{"id":"https://openalex.org/W4388886856","doi":"https://doi.org/10.1145/3605764.3623907","title":"AVScan2Vec: Feature Learning on Antivirus Scan Data for Production-Scale Malware Corpora","display_name":"AVScan2Vec: Feature Learning on Antivirus Scan Data for Production-Scale Malware Corpora","publication_year":2023,"publication_date":"2023-11-21","ids":{"openalex":"https://openalex.org/W4388886856","doi":"https://doi.org/10.1145/3605764.3623907"},"language":"en","primary_location":{"id":"doi:10.1145/3605764.3623907","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3605764.3623907","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5008388322","display_name":"Robert J. Joyce","orcid":"https://orcid.org/0009-0003-7168-1237"},"institutions":[{"id":"https://openalex.org/I1322124587","display_name":"Booz Allen Hamilton (United States)","ror":"https://ror.org/051rcp357","country_code":"US","type":"company","lineage":["https://openalex.org/I1322124587"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Robert J. Joyce","raw_affiliation_strings":["Booz Allen Hamilton, Catonsville, MD, USA"],"raw_orcid":"https://orcid.org/0009-0003-7168-1237","affiliations":[{"raw_affiliation_string":"Booz Allen Hamilton, Catonsville, MD, USA","institution_ids":["https://openalex.org/I1322124587"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085107523","display_name":"Tirth Patel","orcid":"https://orcid.org/0009-0003-3212-8156"},"institutions":[{"id":"https://openalex.org/I79272384","display_name":"University of Maryland, Baltimore County","ror":"https://ror.org/02qskvh78","country_code":"US","type":"education","lineage":["https://openalex.org/I79272384"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tirth Patel","raw_affiliation_strings":["University of Maryland, Baltimore County, Catonsville, MD, USA"],"raw_orcid":"https://orcid.org/0009-0003-3212-8156","affiliations":[{"raw_affiliation_string":"University of Maryland, Baltimore County, Catonsville, MD, USA","institution_ids":["https://openalex.org/I79272384"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025012064","display_name":"Charles Nicholas","orcid":"https://orcid.org/0000-0001-9494-7139"},"institutions":[{"id":"https://openalex.org/I79272384","display_name":"University of Maryland, Baltimore County","ror":"https://ror.org/02qskvh78","country_code":"US","type":"education","lineage":["https://openalex.org/I79272384"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Charles Nicholas","raw_affiliation_strings":["University of Maryland, Baltimore County, Catonsville, MD, USA"],"raw_orcid":"https://orcid.org/0000-0001-9494-7139","affiliations":[{"raw_affiliation_string":"University of Maryland, Baltimore County, Catonsville, MD, USA","institution_ids":["https://openalex.org/I79272384"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5068036546","display_name":"Edward Raff","orcid":"https://orcid.org/0000-0002-9900-1972"},"institutions":[{"id":"https://openalex.org/I1322124587","display_name":"Booz Allen Hamilton (United States)","ror":"https://ror.org/051rcp357","country_code":"US","type":"company","lineage":["https://openalex.org/I1322124587"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Edward Raff","raw_affiliation_strings":["Booz Allen Hamilton, Jamesville , MD, USA"],"raw_orcid":"https://orcid.org/0000-0002-9900-1972","affiliations":[{"raw_affiliation_string":"Booz Allen Hamilton, Jamesville , MD, USA","institution_ids":["https://openalex.org/I1322124587"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5008388322"],"corresponding_institution_ids":["https://openalex.org/I1322124587"],"apc_list":null,"apc_paid":null,"fwci":1.5351,"has_fulltext":false,"cited_by_count":8,"citation_normalized_percentile":{"value":0.84357784,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"185","last_page":"196"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9980999827384949,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8684357404708862},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.838549792766571},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.5205312967300415},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.5114771127700806},{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.4879562258720398},{"id":"https://openalex.org/keywords/search-engine-indexing","display_name":"Search engine indexing","score":0.47544288635253906},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4706997871398926},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.42307668924331665},{"id":"https://openalex.org/keywords/nearest-neighbor-search","display_name":"Nearest neighbor search","score":0.4131097197532654},{"id":"https://openalex.org/keywords/information-retrieval","display_name":"Information