[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125876-en":3,"doc-seo-125876-105":31,"detail-sidebar-cat-0-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},125876,1099523885336,"Violet","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Quo Vadis - Hybrid Machine Learning Meta-Model Based on Contextual and Behavioral Malware Representations","A hybrid machine learning architecture is proposed to improve Windows malware detection by combining multiple deep models that analyze contextual and behavioral characteristics and then fuse them via a meta-model decision. Current Windows malware classifiers often rely on static executable properties because dynamic analysis at scale is constrained by virtualization costs. The approach uses a Windows kernel emulator to extract behavioral patterns efficiently across large corpora with minimal temporal and computational overhead. A dataset of 100k+ in-the-wild samples is collected with threat-intel labels, enabling out-of-sample evaluation showing higher detection and strong performance under low false-positive requirements. Pre-trained models and anonymized emulation reports are released publicly.","Quo Vadis: Hybrid Machine Learning Meta-Model Based on Contextual and Behavioral Malware Representations  \nDmitrijs Trizna  \n[dtrizna@microsoft.com](dtrizna@microsoft.com)  \nMicrosoft Corporation  \nPrague, Czech Republic  \narXiv :2208 . 12248v2 [ cs .CR] 19 Oct 2024  \nABSTRACT  \nWe propose a hybrid machine learning architecture that simultaneously employs multiple deep learning models analyzing contextual and behavioral characteristics of Windows portable executable, producing a final prediction based on a decision from the meta-model. The detection heuristic in contemporary machine learning Windows malware classifiers is typically based on the static properties of the sample since dynamic analysis through virtualization is challenging for vast quantities of samples. To surpass this limitation, we employ a Windows kernel emulation that allows the acquisition of behavioral patterns across large corpora with minimal temporal and computational costs. We partner with a security vendor for a collection of more than 100k int-the-wild samples that resemble the contemporary threat landscape, containing raw PE files and filepaths of applications at the moment of execution. The acquired dataset is at least ten folds larger than reported in related works on behavioral malware analysis. Files in the training dataset are labeled by a professional threat intelligence team, utilizing manual and automated reverse engineering tools. We estimate the hybrid classifier’s operational utility by collecting an out-of-sample test set three months later from the acquisition of the training set. We report an improved detection rate, above the capabilities of the current state-of-the-art model, especially under low false-positive requirements. Additionally, we uncover a meta-model’s ability to identify malicious activity in both validation and test sets even ifnone of the individual models express enough confidence to mark the sample as malevolent. We conclude that the meta-model can learn patterns typical to malicious samples out of representation combinations produced by different analysis techniques. Furthermore, we publicly release pre-trained models and anonymized dataset of emulation reports.  \nCCS CONCEPTS  \n• Security and privacy → Malware and its mitigation; • Computing methodologies → Neural networks; • Hardware → Simulation and emulation.  \nPermission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission [and/or a fee. Request permissions from permissions@acm.org](and/or a fee. Request permissions from permissions@acm.org).  \nAISec ’22, November 11, 2022, Los Angeles, CA, USA  \n© 2022 Copyright held by the owner/author(s) . Publication rights licensed to ACM. ACM ISBN 978-1-4503-9880-0/22/11. . . $15.00  \n[https://doi.org/10.1145/3560830.3563726](https://doi.org/10.1145/3560830.3563726)  \nKEYWORDS  \nmalware, emulation, neural networks, convolutions, reverse engineering  \nACM Reference Format:  \nDmitrijs Trizna. 2022. Quo Vadis: Hybrid Machine Learning Meta-Model Based on Contextual and Behavioral Malware Representations. In Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security (AISec’22), November 11, 2022, Los Angeles, CA, USA. ACM, Los Angeles, CA, USA, 10 pages. [https://doi.org/10.1145/3560830.3563726](https://doi.org/10.1145/3560830.3563726)  \n1 INTRODUCTION  \nMachine learning (ML) algorithms have become essential to malicious software (malware) detection in conventional cybersecurity intrusion prevention systems. Such systems can learn common patterns across a v","cbCaidDs5lfORbWl","https://ap.wps.com/l/cbCaidDs5lfORbWl","pdf",2519090,5,1,10,"English","en",105,"# Abstract\n# Introduction\n## Motivation and limitations of static ML\n## Dynamic analysis with kernel emulation\n## Hybrid architecture and evaluation setup","[{\"question\":\"Why do many current Windows malware classifiers rely on static properties?\",\"answer\":\"Because acquiring sufficient dynamic behavior signals through large-scale virtualization-based analysis is difficult and computationally expensive.\"},{\"question\":\"How does the proposed method obtain behavioral information efficiently at scale?\",\"answer\":\"It uses a Windows kernel emulator to collect behavioral patterns with minimal temporal and computational cost compared with full virtualization.\"},{\"question\":\"What role does the meta-model play in the hybrid architecture?\",\"answer\":\"The meta-model fuses outputs from multiple analysis modules and can identify malicious behavior even when individual models do not produce high-confidence predictions.\"}]","Quo Vadis - Hybrid Machine Learning Meta-Model Based on Contextual and Behavioral Malware Representations | PDF",1785901771,25,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":29},"quo-vadis-hybrid-machine-learning-meta-model-based-on-contextual-and-behavioral-malware-representations","",{"@graph":37,"@context":87},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/quo-vadis-hybrid-machine-learning-meta-model-based-on-contextual-and-behavioral-malware-representations/125876/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-08-20","2026-08-05",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"Why do many current Windows malware classifiers rely on static properties?","Question",{"text":77,"@type":78},"Because acquiring sufficient dynamic behavior signals through large-scale virtualization-based analysis is difficult and computationally expensive.","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"How does the proposed method obtain behavioral information efficiently at scale?",{"text":82,"@type":78},"It uses a Windows kernel emulator to collect behavioral patterns with minimal temporal and computational cost compared with full virtualization.",{"name":84,"@type":75,"acceptedAnswer":85},"What role does the meta-model play in the hybrid architecture?",{"text":86,"@type":78},"The meta-model fuses outputs from multiple analysis modules and can identify malicious behavior even when individual models do not produce high-confidence predictions.","https://schema.org",{"og:url":53,"og:type":89,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":91,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":94},[95,99,103,107,111,116,121,124,129,132,135],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":104,"show_sort_weight":105,"slug":106},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":133,"show_sort_weight":22,"slug":134},"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]