DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework

The existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen’s...

Descripción completa

Detalles Bibliográficos
Autores: Castillo Camargo, Rodrigo, Murcia Nieto, Juan, Rojas, Nicolás, Díaz López, Daniel, Alférez Baquero, Edwin Santiago|||0000-0001-8661-1096, Perales Gómez, Angel Luis, Nespoli, Pantaleone, Gómez Mármol, Félix, Karabiyik, Umit
Tipo de recurso: artículo
Fecha de publicación:2025
País:España
Institución:Universitat Politècnica de Catalunya (UPC)
Repositorio:UPCommons. Portal del coneixement obert de la UPC
Idioma:inglés
OAI Identifier:oai:upcommons.upc.edu:2117/429903
Acceso en línea:https://hdl.handle.net/2117/429903
https://dx.doi.org/10.1186/s42400-025-00396-z
Access Level:acceso abierto
Palabra clave:Malware detection
Malware obfuscation
Computer vision
Transfer learning
Deep learning
Networking system of artificial intelligence
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
id ES_22932f3a04e78d6c8598365b83f86d6b
oai_identifier_str oai:upcommons.upc.edu:2117/429903
network_acronym_str ES
network_name_str España
repository_id_str
spelling DEFENDIFY: defense amplified with transfer learning for obfuscated malware frameworkCastillo Camargo, RodrigoMurcia Nieto, JuanRojas, NicolásDíaz López, DanielAlférez Baquero, Edwin Santiago|||0000-0001-8661-1096Perales Gómez, Angel LuisNespoli, PantaleoneGómez Mármol, FélixKarabiyik, UmitMalware detectionMalware obfuscationComputer visionTransfer learningDeep learningNetworking system of artificial intelligenceÀrees temàtiques de la UPC::Informàtica::Seguretat informàticaThe existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen’s device and reaching critical information systems. To detect malware families, Machine Learning and Deep Learning techniques have been employed recently, demonstrating promising results. However, these techniques lack in detecting more advanced malware that employs obfuscation techniques. In this paper, we present DEFENDIFY, a novel framework, empowered by Computer Vision, Deep Learning, and Transfer Learning techniques, that is able to detect completely obfuscated malware with high performance in terms of accuracy and computational consumption. DEFENDIFY comprises three modules: Dataset Creation, Binary Obfuscation, and Model Generation. These modules work together to detect both obfuscated and nonobfuscated malware. The core module, i.e., the Model Generation, employs an entropy tester that determines whether a sample is obfuscated or not. Then, a Deep Learning model powered by Transfer Learning is employed to determine if it is malware or goodware. We validated our framework using real data gathered from malware repositories and legitimate software. The proposed framework was configured to test four Convolutional Neural Network architectures: ResNet18, ResNet34, EfficientNetB3, and EfficientNetV2S. Among them, the ResNet18 architecture obtained the best performance in detecting both non-obfuscated and obfuscated samples with an F1-score of 99.34% and 97.5%, respectively.This work has been partially funded by the School of Engineering, Science and Technology at Universidad del Rosario (Colombia) through a “Beca de Estancia de Docencia e Investigación ‑ EDI 2022‑1”, by MCIN/AEI/ 10.13039/501100011033, NextGenerationEU/PRTR, UE, under Grant TED 2021129300B‑I00, by MCIN / AEI / 10.13039 / 501100011033 / FEDER, UE, under Grant PID2021 ‑ 122466OB ‑ I00, the strategic project DEFENDER from the Spanish National Institute of Cybersecurity (INCIBE), by the Recovery, Transformation and Resilience Plan, Next Generation EU, and by the Spanish Ministry of Universities linked to the European Union through the NextGenerationEU program, under Margarita Salas postdoctoral fellowship (172/MSJD/22). This work has also been partially funded by the Nvidia Academic Grant Program through GPU instances provided by Saturn Cloud.Peer ReviewedSpringer20252025-12-0120252025-05-20journal articlehttp://purl.org/coar/resource_type/c_6501VoRhttp://purl.org/coar/version/c_970fb48d4fbd8a85info:eu-repo/semantics/articleapplication/pdfhttps://hdl.handle.net/2117/429903https://dx.doi.org/10.1186/s42400-025-00396-zreponame:UPCommons. Portal del coneixement obert de la UPCinstname:Universitat Politècnica de Catalunya (UPC)InglésengAgencia Estatal de Investigación http://doi.org/10.13039/501100011033 Plan Estatal de Investigación Científica y Técnica y de Innovación 2021-2023 PID2021-122466OB-I00 GESTION ROBUSTA, INTERPRETABLE Y ORIENTADA A HUMANOS DE LA CIBERSEGURIDAD Y LA SEGURIDAD EN LA INDUSTRIA 5.0open accesshttp://purl.org/coar/access_right/c_abf2Attribution 4.0 Internationalhttp://creativecommons.org/licenses/by/4.0/info:eu-repo/semantics/openAccessoai:upcommons.upc.edu:2117/4299032026-05-27T15:37:01Z
dc.title.none.fl_str_mv DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
title DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
spellingShingle DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
