A Robust Malware Detection Framework Using Control Flow Graphs, Node2Vec, and GCN Integration

Mohammad Sarwar Hossain Mollah, Mohd Fadzli Marhusin, Syaril Nizam Omar · 2025

Malware detection remains a critical cybersecurity challenge, with existing techniques struggling to address evolving threats. Our research investigates graph-based methodologies, systematically examining limitations in node feature extraction, execution sequence analysis, and representation vectors to enhance detection scalability and resilience against sophisticated obfuscation techniques. In this work, we propose a novel Control Flow Graph (CFG) based malware detection framework using graph convolutional networks (GCNs), which can be capable of detecting malware in a more accurate manner. Firstly, we generate CFGs from Windows Portable Executable (exe) files. Secondly, CFGs are converted into feature embedding vectors using advanced graph embedding technique Node2Vec. Finally, the resulting features are fed into the GCN classifier to construct our framework to detect malware. In our experiment, we collect recently released 17,900 malware and benign samples from VirusShare, MalwareBazar, and SourceForge to create a CFG-based dataset. Our experimental results demonstrate that combining Node2Vec with GCN achieves an impressive accuracy of 95.62%, area under the curve (AUC) of 95.18%, Precision of 95.61%, Recall of 95.62%, and F1-score of 95.82%. These results demonstrate the framework’s robustness in identifying both known and unknown malware samples. Our research emphasizes the importance of selecting appropriate feature extraction techniques and machine learning models, as well as the efficacy of graph-based approaches in detecting sophisticated malware. This framework provides a foundation for future malware detection systems that leverage advanced CFG-based techniques to achieve scalability, resilience, and the ability to counter evolving cyber threats.

Read the paper · More papers on PaperTik