A Malware Detection Model Based on the Fusion of Swin Transformer and Mona Modules

Linjun Yu, Fuyong Zhang · 2025

This paper proposes a novel and efficient malware classification framework that leverages the Swin Transformer architecture enhanced with the lightweight Mona module. By representing binary malware samples as color images—via byte-to-RGB mapping and colorization techniques—the model captures both local texture and global semantic features essential for accurate classification. The Mona adapter module, integrated in parallel with the feed-forward network, improves parameter efficiency and representation learning without significantly increasing model complexity. Extensive experiments on three publicly available datasets—MaleVis, Microsoft BIG 2015, and Fusion-demonstrate the effectiveness of our approach. The proposed model achieves classification accuracies of $\mathbf{9 8. 5 2 \%, 9 8. 3 5 \%,}$ and $98.01 \%$ on the respective datasets, outperforming baseline Swin Transformer and other conventional deep learning methods. These results highlight the model’s capability to generalize across diverse malware distributions while maintaining computational efficiency, making it suitable for practical deployment in securitycritical environments.

Read the paper · More papers on PaperTik