基于 TCN与 ChebyKAN融合网络的恶意软件多分类模型
Malware multi-classification model for based on TCN and ChebyKAN fusion network
针对基于 API 调用序列的传统恶意软件检测方法存在长距离时序依赖捕捉不足、忽略特征间高阶非线性关系等相关问题,提出了一种融合时序卷积网络(TCN)与 Chebyshev-Kolmogorov-Arnold network(ChebyKAN)的恶意软件多分类模型(TCN-SE-ChebyKAN)。首先,基于 TCN 模块对 API 调用序列提取特征,利用因果卷积和膨胀卷积,突破传统循环神经网络在长距离时序依赖建模中的局限,精准捕捉恶意软件多阶段行为的时序关联;其次,引入 SE 模块构建通道注意力机制,动态优化通道权重,解决关键判别性特征被冗余信息掩盖的问题;最后,通过切比雪夫多项式改进 KAN 模块(ChebyKAN),利用其全局逼近特性增强特征间高阶非线性关系的建模能力,克服原始 KAN 中 B样条函数局部性强的缺陷。实验结果表明,该模型在 Mal-API-2019 数据集上 AUC 值达 92.53%,精确率、召回率、F1 值等指标均有显著提升。
The traditional malware detection methods based on API (application programming interface) call sequences fail to sufficiently capture the long-term temporal dependencies and neglect the high-order nonlinear relationships among features. To address these issues, this paper proposes a multi-classification model for malware (TCN-SE-ChebyKAN) that integrates a temporal convolutional network (TCN) and Chebyshev-Kolmogorov-Arnold network (ChebyKAN). First, the TCN module is employed to extract features from API call sequences. By leveraging causal convolutions and dilated convolutions, the model captures temporal characteristics and long-range dependencies representing malware behavior, thereby obtaining more comprehensive behavioral information. Next, a squeeze-and-excitation (SE) network module is introduced to construct a channel attention mechanism. Through dynamic adjustment of channel weights, the model enhances its ability to capture discriminative features. Finally, the KAN (Kolmogorov-Arnold network) module is utilized to model complex relationships among features. By improving the KAN module with Chebyshev polynomials, the model strengthens its capability to model high-order nonlinear relationships among features, boosting overall detection performance. Experimental results demonstrate that the proposed model achieves an AUC value of 92.53% on the Mal-API-2019 data set, with significant improvements in other detection metrics.
| [1] |
|
| [2] |
KOLOSNJAJI B, ZARRAS A, WEBSTER G, |
| [3] |
|
| [4] |
|
| [5] |
|
| [6] |
|
| [7] |
|
| [8] |
|
| [9] |
|
| [10] |
|
| [11] |
曾骏, 王子威, 于扬, |
| [12] |
|
| [13] |
高新成, 张海洋, 朱城枫 . 基于图层级异构图注意力网络的 JavaScript 恶意代码检测[J/OL]. 吉林大学学报(工学版), [2025—05—05]. https://link.cnki.net/doi/10.13229/j.cnki.jdxbgxb.20240962. |
| [14] |
|
| [15] |
|
| [16] |
李思聪, 王坚, 宋亚飞, |
| [17] |
|
| [18] |
郭玥秀, 杨伟, 刘琦, |
| [19] |
|
| [20] |
|
| [21] |
|
| [22] |
袁立宁, 冯文刚, 刘钊 . 基于 Kolmogorov—Arnold 网络的节点分类算法[J]. 计算机科学与探索, 2025, 19(3): 645-656. |
| [23] |
|
| [24] |
韩梦如, 郭子磊, 赵运晓, |
| [25] |
|
| [26] |
|
| [27] |
|
| [28] |
|
| [29] |
|
国家自然科学基金(61702093)
中国高校产学研创新基金(2021ITA02011)
黑龙江省教育科学规划课题(GJB1425352)
/
| 〈 |
|
〉 |