Leveraging intelligent multimodal fusion for few-shot malware classification

Ying Ren , Ziyu Liu , Junbo Wang , Peng Wang

Intelligence & Robotics ›› 2026, Vol. 6 ›› Issue (2) : 253 -74.

PDF
Intelligence & Robotics ›› 2026, Vol. 6 ›› Issue (2) :253 -74. DOI: 10.20517/ir.2026.13
Research Article
Leveraging intelligent multimodal fusion for few-shot malware classification
Author information +
History +
PDF

Abstract

Traditional malware classification methods heavily rely on extensive labeled data and single modal features, which limits their adaptability to evolving threats. In this paper, we propose an intelligent multimodal fusion framework that leverages complementary information from static and dynamic analysis for few-shot malware classification. Specifically, we convert malware binaries into grayscale images to capture static characteristics and extract application programming interface (API) call sequences to represent dynamic behaviors. To effectively integrate these heterogeneous modalities under limited data conditions, we introduce a lightweight graph neural network-based intelligent feature fusion module. This module segments modality-specific features, constructs a bipartite graph between segments, and performs cross-modal message passing to learn fine-grained correlations. The fused representations are then used in a prototypical network for few-shot classification. We construct two malware datasets augmented with multimodal features and conduct extensive experiments under few-shot settings. Results demonstrate that our approach significantly outperforms both unimodal baselines and naive fusion methods, achieving up to 95.73% accuracy in 5-way 5-shot classification. Ablation studies and efficiency analysis confirm that our fusion module adds minimal computational overhead while enhancing both accuracy and interpretability. This work highlights the potential of intelligent multimodal integration for robust malware classification with limited labeled data.

Keywords

Intelligent multimodal learning / multimodal feature fusion / malware classification / few-shot learning

Cite this article

Download citation ▾
Ying Ren, Ziyu Liu, Junbo Wang, Peng Wang. Leveraging intelligent multimodal fusion for few-shot malware classification. Intelligence & Robotics, 2026, 6 (2) : 253-74 DOI:10.20517/ir.2026.13

登录浏览全文

4963

注册一个新账户 忘记密码

References

[1]

Stuttard D. The web application hacker’s handbook: finding and exploiting security flaws. John Wiley & Sons; 2011. https://books.google.com/books?id=NSBHAAAAQBAJ. (accessed 2026-06-08)

[2]

Bhodia N,Di Troia F. Transfer learning for image-based malware classification. arXiv 2019, arXiv:1903.11551. Available online: https://doi.org/10.48550/arXiv.1903.11551. (accessed 2026-06-08)

[3]

Vu DL,Nguyen TV,Massacci F.A convolutional transformation network for malware classification. In 2019 6th NAFOSTED conference on information and computer science (NICS). Hanoi, Vietnam, Dec 12-13, 2019. IEEE; 2019. pp. 234-39.

[4]

Vasan D,Wassan S,Zheng Q.Image-based malware classification using ensemble of CNN architectures (IMCEC).Comput Secur2020;92:101748

[5]

Kolosnjaji B,Webster G.Deep learning for classification of malware system call sequences. In AI 2016: Advances in Artificial Intelligence: 29th Australasian Joint Conference. Hobart, Australia, December 5-8, 2016. Springer; 2016. pp. 137-49.

[6]

Wang P,Wang J.A novel few-shot malware classification approach for unknown family recognition with multi-prototype modeling.Comput Secur2021;106:102273

[7]

Wang J,Wu H.AGProto: adaptive graph ProtoNet towards sample adaption for few-shot malware classification.Electronics2024;13:935

[8]

Snell J,Zemel R. Prototypical networks for few-shot learning. arXiv 2017, arXiv:1703.05175. Available online: https://doi.org/10.48550/arXiv.1703.05175. (accessed 2026-06-08)

[9]

Vinayakumar R,Soman K,Venkatraman S.Robust intelligent malware detection using deep learning.IEEE Access2019;7:46717-38

[10]

Raff E,Sylvester J,Catanzaro B. Malware detection by eating a whole EXE. arXiv 2017, arXiv:1710.09435. Available online: https://doi.org/10.48550/arXiv.1710.09435. (accessed 2026-06-08)

[11]

Gibert D,Planes J.A hierarchical convolutional neural network for malware classification. In 2019 International Joint Conference on Neural Networks (IJCNN). Budapeest, Hungary, Jul 14-19, 2019. IEEE; 2019. pp. 1-8.

