Transfer learning based multi-class malware classification using VGG16 feature extractor and SVM classifier
Harman Saggu, Er. Karandeep Singh, Tammisetti Nagendra Babu · 2024
Malicious programs are becoming a severe problem in today’s internet-connected world. Several works have explored image analysis-based malware detection in recent years. The image analysis method converts the malicious code into gray-scale images, which enables the use of deep learning models in the domain of malware detection. This paper proposes a new architecture using a fine-tuned Visual Geometry Group(VGG16) model with a support vector machine (SVM) classifier to achieve high-performance accuracy in detecting and classifying evolving malware. At first, the malicious code is represented in gray-scale images, which are further reshaped and resized to be fed into a fine-tuned VGG16 model as end-to-end feature extraction with the least dependence on human-crafted feature engineering. The extracted textural feature maps are further correlated to remove the highly correlated features before using them to train a support vector machine (SVM) classifier. The experiments are performed on public bench-marked MalImg datasets and actual malware samples. The VGG 16+ SVM model obtained 99.25% classification accuracy for the MalImg and 80.29% for real-world malware, which signifies that the model can detect real-world instances of malware. The proposed method outperforms similar existing works and is suitable for deployment in an IoT environment due to the least cost involved in feature engineering.