School of Information,Xi’an University of Finance and Economics,Xi’an 710100,Shaanxi,China
Show less
文章历史+
Received
Published
2025-01-18
2026-06-24
Issue Date
2026-07-23
PDF (3836K)
摘要
与日俱增的恶意软件变种为网络安全带来严重威胁,准确且快速地识别恶意软件变种是安全防御的关键环节。现有研究利用端到端的深度学习模型优势进行检测,但复杂度较高,在性能及计算资源方面受限,给实际部署带来困难。本文构建了基于颜色编码与数据映射的GMA(byte stream GLCM, assembly instruction Markov, API)图像数据集,最大化保留特征信息量的同时,实现数据规模轻量化;提出了基于解耦知识蒸馏的恶意软件轻量化检测模型MTFKD(Malware Texture Feature Classification based on Knowledge Distillation),应用知识蒸馏策略实现模型轻量化,结合高效多尺度注意力机制与空洞空间金字塔池强化特征表达,并使用改进的随机森林算法提升分类效率。实验表明,本文模型在检测准确率达到99.49%的情况下,复杂度明显降低,大大增强模型的实际应用性与泛化能力。
Abstract
The rapid proliferation of malware variants poses a serious threat to network security, and accurately and quickly identifying these variants is a key aspect of security defense. Existing research leverages the advantages of end-to-end deep learning models for detection; however, the models are computationally expensive and have limitations in performance, making practical deployment challenging. Therefore, a GMA (byte stream GLCM, assembly instruction Markov, API) image dataset based on color coding and data mapping is built, which maximizes feature information retention while ensuring lightweight data scaling. A lightweight malware detection model, MTFKD (Malware Texture Feature Classification based on Knowledge Distillation), is proposed, which applies a knowledge distillation strategy to reduce model complexity, integrates an efficient multi-scale attention mechanism with the atrous spatial pyramid pooling to enhance feature expression, and employs an improved Random Forest algorithm to enhance classification efficiency. Experiments demonstrate that the proposed model achieves 99.49% detection accuracy with significantly reduced complexity, greatly enhancing the model’s practical applicability and generalization.
利用DKD进行模型轻量化处理,将复杂教师网络的知识迁移至简单学生网络。DKD的总损失函数如(4)式所示,包含目标类知识蒸馏(Target Class Knowledge Distillation, TCKD)和非目标类知识蒸馏(Non-Target Class Knowledge Distillation, NCKD)两个独立部分。
XIEL X, WEIC Y, YANGH Y, et al. Review on malware detection and classification using imaging-based methods[J]. Chinese Journal of Computers, 2025, 48(3): 650-674. DOI: 10.11897/SP.J.1016.2025.00650(Ch ).
[5]
DENGH X, GUOC, SHENG W, et al. MCTVD: A malware classification method based on three-channel visualization and deep learning[J]. Computers & Security, 2023, 126: 103084. DOI: 10.1016/j.cose.2022.103084 .
YANGC Y, XUY, ZHANGS C, et al. A malware classification method based on three-channel images[J]. Journal of Wuhan University (Natural Science Edition), 2022, 68(1): 26-34. DOI: 10.14188/j.1671-8836.2021.2005(Ch ).
[8]
CUIZ H, XUEF, CAIX J, et al. Detection of malicious code variants based on deep learning[J]. IEEE Transactions on Industrial Informatics, 2018, 14(7): 3187-3196. DOI: 10.1109/TII.2018.2822680 .
[9]
XINGX F, JINX, ELAHIH, et al. A malware detection approach using autoencoder in deep learning[J]. IEEE Access, 2022, 10: 25696-25706. DOI: 10.1109/ACCESS.2022.3155695 .
[10]
DHANYAK A, VINODP, YERIMAS Y, et al. Obfuscated malware detection in IoT Android applications using Markov images and CNN[J]. IEEE Systems Journal, 2023, 17(2): 2756-2766. DOI: 10.1109/JSYST.2023.3238678 .
WANGJ W, CHENZ J, XIEX, et al. Deep visualization classification method for malicious code based on Ngram-TFIDF[J]. Journal on Communications, 2024, 45(6): 160-175. DOI:10.11959/j.issn.1000-436x.2024115(Ch ).
XUANB N, LIJ. Malware classification method based on improved CNN[J]. Acta Electronica Sinica, 2023, 51(5): 1187-1197. DOI:10.12263/DZXB.20220818(Ch ).