[12]

Raff E,Cox R.An investigation of byte n-gram features for malware classification.J Comput Virol Hack Tech2018;14:1-20

[13]

Cui Z,Cai X,Wang Gg.Detection of malicious code variants based on deep learning.IEEE Trans Ind Inform2018;14:3187-96

[14]

Jiang Y,Wu Y.A novel image-based malware classification model using deep learning. In International Conference on Neural Information Processing. Springer; 2019. pp. 150-61.

[15]

Yuan B,Liu D,Wu P.Byte-level malware classification based on markov images and deep learning.Comput Secur2020;92:101740

[16]

Sharma O,Kalia A.Windows and IoT malware visualization and classification with deep CNN and Xception CNN using Markov images.J Intell Inf Syst2023;60:349-75

[17]

Azmoodeh A,Choo KKR.Robust malware detection for internet of (battlefield) things devices using deep eigenspace learning.IEEE Trans Sustain Comput2019;4:88-95

[18]

Zhu H,Wang L,Sheng VS.Android malware detection based on multi-head squeeze-and-excitation residual network.Expert Syst Appl2023;212:118705

[19]

Sasidharan SK.ProDroid - an Android malware detection framework based on profile hidden Markov model.Pervasive Mob Comput2021;72:101336

[20]

Lee YT,Wan TL.Cross platform IoT-malware family classification based on printable strings. In 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). Guangzhou, China, Dec 29 2020 - Jan 01 2021. IEEE; 2020. pp. 775-84.

[21]

Han W,Wang Y,Kong Z.MalDAE: detecting and explaining malware based on correlation and fusion of static and dynamic characteristics.Comput Secur2019;83:208-33

[22]

Xu J,Deng RH.SDAC: a slow-aging solution for android malware detection using semantic distance based API clustering.IEEE Trans Dependable Secure Comput2022;19:1149-63

[23]

Yan S,Wang W,Zhang W.A survey of adversarial attack and defense methods for malware classification in cyber security.IEEE Commun Surv Tutor2023;25:467-96

[24]

Han X,Pasquier T. SIGL: Securing software installations through deep graph learning. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association; 2021. pp. 2345-62. https://www.usenix.org/conference/usenixsecurity21/presentation/han-xueyuan. (accessed 2026-06-08)

[25]

Amer E,El-Sappagh S.A multi-perspective malware detection approach through behavioral fusion of API call sequence.Comput Secur2021;110:102449

[26]

Lin K,Xiao F.MFFusion: a multi-level features fusion model for malicious traffic detection based on deep learning.Comput Netw2022;202:108658

[27]

Almashhadani AO,Kaiiali M.MFMCNS: a multi-feature and multi-classifier network-based system for ransomworm detection.Comput Secur2022;121:102860

[28]

Wang Q,Li D. You are what you do: hunting stealthy malware via data provenance analysis. In Network and Distributed Systems Security (NDSS) Symposium 2020. San Diego, USA, Feb 23-26, 2020. https://www.ndss-symposium.org/wp-content/uploads/2020/02/24167.pdf. (accessed 2026-06-08)

[29]

Damodaran A,Visaggio CA,Stamp M.A comparison of static, dynamic, and hybrid analysis for malware detection.J Comput Virol Hack Tech2017;13:1-12

[30]

Gopinath M.A comprehensive survey on deep learning based malware detection techniques.Comput Sci Rev2023;47:100529

[31]

Huang X,Yang W.A method for windows malware detection based on deep learning.J Sign Process Syst2021;93:265-73

[32]

Yoo S,Kim S.AI-HydRa: advanced hybrid approach using random forest and deep learning for malware classification.Inform Sci2021;546:420-35

[33]

Nguyen TN,Nguyen HT.An advanced computing approach for IoT-botnet detection in industrial Internet of Things.IEEE Trans Ind Inform2022;18:8298-306

[34]

O’Shaughnessy S.Image-based malware classification hybrid framework based on space-filling curves.Comput Secur2022;116:102660

[35]

Kim T,Rho M,Im EG.A multimodal deep learning method for android malware detection using various features.IEEE Trans Inf Forensics Secur2019;14:773-88

[36]

Gibert D,Planes J.HYDRA: a multimodal deep learning framework for malware classification.Comput Secur2020;95:101873

[37]

Dib M,Bou-Harb E.A multi-dimensional deep learning framework for iot malware classification and family attribution.IEEE Trans Netw Serv Manag2021;18:1165-77

[38]

He Y,Qin Z,Chen C.Combating concept drift with explanatory detection and adaptation for Android malware classification. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security. New York, USA. Association for Computing Machinery; 2025. pp. 978-92.