Castillo Camargo, Rodrigo
Malware detection
Malware obfuscation
Computer vision
Transfer learning
Deep learning
Networking system of artificial intelligence
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
title_short DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
title_full DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
title_fullStr DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
title_full_unstemmed DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
title_sort DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework
dc.creator.none.fl_str_mv Castillo Camargo, Rodrigo
Murcia Nieto, Juan
Rojas, Nicolás
Díaz López, Daniel
Alférez Baquero, Edwin Santiago|||0000-0001-8661-1096
Perales Gómez, Angel Luis
Nespoli, Pantaleone
Gómez Mármol, Félix
Karabiyik, Umit
author Castillo Camargo, Rodrigo
author_facet Castillo Camargo, Rodrigo
Murcia Nieto, Juan
Rojas, Nicolás
Díaz López, Daniel
Alférez Baquero, Edwin Santiago|||0000-0001-8661-1096
Perales Gómez, Angel Luis
Nespoli, Pantaleone
Gómez Mármol, Félix
Karabiyik, Umit
author_role author
author2 Murcia Nieto, Juan
Rojas, Nicolás
Díaz López, Daniel
Alférez Baquero, Edwin Santiago|||0000-0001-8661-1096
Perales Gómez, Angel Luis
Nespoli, Pantaleone
Gómez Mármol, Félix
Karabiyik, Umit
author2_role author
author
author
author
author
author
author
author
dc.subject.none.fl_str_mv Malware detection
Malware obfuscation
Computer vision
Transfer learning
Deep learning
Networking system of artificial intelligence
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
topic Malware detection
Malware obfuscation
Computer vision
Transfer learning
Deep learning
Networking system of artificial intelligence
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica
description The existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen’s device and reaching critical information systems. To detect malware families, Machine Learning and Deep Learning techniques have been employed recently, demonstrating promising results. However, these techniques lack in detecting more advanced malware that employs obfuscation techniques. In this paper, we present DEFENDIFY, a novel framework, empowered by Computer Vision, Deep Learning, and Transfer Learning techniques, that is able to detect completely obfuscated malware with high performance in terms of accuracy and computational consumption. DEFENDIFY comprises three modules: Dataset Creation, Binary Obfuscation, and Model Generation. These modules work together to detect both obfuscated and nonobfuscated malware. The core module, i.e., the Model Generation, employs an entropy tester that determines whether a sample is obfuscated or not. Then, a Deep Learning model powered by Transfer Learning is employed to determine if it is malware or goodware. We validated our framework using real data gathered from malware repositories and legitimate software. The proposed framework was configured to test four Convolutional Neural Network architectures: ResNet18, ResNet34, EfficientNetB3, and EfficientNetV2S. Among them, the ResNet18 architecture obtained the best performance in detecting both non-obfuscated and obfuscated samples with an F1-score of 99.34% and 97.5%, respectively.
publishDate 2025
dc.date.none.fl_str_mv 2025
2025-12-01
2025
2025-05-20
dc.type.none.fl_str_mv journal article
http://purl.org/coar/resource_type/c_6501
VoR
http://purl.org/coar/version/c_970fb48d4fbd8a85
dc.type.openaire.fl_str_mv info:eu-repo/semantics/article
format article
dc.identifier.none.fl_str_mv https://hdl.handle.net/2117/429903
https://dx.doi.org/10.1186/s42400-025-00396-z
url https://hdl.handle.net/2117/429903
https://dx.doi.org/10.1186/s42400-025-00396-z
dc.language.none.fl_str_mv Inglés
eng
language_invalid_str_mv Inglés
language eng
dc.relation.none.fl_str_mv Agencia Estatal de Investigación http://doi.org/10.13039/501100011033 Plan Estatal de Investigación Científica y Técnica y de Innovación 2021-2023 PID2021-122466OB-I00 GESTION ROBUSTA, INTERPRETABLE Y ORIENTADA A HUMANOS DE LA CIBERSEGURIDAD Y LA SEGURIDAD EN LA INDUSTRIA 5.0
dc.rights.none.fl_str_mv open access
http://purl.org/coar/access_right/c_abf2
Attribution 4.0 International
http://creativecommons.org/licenses/by/4.0/
dc.rights.openaire.fl_str_mv info:eu-repo/semantics/openAccess
rights_invalid_str_mv open access
http://purl.org/coar/access_right/c_abf2
Attribution 4.0 International
http://creativecommons.org/licenses/by/4.0/
eu_rights_str_mv openAccess
dc.format.none.fl_str_mv application/pdf
dc.publisher.none.fl_str_mv Springer
publisher.none.fl_str_mv Springer
dc.source.none.fl_str_mv reponame:UPCommons. Portal del coneixement obert de la UPC
instname:Universitat Politècnica de Catalunya (UPC)
instname_str Universitat Politècnica de Catalunya (UPC)
reponame_str UPCommons. Portal del coneixement obert de la UPC
collection UPCommons. Portal del coneixement obert de la UPC
repository.name.fl_str_mv
repository.mail.fl_str_mv
_version_ 1869404589753630720
score 15.223283