Yan Zhang
2025.2.21Mari Papel y Corrugado
tlooto Summary
The model performs better in terms of precision, recall, and F1 value than conventional techniques like Node2Vec, GCN, and GraphSAGE, according to the trials done on the APIMDS and Mal-API-2019 datasets.
Abstract
In the realm of information security, malware detection in IoT environments is crucial. This research proposes a heterogeneous graph network based malware classification model to enhance the detection and categorization of sophisticated malware samples. The model is composed of five primary modules: a module for building heterogeneous graphs; a module for generating random wandering sequences; an aggregation module based on LSTM; a module for wandering based on attention mechanisms; and a module for classification and prediction. Initially, a heterogeneous graph comprising API and malware nodes is built, and using random wandering, the associations between far-off nodes are obtained to improve the representation of node features. Next, using the attention mechanism, LSTM is utilized to aggregate the data of nodes on various paths, learn how different paths affect nodes, and ultimately output the node categorization results through the linear layer. The model performs better in terms of precision, recall, and F1 value than conventional techniques like Node2Vec, GCN, and GraphSAGE, according to the trials done on the APIMDS and Mal-API-2019 datasets. Furthermore, by inserting, removing, and changing pointless API calls, robustness tests are carried out to confirm the model’s resilience to malware variants.
Citation format
ZHANG, Yan. An innovative deep learning method for iot malware identification. Mari Papel y Corrugado, 2025.