retrieval","score":0.3278261125087738},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.20340189337730408},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.13062426447868347}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8684357404708862},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.838549792766571},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.5205312967300415},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.5114771127700806},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.4879562258720398},{"id":"https://openalex.org/C75165309","wikidata":"https://www.wikidata.org/wiki/Q2258979","display_name":"Search engine indexing","level":2,"score":0.47544288635253906},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4706997871398926},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.42307668924331665},{"id":"https://openalex.org/C116738811","wikidata":"https://www.wikidata.org/wiki/Q608751","display_name":"Nearest neighbor search","level":2,"score":0.4131097197532654},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.3278261125087738},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.20340189337730408},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.13062426447868347},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3605764.3623907","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3605764.3623907","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":14,"referenced_works":["https://openalex.org/W1893133781","https://openalex.org/W1996975221","https://openalex.org/W2021436318","https://openalex.org/W2021963610","https://openalex.org/W2267635142","https://openalex.org/W2612690371","https://openalex.org/W2736972628","https://openalex.org/W2900633536","https://openalex.org/W2962756421","https://openalex.org/W2964150020","https://openalex.org/W2998001547","https://openalex.org/W3083599435","https://openalex.org/W3111533025","https://openalex.org/W7093349750"],"related_works":["https://openalex.org/W2097492617","https://openalex.org/W2753240997","https://openalex.org/W1764168690","https://openalex.org/W2537959205","https://openalex.org/W2740895074","https://openalex.org/W1949910768","https://openalex.org/W1480566255","https://openalex.org/W2254397067","https://openalex.org/W2013685631","https://openalex.org/W1882921205"],"abstract_inverted_index":{"When":[0],"investigating":[1],"a":[2,10,26,55,100,115,133,138],"malicious":[3,101,134],"file,":[4],"searching":[5],"for":[6,60,132],"related":[7],"files":[8,28],"is":[9,63,93],"common":[11],"task":[12],"that":[13,19,170,188,209],"malware":[14,21,84,182,196],"analysts":[15],"must":[16],"perform.":[17],"Given":[18],"production":[20,183],"corpora":[22],"may":[23],"contain":[24],"over":[25],"billion":[27],"and":[29,37,77,97,108,136,159,205],"consume":[30],"petabytes":[31],"of":[32,49,58,123],"storage,":[33],"many":[34,109],"feature":[35,197],"extraction":[36],"similarity":[38],"search":[39],"approaches":[40],"are":[41,69,78,144,191],"computationally":[42],"infeasible.":[43],"Our":[44],"work":[45],"explores":[46],"the":[47,82,121,180],"potential":[48],"antivirus":[50],"(AV)":[51],"scan":[52,67,91,125,130],"data":[53,131],"as":[54,75],"scalable":[56],"source":[57],"features":[59],"malware.":[61],"This":[62],"possible":[64],"because":[65],"AV":[66,90,124,129],"reports":[68],"widely":[70],"available":[71],"through":[72],"services":[73],"such":[74],"VirusTotal":[76],"~100x":[79],"smaller":[80,148],"than":[81,149],"average":[83],"sample.":[85],"The":[86],"information":[87,96],"within":[88],"an":[89],"report":[92],"abundant":[94],"with":[95],"can":[98,176],"indicate":[99],"file's":[102],"family,":[103],"behavior,":[104],"target":[105],"operating":[106],"system,":[107],"other":[110,194],"characteristics.":[111],"We":[112,185],"introduce":[113],"AVScan2Vec,":[114],"neural":[116],"model":[117],"trained":[118],"to":[119,146,178,193],"comprehend":[120],"semantics":[122],"data.":[126],"AVScan2Vec":[127,142,174,189],"ingests":[128],"file":[135],"outputs":[137],"meaningful":[139],"vector":[140,157,198],"representation.":[141],"vectors":[143,175,190],"~3":[145],"85x":[147],"popular":[150],"alternatives":[151],"in":[152],"use":[153],"today,":[154],"enabling":[155],"faster":[156],"comparisons":[158],"lower":[160],"memory":[161],"usage.":[162],"By":[163],"incorporating":[164],"Dynamic":[165],"Continuous":[166],"Indexing,":[167],"we":[168,210],"show":[169],"nearest-neighbor":[171,206],"queries":[172],"on":[173],"scale":[177],"even":[179],"largest":[181],"datasets.":[184],"also":[186],"demonstrate":[187],"superior":[192],"leading":[195],"representations":[199],"across":[200],"nearly":[201],"all":[202],"classification,":[203],"clustering,":[204],"lookup":[207],"algorithms":[208],"evaluated.":[211]},"counts_by_year":[{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
