{"id":"https://openalex.org/W3186739895","doi":"https://doi.org/10.1109/tdsc.2021.3097296","title":"DL-FHMC: Deep Learning-Based Fine-Grained Hierarchical Learning Approach for Robust Malware Classification","display_name":"DL-FHMC: Deep Learning-Based Fine-Grained Hierarchical Learning Approach for Robust Malware Classification","publication_year":2021,"publication_date":"2021-08-24","ids":{"openalex":"https://openalex.org/W3186739895","doi":"https://doi.org/10.1109/tdsc.2021.3097296","mag":"3186739895"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2021.3097296","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2021.3097296","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5005907786","display_name":"Ahmed Abusnaina","orcid":"https://orcid.org/0000-0001-5032-3412"},"institutions":[{"id":"https://openalex.org/I106165777","display_name":"University of Central Florida","ror":"https://ror.org/036nfer12","country_code":"US","type":"education","lineage":["https://openalex.org/I106165777"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ahmed Abusnaina","raw_affiliation_strings":["Department of Computer Science, University of Central Florida, Orlando, FL, USA"],"raw_orcid":"https://orcid.org/0000-0001-5032-3412","affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Central Florida, Orlando, FL, USA","institution_ids":["https://openalex.org/I106165777"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5042456819","display_name":"Mohammed Abuhamad","orcid":"https://orcid.org/0000-0002-3368-6024"},"institutions":[{"id":"https://openalex.org/I1925986","display_name":"Loyola University Chicago","ror":"https://ror.org/04b6x2g63","country_code":"US","type":"education","lineage":["https://openalex.org/I1925986"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mohammed Abuhamad","raw_affiliation_strings":["Department of Computer Science, Loyola University, Chicago, IL, USA"],"raw_orcid":"https://orcid.org/0000-0002-3368-6024","affiliations":[{"raw_affiliation_string":"Department of Computer Science, Loyola University, Chicago, IL, USA","institution_ids":["https://openalex.org/I1925986"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067599262","display_name":"Hisham Alasmary","orcid":"https://orcid.org/0000-0002-6482-3968"},"institutions":[{"id":"https://openalex.org/I82952536","display_name":"King Khalid University","ror":"https://ror.org/052kwzs30","country_code":"SA","type":"education","lineage":["https://openalex.org/I82952536"]}],"countries":["SA"],"is_corresponding":false,"raw_author_name":"Hisham Alasmary","raw_affiliation_strings":["Department of Computer Science, King Khalid University, Abha, Saudi Arabia"],"raw_orcid":"https://orcid.org/0000-0002-6482-3968","affiliations":[{"raw_affiliation_string":"Department of Computer Science, King Khalid University, Abha, Saudi Arabia","institution_ids":["https://openalex.org/I82952536"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5064140739","display_name":"Afsah Anwar","orcid":"https://orcid.org/0000-0003-1449-3590"},"institutions":[{"id":"https://openalex.org/I106165777","display_name":"University of Central Florida","ror":"https://ror.org/036nfer12","country_code":"US","type":"education","lineage":["https://openalex.org/I106165777"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Afsah Anwar","raw_affiliation_strings":["Department of Computer Science, University of Central Florida, Orlando, FL, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Central Florida, Orlando, FL, USA","institution_ids":["https://openalex.org/I106165777"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5017780520","display_name":"Rhongho Jang","orcid":"https://orcid.org/0000-0002-3417-6851"},"institutions":[{"id":"https://openalex.org/I185443292","display_name":"Wayne State University","ror":"https://ror.org/01070mq45","country_code":"US","type":"education","lineage":["https://openalex.org/I185443292"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Rhongho Jang","raw_affiliation_strings":["Department of Computer Science, Wayne State University, Detroit, MI, USA"],"raw_orcid":"https://orcid.org/0000-0002-3417-6851","affiliations":[{"raw_affiliation_string":"Department of Computer Science, Wayne State University, Detroit, MI, USA","institution_ids":["https://openalex.org/I185443292"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091100480","display_name":"Saeed