{"id":"https://openalex.org/W2984666763","doi":"https://doi.org/10.1145/3338501.3357374","title":"Malware Detection on Highly Imbalanced Data through Sequence Modeling","display_name":"Malware Detection on Highly Imbalanced Data through Sequence Modeling","publication_year":2019,"publication_date":"2019-11-08","ids":{"openalex":"https://openalex.org/W2984666763","doi":"https://doi.org/10.1145/3338501.3357374","mag":"2984666763"},"language":"en","primary_location":{"id":"doi:10.1145/3338501.3357374","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3338501.3357374","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3338501.3357374","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3338501.3357374","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5001097796","display_name":"Rajvardhan Oak","orcid":"https://orcid.org/0000-0003-1928-099X"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Rajvardhan Oak","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102737328","display_name":"Min Du","orcid":"https://orcid.org/0000-0002-8277-0206"},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Min Du","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045187233","display_name":"David Yan","orcid":null},"institutions":[{"id":"https://openalex.org/I95457486","display_name":"University of California, Berkeley","ror":"https://ror.org/01an7q238","country_code":"US","type":"education","lineage":["https://openalex.org/I95457486"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"David Yan","raw_affiliation_strings":["University of California, Berkeley, Berkeley, CA, USA"],"affiliations":[{"raw_affiliation_string":"University of California, Berkeley, Berkeley, CA, USA","institution_ids":["https://openalex.org/I95457486"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5067768850","display_name":"Harshvardhan Takawale","orcid":"https://orcid.org/0000-0002-5454-8413"},"institutions":[{"id":"https://openalex.org/I74796645","display_name":"Birla Institute of Technology and Science, Pilani","ror":"https://ror.org/001p3jz28","country_code":"IN","type":"education","lineage":["https://openalex.org/I74796645"]}],"countries":["IN"],"is_corresponding":false,"raw_author_name":"Harshvardhan Takawale","raw_affiliation_strings":["BITS Pilani, Hyderabad, UNK, India"],"affiliations":[{"raw_affiliation_string":"BITS Pilani, Hyderabad, UNK, India","institution_ids":["https://openalex.org/I74796645"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5109440792","display_name":"Idan Amit","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Idan Amit","raw_affiliation_strings":["Palo Alto Networks, Tel-Aviv, Israel"],"affiliations":[{"raw_affiliation_string":"Palo Alto Networks, Tel-Aviv, Israel","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5001097796"],"corresponding_institution_ids":["https://openalex.org/I95457486"],"apc_list":null,"apc_paid":null,"fwci":10.8946,"has_fulltext":true,"cited_by_count":112,"citation_normalized_percentile":{"value":0.98975172,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"37","last_page":"48"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9972000122070312,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9944000244140625,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.9130947589874268},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8414596319198608},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5952271819114685},{"id":"https://openalex.org/keywords/android-malware","display_name":"Android malware","score":0.5755248665809631},{"id":"https://openalex.org/keywords/sequence","display_name":"Sequence (biology)","score":0.5116286873817444},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5109519362449646},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.4864775836467743},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4837224781513214},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.10503020882606506}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.9130947589874268},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8414596319198608},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5952271819114685},{"id":"https://openalex.org/C2989133298","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android malware","level":3,"score":0.5755248665809631},{"id":"https://openalex.org/C2778112365","wikidata":"https://www.wikidata.org/wiki/Q3511065","display_name":"Sequence (biology)","level":2,"score":0.5116286873817444},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5109519362449646},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.4864775836467743},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4837224781513214},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.10503020882606506},{"id":"https://openalex.org/C54355233","wikidata":"https://www.wikidata.org/wiki/Q7162","display_name":"Genetics","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3338501.3357374","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3338501.3357374","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3338501.3357374","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3338501.3357374","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3338501.3357374","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3338501.3357374","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320333609","display_name":"Center for Long-Term Cybersecurity, University of California Berkeley","ror":null}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2984666763.pdf","grobid_xml":"https://content.openalex.org/works/W2984666763.grobid-xml"},"referenced_works_count":39,"referenced_works":["https://openalex.org/W258019806","https://openalex.org/W1516184288","https://openalex.org/W1686810756","https://openalex.org/W1980867644","https://openalex.org/W1990649188","https://openalex.org/W1999489595","https://openalex.org/W2002478203","https://openalex.org/W2053724458","https://openalex.org/W2057787526","https://openalex.org/W2064675550","https://openalex.org/W2077278164","https://openalex.org/W2122672392","https://openalex.org/W2131523719","https://openalex.org/W2132870739","https://openalex.org/W2140190241","https://openalex.org/W2151135920","https://openalex.org/W2154871153","https://openalex.org/W2251939518","https://openalex.org/W2407313496","https://openalex.org/W2471853823","https://openalex.org/W2586845402","https://openalex.org/W2626778328","https://openalex.org/W2767094836","https://openalex.org/W2776884785","https://openalex.org/W2786088545","https://openalex.org/W2789983203","https://openalex.org/W2804337196","https://openalex.org/W2913493033","https://openalex.org/W2914516771","https://openalex.org/W2949868354","https://openalex.org/W2950133940","https://openalex.org/W2950813464","https://openalex.org/W2963088995","https://openalex.org/W2963341956","https://openalex.org/W2964223283","https://openalex.org/W2966252319","https://openalex.org/W2984100107","https://openalex.org/W4205671217","https://openalex.org/W4212774754"],"related_works":["https://openalex.org/W2782775281","https://openalex.org/W2560361988","https://openalex.org/W2507113366","https://openalex.org/W3025122950","https://openalex.org/W2311926078","https://openalex.org/W3200508744","https://openalex.org/W2462192250","https://openalex.org/W4312234627","https://openalex.org/W3195312353","https://openalex.org/W2717179875"],"abstract_inverted_index":{"We":[0,20,88,123],"explore":[1],"the":[2,27,49,52,102,140,153],"task":[3],"of":[4,12,26,54,61,72,98,134,139,155],"Android":[5],"malware":[6,55,99,115],"detection":[7,116],"based":[8,128],"on":[9],"dynamic":[10],"analysis":[11],"application":[13],"activity":[14],"sequences":[15,38],"using":[16],"deep":[17],"learning":[18],"techniques.":[19],"show":[21,107],"that":[22,35,60,108,125],"analyzing":[23,36],"a":[24,44,95],"sequence":[25],"activities":[28],"is":[29,56,78,110],"informative":[30],"for":[31],"detecting":[32],"malware,":[33,143],"but":[34],"longer":[37],"does":[39],"not":[40],"necessarily":[41],"lead":[42],"to":[43,59,112],"more":[45,67],"accurate":[46],"model.":[47],"In":[48],"real-world":[50,90],"scenario,":[51],"number":[53],"low":[57],"compared":[58],"harmless":[62],"applications.":[63],"Our":[64],"dataset":[65,77],"has":[66],"than":[68,81],"180,000":[69],"samples,":[70],"two-thirds":[71],"which":[73,144],"are":[74],"malware.":[75],"This":[76],"significantly":[79,145],"larger":[80],"other":[82],"datasets":[83],"used":[84],"in":[85,159],"previous":[86],"studies.":[87],"mimic":[89],"cases":[91],"by":[92],"randomly":[93],"sampling":[94],"small":[96],"portion":[97],"samples.":[100],"Using":[101],"state-of-the-art":[103,148],"model":[104,129],"BERT,":[105],"we":[106],"it":[109],"possible":[111],"achieve":[113],"desired":[114],"performance":[117],"with":[118,136,161],"an":[119,131],"extremely":[120],"unbalanced":[121],"dataset.":[122],"find":[124],"our":[126,156],"BERT":[127],"achieves":[130],"F1":[132],"score":[133],"0.919":[135],"just":[137],"0.5%":[138],"examples":[141],"being":[142],"outperforms":[146],"current":[147],"approaches.":[149],"The":[150],"results":[151],"validate":[152],"effectiveness":[154],"proposed":[157],"method":[158],"dealing":[160],"highly":[162],"imbalanced":[163],"datasets.":[164]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":12},{"year":2024,"cited_by_count":21},{"year":2023,"cited_by_count":12},{"year":2022,"cited_by_count":49},{"year":2021,"cited_by_count":12},{"year":2020,"cited_by_count":4}],"updated_date":"2026-03-31T07:56:22.981413","created_date":"2025-10-10T00:00:00"}
