基于 TCNChebyKAN融合网络的恶意软件多分类模型

高新成 ,  朱城枫

电子科技大学学报 ›› 2026, Vol. 55 ›› Issue (2) : 215 -223.

PDF (1001KB)
电子科技大学学报 ›› 2026, Vol. 55 ›› Issue (2) : 215 -223. DOI: 10.12178/1001-0548.2025099
计算机工程与应用

基于 TCNChebyKAN融合网络的恶意软件多分类模型

作者信息 +

Malware multi-classification model for based on TCN and ChebyKAN fusion network

Author information +
文章历史 +
PDF (1024K)

摘要

针对基于 API 调用序列的传统恶意软件检测方法存在长距离时序依赖捕捉不足、忽略特征间高阶非线性关系等相关问题,提出了一种融合时序卷积网络(TCN)与 Chebyshev-Kolmogorov-Arnold network(ChebyKAN)的恶意软件多分类模型(TCN-SE-ChebyKAN)。首先,基于 TCN 模块对 API 调用序列提取特征,利用因果卷积和膨胀卷积,突破传统循环神经网络在长距离时序依赖建模中的局限,精准捕捉恶意软件多阶段行为的时序关联;其次,引入 SE 模块构建通道注意力机制,动态优化通道权重,解决关键判别性特征被冗余信息掩盖的问题;最后,通过切比雪夫多项式改进 KAN 模块(ChebyKAN),利用其全局逼近特性增强特征间高阶非线性关系的建模能力,克服原始 KAN 中 B样条函数局部性强的缺陷。实验结果表明,该模型在 Mal-API-2019 数据集上 AUC 值达 92.53%,精确率、召回率、F1 值等指标均有显著提升。

Abstract

The traditional malware detection methods based on API (application programming interface) call sequences fail to sufficiently capture the long-term temporal dependencies and neglect the high-order nonlinear relationships among features. To address these issues, this paper proposes a multi-classification model for malware (TCN-SE-ChebyKAN) that integrates a temporal convolutional network (TCN) and Chebyshev-Kolmogorov-Arnold network (ChebyKAN). First, the TCN module is employed to extract features from API call sequences. By leveraging causal convolutions and dilated convolutions, the model captures temporal characteristics and long-range dependencies representing malware behavior, thereby obtaining more comprehensive behavioral information. Next, a squeeze-and-excitation (SE) network module is introduced to construct a channel attention mechanism. Through dynamic adjustment of channel weights, the model enhances its ability to capture discriminative features. Finally, the KAN (Kolmogorov-Arnold network) module is utilized to model complex relationships among features. By improving the KAN module with Chebyshev polynomials, the model strengthens its capability to model high-order nonlinear relationships among features, boosting overall detection performance. Experimental results demonstrate that the proposed model achieves an AUC value of 92.53% on the Mal-API-2019 data set, with significant improvements in other detection metrics.

关键词

恶意软件 / API 调用序列 / SE 模块 / ChebyKAN / 时序卷积网络

Key words

malicious software / API call sequence / SE module / ChebyKAN / temporal convolutional network

引用本文

引用格式 ▾
高新成,朱城枫. 基于 TCNChebyKAN融合网络的恶意软件多分类模型[J]. 电子科技大学学报, 2026, 55(2): 215-223 DOI:10.12178/1001-0548.2025099

登录浏览全文

4963

注册一个新账户 忘记密码

参考文献

[1]

ZELINKA I, AMER E. An ensemble—based malware detection model using minimum feature set[J]. Mendel, 2019, 25(2): 1-10.

[2]

KOLOSNJAJI B, ZARRAS A, WEBSTER G, et al. Deep learning for classification of malware system call sequences[C]// AI 2016: Advances in Artificial Intelligence. Cham: Springer International Publishing, 2016: 137-149.

[3]

YE Y F, LI T, ADJEROH D, et al. A survey on malware detection using data mining techniques[J]. ACM Computing Surveys, 2018, 50(3): 1-40.

[4]

CATAK F O, YAZı A F, ELEZAJ O, et al. Deep learning based Sequential model for malware analysis using Windows exe API Calls[J]. PeerJ Computer Science, 2020, 6: e285.

[5]

LI C, ZHENG J J. API call—based malware classification using recurrent neural networks[J]. Journal of Cyber Security and Mobility, 2021, 10(3): 617-640.

[6]

DEMIRKıRAN F, AYKUT Ç, UĞUR Ü, et al. An ensemble of pre—trained transformer models for imbalanced multiclass malware classification[J]. Computers & Security, 2022, 121: 102846.

[7]

PANDA B, BISOYI S S, PANIGRAHY S. An ensemble approach for imbalanced multiclass malware classification using 1D—CNN[J]. PeerJ Computer Science, 2023, 9: e1677.