Salem","orcid":"https://orcid.org/0000-0001-6478-4674"},"institutions":[{"id":"https://openalex.org/I57328836","display_name":"North Dakota State University","ror":"https://ror.org/05h1bnb22","country_code":"US","type":"education","lineage":["https://openalex.org/I57328836"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Saeed Salem","raw_affiliation_strings":["Department of Computer Science, North Dakota State University, Fargo, ND, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Computer Science, North Dakota State University, Fargo, ND, USA","institution_ids":["https://openalex.org/I57328836"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5079230730","display_name":"DaeHun Nyang","orcid":"https://orcid.org/0000-0001-5183-891X"},"institutions":[{"id":"https://openalex.org/I88386943","display_name":"Baewha Women's University","ror":"https://ror.org/02sd77t30","country_code":"KR","type":"education","lineage":["https://openalex.org/I88386943"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"DaeHun Nyang","raw_affiliation_strings":["Department of Cyber Security, Ewha Women University, Seoul, South Korea"],"raw_orcid":"https://orcid.org/0000-0001-5183-891X","affiliations":[{"raw_affiliation_string":"Department of Cyber Security, Ewha Women University, Seoul, South Korea","institution_ids":["https://openalex.org/I88386943"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5077402873","display_name":"Aziz Mohaisen","orcid":"https://orcid.org/0000-0003-3227-2505"},"institutions":[{"id":"https://openalex.org/I106165777","display_name":"University of Central Florida","ror":"https://ror.org/036nfer12","country_code":"US","type":"education","lineage":["https://openalex.org/I106165777"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"David Mohaisen","raw_affiliation_strings":["Department of Computer Science, University of Central Florida, Orlando, FL, USA"],"raw_orcid":"https://orcid.org/0000-0003-3227-2505","affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Central Florida, Orlando, FL, USA","institution_ids":["https://openalex.org/I106165777"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":8,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":6.3312,"has_fulltext":false,"cited_by_count":58,"citation_normalized_percentile":{"value":0.97449287,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":100},"biblio":{"volume":"19","issue":"5","first_page":"3432","last_page":"3447"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9902999997138977,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.884480357170105},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8524840474128723},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.681483805179596},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.6524096727371216},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.5377867817878723},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.5375243425369263},{"id":"https://openalex.org/keywords/overhead","display_name":"Overhead (engineering)","score":0.48864036798477173},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2177806794643402}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.884480357170105},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8524840474128723},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.681483805179596},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.6524096727371216},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.5377867817878723},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.5375243425369263},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.48864036798477173},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2177806794643402},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tdsc.2021.3097296","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2021.3097296","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320320671","display_name":"National Research