[39]

Chai Y,Qiu J.MalFSCIL: a few-shot class-incremental learning approach for malware detection.IEEE Trans Inf Forensics Secur2025;20:2999-3014

[40]

Miller SJ,Adams P,Slater R. Multi-modal classification using images and text. SMU Data Sci. Rev. 2020, 3, 6. https://scholar.smu.edu/cgi/viewcontent.cgi?article=1165&context=datasciencereview. (accessed 2026-06-08)

[41]

Audebert N,Slimani K.Multimodal deep networks for text and image-based document classification. In Machine Learning and Knowledge Discovery in Databases: International Workshops of ECML PKDD 2019. Würzburg, Germany, Sep 16-20, 2019. Springer; 2020. pp. 427-43.

[42]

Antol S,Lu J. VQA: visual question answering. 2015. https://openaccess.thecvf.com/content_iccv_2015/papers/Antol_VQA_Visual_Question_ICCV_2015_paper.pdf. (accessed 2026-06-08)

[43]

Xu K,Kiros R. Show, attend and tell: neural image caption generation with visual attention. In Proceedings of the 32nd International Conference on Machine Learning, PMLR. 2015. pp. 2048-57. https://proceedings.mlr.press/v37/xuc15.html. (accessed 2026-06-08)

[44]

Anderson P,Buehler C.Bottom-up and top-down attention for image captioning and visual question answering. In 2018 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). 2018. pp. 6077-86.

[45]

Simonyan K. Very deep convolutional networks for large-scale image recognition. arXiv 2014, arXiv:1409.1556. Available online: https://doi.org/10.48550/arXiv.1409.1556. (accessed 2026-06-08)

[46]

Hochreiter S.Long short-term memory.Neural Comput1997;9:1735-80

[47]

Yang Z,Gao J,Smola A. Stacked attention networks for image question answering. arXiv 2015, arXiv:1511.02274. Available online: https://doi.org/10.48550/arXiv.1511.02274. (accessed 2026-06-08)

[48]

Kim JH,Zhang BT. Bilinear attention networks. arXiv 2018, arXiv:1805.07932. Available online: https://doi.org/10.48550/arXiv.1805.07932. (accessed 2026-06-08)

[49]

Vaswani A,Parmar N. Attention is all you need. arXiv 2017, arXiv:1706.03762. Available online: https://doi.org/10.48550/arXiv.1706.03762. (accessed 2026-06-08)

[50]

Devlin J,Lee K. BERT: pre-training of deep bidirectional transformers for language understanding. arXiv 2018, arXiv:1810.04805. Available online: https://doi.org/10.48550/arXiv.1810.04805. (accessed 2026-06-08)

[51]

Nataraj L,Jacob G.Malware images: visualization and automatic classification. In Proceedings of the 8th International Symposium on Visualization for Cyber Security. Association for Computing Machinery; 2011. p. 1-7.

[52]

Seok S.Visualized malware classification based-on convolutional neural network.J Korea Inst Inf Secur Cryptol2016;26:197-208https://www.researchgate.net/publication/301236691_Visualized_Malware_Classification_Based-on_Convolutional_Neural_Network. (accessed 2026-06-08)

[53]

Hospedales T,Micaelli P. Meta-learning in neural networks: a survey. IEEE Trans. Pattern Anal. Mach. Intell. 2021, 44, 5149-69. https://ieeexplore.ieee.org/stamp/stamp.jsp?arnumber=9428530. (accessed 2026-06-08)

[54]

Song Y,Mondal SK. A comprehensive survey of few-shot learning: evolution, applications, challenges, and opportunities. arXiv 2022, arXiv:2205.06743. Available online: https://doi.org/10.48550/arXiv.2205.06743. (accessed 2026-06-08)

[55]

Vinyals O,Lillicrap T,Wierstra D. Matching networks for one shot learning. arXiv 2016, arXiv:1606.04080. Available online: https://doi.org/10.48550/arXiv.1606.04080. (accessed 2026-06-08)

[56]

Gao T,Liu Z.Hybrid attention-based prototypical networks for noisy few-shot relation classification.Proc AAAI Conf Artif Intell2019;33:6407-14

[57]

Ndibanje B,Kang YJ,Kim TY.Cross-method-based analysis and classification of malicious behavior by API calls extraction.Appl Sci2019;9:239

[58]

Belal MM.Global-local attention-based butterfly vision transformer for visualization-based malware classification.IEEE Access2023;11:69337-55

[59]

Paszke A,Chintala S. Automatic differentiation in PyTorch. In 31st Conference on Neural Information Processing Systems (NIPS 2017). Long Beach, USA. 2017. https://openreview.net/pdf?id=BJJsrmfCZ. (accessed 2026-06-08)

PDF

0

Accesses

0

Citation

Detail

Sections
Recommended

/