Enhancing Few-Shot Malware Classification Through Joint Learning of Malware Images and Opcode Sequences
Hanjun Li, Shuhong Chen, Guojun Wang, Cheng Liu, Haojie Yin, Zhenkun Luo · 2024
An unending stream of malware variations presents a severe threat to the Internet community as a way of initiating cyber-attacks. Although few-shot learning-based malware classification methods have achieved some success in detecting unknown malware and using limited data for training, the majority of current techniques still struggle with classification performance because they only take into account a single malware image or API call sequence feature, ignoring the multi-dimensional nature of malware. To deal with these challenges, this paper proposes a malware image and opcode joint learning method for few-shot malware classification. We employ a cross-modal attention mechanism to determine the weight representing the correlation between the malware’s binary and assembly codes. Furthermore, we compute a weighted prototype based on the fused feature vector of binary and assembly codes to enhance the prototype’s generalizability. Extensive experiments demonstrate the superiority of our method compared to existing few-shot malware classification models, with an average accuracy of more than 83% in the 5-way settings with only two samples on both LargePE and VirusShare datasets.