Foundation","ror":"https://ror.org/05s0g1g46"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":54,"referenced_works":["https://openalex.org/W121173099","https://openalex.org/W134490355","https://openalex.org/W1584505081","https://openalex.org/W1587106557","https://openalex.org/W1975966552","https://openalex.org/W1981221397","https://openalex.org/W2010256880","https://openalex.org/W2095343582","https://openalex.org/W2095705004","https://openalex.org/W2104495462","https://openalex.org/W2111038628","https://openalex.org/W2122672392","https://openalex.org/W2147405597","https://openalex.org/W2151135920","https://openalex.org/W2166128942","https://openalex.org/W2170726034","https://openalex.org/W2180612164","https://openalex.org/W2216498498","https://openalex.org/W2243397390","https://openalex.org/W2324464293","https://openalex.org/W2360903897","https://openalex.org/W2514847810","https://openalex.org/W2561975083","https://openalex.org/W2591830932","https://openalex.org/W2602652370","https://openalex.org/W2603766943","https://openalex.org/W2607219512","https://openalex.org/W2613352518","https://openalex.org/W2744095836","https://openalex.org/W2792450155","https://openalex.org/W2897812226","https://openalex.org/W2901828657","https://openalex.org/W2961099251","https://openalex.org/W2963204406","https://openalex.org/W2963564844","https://openalex.org/W2963777745","https://openalex.org/W2963857521","https://openalex.org/W2966342255","https://openalex.org/W2973628901","https://openalex.org/W2982596671","https://openalex.org/W2987962504","https://openalex.org/W2991206321","https://openalex.org/W3099284022","https://openalex.org/W3102720581","https://openalex.org/W3112311055","https://openalex.org/W3131231119","https://openalex.org/W3159204880","https://openalex.org/W4230608978","https://openalex.org/W6622262455","https://openalex.org/W6633578641","https://openalex.org/W6640425456","https://openalex.org/W6674330103","https://openalex.org/W6734787559","https://openalex.org/W6754279747"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W4285226279","https://openalex.org/W4380075502"],"abstract_inverted_index":{"The":[0,216],"acceptance":[1],"of":[2,5,20,26,60,110,117,162,229],"the":[3,17,24,58,70,123,160,169,230],"Internet":[4],"Things":[6],"(IoT)":[7],"for":[8,47,84,97,133,210],"both":[9],"household":[10],"and":[11,32,41,50,127,140,153,183,208],"industrial":[12],"applications":[13],"is":[14],"accompanied":[15],"by":[16,66,122],"rapid":[18],"growth":[19],"IoT":[21,34,86,99,119,164,203],"malware.":[22],"With":[23],"increase":[25],"their":[27,234],"attack":[28],"surface,":[29],"analyzing,":[30],"understanding,":[31],"detecting":[33,150],"malicious":[35,100,118,134,204],"behavior":[36,135],"are":[37,45],"crucial.":[38],"Traditionally,":[39],"machine":[40,138],"deep":[42],"learning-based":[43],"approaches":[44,62],"used":[46],"malware":[48,87,151,165],"detection":[49,166,212],"behavioral":[51,95,111,198],"understanding.":[52],"However,":[53],"recent":[54],"research":[55],"has":[56],"shown":[57],"susceptibility":[59],"those":[61],"to":[63,69],"adversarial":[64,98,154,170,231],"attacks":[65,232],"introducing":[67],"noise":[68],"feature":[71],"space.":[72],"In":[73,103],"this":[74],"work,":[75],"we":[76,105],"introduce":[77,189],"DL-FHMC,":[78],"a":[79,107,114,131,193,221],"fine-grained":[80],"hierarchical":[81],"learning":[82,139],"approach":[83],"robust":[85],"detection.":[88,102,136],"DL-FHMC":[89,145],"utilizes":[90],"Control":[91],"Flow":[92],"Graph":[93,181],"(CFG)-based":[94],"patterns":[96,112,199],"software":[101],"particular,":[104],"extract":[106],"comprehensive":[108,197],"list":[109],"from":[113,200],"large":[115],"dataset":[116],"binaries,":[120],"represented":[121],"shared":[124],"execution":[125],"flows,":[126],"use":[128],"them":[129],"as":[130,220],"modality":[132],"Leveraging":[137],"subgraph":[141],"isomorphism":[142],"matching":[143],"algorithms,":[144],"provides":[146],"state-of-the-art":[147],"performance":[148],"in":[149,172],"samples":[152],"examples":[155],"(AEs).":[156],"We":[157,187],"first":[158],"highlight":[159],"caveats":[161],"CFG-based":[163],"systems,":[167],"showing":[168],"capabilities":[171],"generating":[173],"practical":[174],"functionality-preserving":[175],"AEs":[176,211],"with":[177,213,225],"reduced":[178],"overhead":[179],"using":[180],"Embedding":[182],"Augmentation":[184],"(GEA)":[185],"techniques.":[186],"then":[188],"Suspicious":[190],"Behavior":[191],"Detector,":[192],"component":[194],"that":[195],"extracts":[196],"three":[201],"popular":[202],"families,":[205],"Gafgyt,":[206],"Mirai,":[207],"Tsunami,":[209],"high":[214],"accuracy.":[215],"proposed":[217],"detector":[218],"operates":[219],"model-independent":[222],"standalone":[223],"module,":[224],"no":[226],"prior":[227],"assumptions":[228],"nor":[233],"configurations.":[235]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":16},{"year":2024,"cited_by_count":20},{"year":2023,"cited_by_count":14},{"year":2022,"cited_by_count":7}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
