Image analysis and fine-tuned ResNet50 model for effective malware detection

Sanjeev Kumar, Yudhishthira Sapru, Jitendra Kumar, Sugandha Sapru · Procedia Computer Science · 2025

With the rapid growth of connected assets to the Internet, malware attacks have increased exponentially, often causing substantial damage to these connected assets. Early detection of evolving malware attacks can avoid such damage to the Internet ecosystem. However, it requires an efficient and robust approach with little reliance on existing signature-based approaches, as these are no longer effective in detecting obfuscated and complex malware attacks. This study presents a new malware detection and classification approach using image analysis and a fine-tuned ResNet50 convolution neural network (CNN) model through transfer learning. The raw binary executable programs are transformed into grayscale images and resized to 224 × 224 × 1 image size to be fed to the deep CNN model for feature extraction. The pre-trained ResNet50 model is customized to extract the textural features by retaining the learned weight and bias from the source ImageNet data and making the last fully connected layer non-trainable. After that, a fully connected dense layer is added for dimension reduction of the feature map into N × 128, with N as the number of malware files. Two public datasets are used in experiments - MalImg and Microsoft BIG. This study uses comprehensive performance metrics to evaluate the model and obtained an accuracy of 98.50% for the MalImg dataset and 94.85% for the Microsoft BIG data set. The experiment results show that the proposed methodology can handle malware obfuscated by standard polymorphic techniques and is better than similar methods in the literature.

Read the paper · More papers on PaperTik