Deep Learning for Agile Malware Detection

Mirza Abbas Uddin, Sanjana Hossain Sonali, Mohammad Shahriar Rahman, Mohammad Shamim Ahsan · 2024

The rapid growth of technology dependence has led to a significant increase in cyberattacks, specifically, the occurrences of malicious software (malware) threats have surged exponentially. In this paper we discuss how to use deep learning (DL) techniques, specifically deep neural networks (DNNs), to detect malware quickly and accurately. In detecting attacks, accuracy alone is insufficient; speed is equally vital. Considering this, we look at different techniques, such as choosing the right initializer, activation functions (AFs), optimizers, and learning rate schedulers (LRSs), and several different combinations of these techniques to observe which ones work best for malware detection. Particularly, the main goal of this work is to contribute to the literature in understanding how to use DNNs combining different components for detecting malware considering the efficacy of the components and situational dependencies. Our results show that He initialization and ReLU activation generally achieved faster training and prediction times for malware detection. On the contrary, Glorot initialization and Sigmoid activation yield moderate or slower performance. Moreover, advanced optimizers like adaptive moment estimation (Adam), root mean square propagation (RMSProp), and Nesterov adaptive moment estimation (Nadam) contribute to faster convergence, while stochastic gradient descent (SGD) and its variations exhibit less consistent performance. Furthermore, we find out that learning rates did not exhibit a clear trend in the performance of malware detection.

Read the paper · More papers on PaperTik