.1186/s42400-025-00396-zreponame:UPCommons. Portal del coneixement obert de la UPCinstname:Universitat Politècnica de Catalunya (UPC)InglésengAgencia Estatal de Investigación http://doi.org/10.13039/501100011033 Plan Estatal de Investigación Científica y Técnica y de Innovación 2021-2023 PID2021-122466OB-I00 GESTION ROBUSTA, INTERPRETABLE Y ORIENTADA A HUMANOS DE LA CIBERSEGURIDAD Y LA SEGURIDAD EN LA INDUSTRIA 5.0open accesshttp://purl.org/coar/access_right/c_abf2Attribution 4.0 Internationalhttp://creativecommons.org/licenses/by/4.0/info:eu-repo/semantics/openAccessoai:upcommons.upc.edu:2117/4299032026-05-27T15:37:01Z |
| dc.title.none.fl_str_mv |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework |
| title |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework |
| spellingShingle |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework Castillo Camargo, Rodrigo Malware detection Malware obfuscation Computer vision Transfer learning Deep learning Networking system of artificial intelligence Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica |
| title_short |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework |
| title_full |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework |
| title_fullStr |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework |
| title_full_unstemmed |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework |
| title_sort |
DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework |
| dc.creator.none.fl_str_mv |
Castillo Camargo, Rodrigo Murcia Nieto, Juan Rojas, Nicolás Díaz López, Daniel Alférez Baquero, Edwin Santiago|||0000-0001-8661-1096 Perales Gómez, Angel Luis Nespoli, Pantaleone Gómez Mármol, Félix Karabiyik, Umit |
| author |
Castillo Camargo, Rodrigo |
| author_facet |
Castillo Camargo, Rodrigo Murcia Nieto, Juan Rojas, Nicolás Díaz López, Daniel Alférez Baquero, Edwin Santiago|||0000-0001-8661-1096 Perales Gómez, Angel Luis Nespoli, Pantaleone Gómez Mármol, Félix Karabiyik, Umit |
| author_role |
author |
| author2 |
Murcia Nieto, Juan Rojas, Nicolás Díaz López, Daniel Alférez Baquero, Edwin Santiago|||0000-0001-8661-1096 Perales Gómez, Angel Luis Nespoli, Pantaleone Gómez Mármol, Félix Karabiyik, Umit |
| author2_role |
author author author author author author author author |
| dc.subject.none.fl_str_mv |
Malware detection Malware obfuscation Computer vision Transfer learning Deep learning Networking system of artificial intelligence Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica |
| topic |
Malware detection Malware obfuscation Computer vision Transfer learning Deep learning Networking system of artificial intelligence Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica |
| description |
The existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen’s device and reaching critical information systems. To detect malware families, Machine Learning and Deep Learning techniques have been employed recently, demonstrating promising results. However, these techniques lack in detecting more advanced malware that employs obfuscation techniques. In this paper, we present DEFENDIFY, a novel framework, empowered by Computer Vision, Deep Learning, and Transfer Learning techniques, that is able to detect completely obfuscated malware with high performance in terms of accuracy and computational consumption. DEFENDIFY comprises three modules: Dataset Creation, Binary Obfuscation, and Model Generation. These modules work together to detect both obfuscated and nonobfuscated malware. The core module, i.e., the Model Generation, employs an entropy tester that determines whether a sample is obfuscated or not. Then, a Deep Learning model powered by Transfer Learning is employed to determine if it is malware or goodware. We validated our framework using real data gathered from malware repositories and legitimate software. The proposed framework was configured to test four Convolutional Neural Network architectures: ResNet18, ResNet34, EfficientNetB3, and EfficientNetV2S. Among them, the ResNet18 architecture obtained the best performance in detecting both non-obfuscated and obfuscated samples with an F1-score of 99.34% and 97.5%, respectively. |
| publishDate |
2025 |
| dc.date.none.fl_str_mv |
2025 2025-12-01 2025 2025-05-20 |
| dc.type.none.fl_str_mv |
journal article http://purl.org/coar/resource_type/c_6501 VoR http://purl.org/coar/version/c_970fb48d4fbd8a85 |
| dc.type.openaire.fl_str_mv |
info:eu-repo/semantics/article |
| format |
article |
| dc.identifier.none.fl_str_mv |
https://hdl.handle.net/2117/429903 https://dx.doi.org/10.1186/s42400-025-00396-z |
| url |
https://hdl.handle.net/2117/429903 https://dx.doi.org/10.1186/s42400-025-00396-z |
| dc.language.none.fl_str_mv |
Inglés eng |
| language_invalid_str_mv |
Inglés |
| language |
eng |
| dc.relation.none.fl_str_mv |
Agencia Estatal de Investigación http://doi.org/10.13039/501100011033 Plan Estatal de Investigación Científica y Técnica y de Innovación 2021-2023 PID2021-122466OB-I00 GESTION ROBUSTA, INTERPRETABLE Y ORIENTADA A HUMANOS DE LA CIBERSEGURIDAD Y LA SEGURIDAD EN LA INDUSTRIA 5.0 |
| dc.rights.none.fl_str_mv |
open access http://purl.org/coar/access_right/c_abf2 Attribution 4.0 International http://creativecommons.org/licenses/by/4.0/ |
| dc.rights.openaire.fl_str_mv |
info:eu-repo/semantics/openAccess |
| rights_invalid_str_mv |
open access http://purl.org/coar/access_right/c_abf2 Attribution 4.0 International http://creativecommons.org/licenses/by/4.0/ |
| eu_rights_str_mv |
openAccess |
| dc.format.none.fl_str_mv |
application/pdf |
| dc.publisher.none.fl_str_mv |
Springer |
| publisher.none.fl_str_mv |
Springer |
| dc.source.none.fl_str_mv |
reponame:UPCommons. Portal del coneixement obert de la UPC instname:Universitat Politècnica de Catalunya (UPC) |
| instname_str |
Universitat Politècnica de Catalunya (UPC) |
| reponame_str |
UPCommons. Portal del coneixement obert de la UPC |
| collection |
UPCommons. Portal del coneixement obert de la UPC |
| repository.name.fl_str_mv |
|
| repository.mail.fl_str_mv |
|
| _version_ |
1869404589753630720 |
| score |
15.223283 |