[8]

CUI L, YIN J N, CUI J C, et al. API2Vec: Boosting API sequence representation for malware detection and classification[J]. IEEE Transactions on Software Engineering, 2024, 50(8): 2142-2162.

[9]

QIAN L P, CONG L. Channel features and API frequency—based transformer model for malware identification[J]. Sensors, 2024, 24(2): 580.

[10]

BAKıR H. A new method for tuning the CNN pre—trained models as a feature extractor for malware detection[J]. Pattern Analysis and Applications, 2025, 28(1): 26.

[11]

曾骏, 王子威, 于扬, . 自然语言处理领域中的词嵌入方法综述[J]. 计算机科学与探索, 2024, 18(1): 24-43.

[12]

ZENG J, WANG Z W, YU Y, et al. A survey of word embedding methods in natural language processing[J]. Computer Science and Exploration, 2024, 18(1): 24-43.

[13]

高新成, 张海洋, 朱城枫 . 基于图层级异构图注意力网络的 JavaScript 恶意代码检测[J/OL]. 吉林大学学报(工学版), [2025—05—05]. https://link.cnki.net/doi/10.13229/j.cnki.jdxbgxb.20240962.

[14]

GAO X C, ZHANG H Y, ZHU C F. JavaScript malicious code detection based on layer—level heterogeneous graph attention network[J/OL]. Journal of Jilin University (Engineering and Technology Edition), [2025—05—05]. https://link.cnki.net/doi/10.13229/j.cnki.jdxbgxb.20240962.

[15]

FAN Y Y, LI C J, YI Q, et al. Classification of field moving targets based on improved TCN network[J]. Computer Engineering, 2021, 47: 106-112.

[16]

李思聪, 王坚, 宋亚飞, . 基于 BiTCN—DLP 的恶意代码分类方法[J]. 信息网络安全, 2023, 23(11): 104-117.

[17]

LI S C, WANG J, SONG Y F, et al. Malicious code classification method based on BiTCN—DLP[J]. Cyberspace Security, 2023, 23(11): 104-117.

[18]

郭玥秀, 杨伟, 刘琦, . 残差网络研究综述[J]. 计算机应用研究, 2020, 37(5): 1292-1297.

[19]

GUO Y X, YANG W, LIU Q, et al. A survey of residual network research[J]. Application Research of Computers, 2020, 37(5): 1292-1297.

[20]

HU J, SHEN L, SUN G. Squeeze—and—excitation networks[C]// Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. New York: IEEE, 2018: 7132-7141.

[21]

LIU Z, WANG Y, VAIDYA S, et al. Kan: Kolmogorov—ar—nold networks[EB/OL]. [ 2024—11—10]. https://arxiv.org/pdf/2404.19756.

[22]

袁立宁, 冯文刚, 刘钊 . 基于 Kolmogorov—Arnold 网络的节点分类算法[J]. 计算机科学与探索, 2025, 19(3): 645-656.

[23]

YUAN L N, FENG W G, LIU Z. Node classification based on kolmogorov—arnold networks[J]. Journal of Frontiers of Computer Science & Technology, 2025, 19(3): 645-656.

[24]

韩梦如, 郭子磊, 赵运晓, . 基于 Chebyshev 点的 B 样条配置法在奇异摄动两点边值问题中的应用研究[J]. 应用数学进展, 2025, 14(5): 262-273.

[25]

HAN M R, GUO Z L, ZHAO Y X, et al. Study on application of Chebyshev B—spline collocation method on singularly perturbed two—point boundary value problems[J]. Advances in Applied Mathematics, 2025, 14(5): 262-273.

[26]

TEKEREK A. A novel architecture for web—based attack detection using convolutional neural network[J]. Computers & Security, 2021, 100: 102096.

[27]

YU L T, ZHANG W N, WANG J, et al. SeqGAN: Sequence generative adversarial nets with policy gradient[J]. Proceedings of the AAAI Conference on Artificial Intelligence, 2017, 31(1): 493.

[28]

CANNARILE A, CARRERA F, GALANTUCCI S, et al. A study on malware detection and classification using the analysis of API calls sequences through shallow learning and recurrent neural networks[C]// Proceedings of the ITASEC’22: Italian Conference on Cybersecurity. Rome: [s.n.], 2022.

[29]

BRANCO P, TORGO L, RIBEIRO R P. Relevance—based evaluation metrics for multi—class imbalanced domains[M]// Advances in Knowledge Discovery and Data Mining. Cham: Springer International Publishing, 2017: 698-710.

基金资助

国家自然科学基金(61702093)

中国高校产学研创新基金(2021ITA02011)

黑龙江省教育科学规划课题(GJB1425352)

AI Summary AI Mindmap
PDF (1001KB)

259

访问

0

被引

详细

导航
相关文章

AI思维导图

/