[16]
AMERE, ZELINKAI. A dynamic Windows malware detection and prediction method based on contextual understanding of API call sequence[J]. Computers & Security, 2020, 92: 101760. DOI: 10.1016/j.cose.2020.101760 .
[17]
CONTIM, KHANDHARS, VINODP. A few-shot malware classification approach for unknown family recognition using malware feature visualization[J]. Computers & Security, 2022, 122: 102887. DOI: 10.1016/j.cose.2022.102887 .
[18]
ZHAOB R, CUIQ, SONGR J, et al. Decoupled knowledge distillation[C]//2022 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2022: 11943-11952. DOI: 10.1109/CVPR52688.2022.01165 .
[19]
HEY W, KANGX G, YANQ B, et al. ResNeXt+: Attention mechanisms based on ResNeXt for malware detection and classification[J]. IEEE Transactions on Information Forensics and Security, 2024, 19: 1142-1155. DOI: 10.1109/TIFS.2023.3328431 .
[20]
ZHANGL F, SONGJ B, GAOA, et al. Be your own teacher: Improve the performance of convolutional neural networks via self distillation[C]//2019 IEEE/CVF International Conference on Computer Vision (ICCV). New York: IEEE Press, 2019: 3712-3721. DOI: 10.1109/ICCV.2019.00381 .
[21]
ZOUB H, CAOC J, WANGL J, et al. FACILE: A capsule network with fewer capsules and richer hierarchical information for malware image classification[J]. Computers & Security, 2024, 137: 103606. DOI: 10.1016/j.cose.2023.103606 .
[22]
OUYANGD L, HES, ZHANGG Z, et al. Efficient multi-scale attention module with cross-spatial learning[C]//ICASSP 2023—2023 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). New York: IEEE Press, 2023: 1-5. DOI: 10.1109/ICASSP49357.2023.10096516 .
[23]
HOUQ B, ZHOUD Q, FENGJ S. Coordinate attention for efficient mobile network design[C]//2021 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). New York: IEEE Press, 2021: 13708-13717. DOI: 10.1109/ CVPR46437.2021.01350 .
[24]
CHENL C, PAPANDREOUG, KOKKINOSI, et al. DeepLab: Semantic image segmentation with deep convolutional nets, atrous convolution, and fully connected CRFs[J]. IEEE Transactions on Pattern Analysis and Machine Intelligence, 2018, 40(4): 834-848. DOI: 10.1109/TPAMI.2017.2699184 .
XIONGJ, QINR C, HEM Y, et al. Application of improved random forest algorithm in Android malware detection[J]. Computer Engineering and Applications, 2021, 57(3): 130-136. DOI: 10.3778/j.issn.1002-8331.2001-0291(Ch ).
[27]
RONENR, RADUM, FEUERSTEINC, et al. Microsoft malware classification challenge[EB/OL]. [2015-02-04].
[28]
CHAGANTIR, RAVIV, PHAMT D. Image-based malware representation approach with EfficientNet convolutional neural networks for effective malware classification[J]. Journal of Information Security and Applications, 2022, 69: 103306. DOI: 10.1016/j.jisa.2022.103306 .
[29]
SHARMAO, SHARMAA, KALIAA. MIGAN: GAN for facilitating malware image synthesis with improved malware classification on novel dataset[J]. Expert Systems with Applications, 2024, 241: 122678. DOI: 10.1016/j.eswa.2023.122678 .
LIS C, WANGJ, SONGY F, et al. TriCh-LKRepNet: A large kernel convolutional malicious code classification network for structure reparameterisation and triple-channel mapping[J]. Acta Electronica Sinica, 2024, 52(7): 2331-2340. DOI: 10.12263/DZXB.20240162(Ch ).
[32]
SHARMAO, SHARMAA, KALIAA. Windows and IoT malware visualization and classification with deep CNN and Xception CNN using Markov images[J]. Journal of Intelligent Information Systems, 2023, 60(2): 349-375. DOI: 10.1007/s10844-022-00734-4 .
[33]
XIAOM, GUOC, SHENG W, et al. Image-based malware classification using section distribution information[J]. Computers & Security, 2021, 110: 102420. DOI: 10.1016/j.cose.2021.102420 .
[34]
WANGF W, SHIX P, YANGF, et al. MalSort: Lightweight and efficient image-based malware classification using masked self-supervised framework with Swin Transformer[J]. Journal of Information Security and Applications, 2024, 83: 103784. DOI: 10.1016/j.jisa.2024.103784 .