{"id":"https://openalex.org/W7143494402","doi":"https://doi.org/10.48550/arxiv.2603.26632","title":"Machine Learning Transferability for Malware Detection","display_name":"Machine Learning Transferability for Malware Detection","publication_year":2026,"publication_date":"2026-03-27","ids":{"openalex":"https://openalex.org/W7143494402","doi":"https://doi.org/10.48550/arxiv.2603.26632"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.26632","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.26632","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.26632","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5130968868","display_name":"C\u00e9sar Vieira","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Vieira, C\u00e9sar","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000190815","display_name":"Jo\u00e3o Vitorino","orcid":"https://orcid.org/0000-0002-4968-3653"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Vitorino, Jo\u00e3o","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5004608532","display_name":"Eva Maia","orcid":"https://orcid.org/0000-0002-8075-531X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Maia, Eva","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5130968350","display_name":"Isabel Pra\u00e7a","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Pra\u00e7a, Isabel","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9628999829292297,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9628999829292297,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.01080000028014183,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.006200000178068876,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/preprocessor","display_name":"Preprocessor","score":0.6866000294685364},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.560699999332428},{"id":"https://openalex.org/keywords/executable","display_name":"Executable","score":0.5291000008583069},{"id":"https://openalex.org/keywords/obfuscation","display_name":"Obfuscation","score":0.4731000065803528},{"id":"https://openalex.org/keywords/data-pre-processing","display_name":"Data pre-processing","score":0.47099998593330383},{"id":"https://openalex.org/keywords/transferability","display_name":"Transferability","score":0.451200008392334},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.3968000113964081},{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.3555000126361847}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7207000255584717},{"id":"https://openalex.org/C34736171","wikidata":"https://www.wikidata.org/wiki/Q918333","display_name":"Preprocessor","level":2,"score":0.6866000294685364},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5860999822616577},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5681999921798706},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.560699999332428},{"id":"https://openalex.org/C160145156","wikidata":"https://www.wikidata.org/wiki/Q778586","display_name":"Executable","level":2,"score":0.5291000008583069},{"id":"https://openalex.org/C40305131","wikidata":"https://www.wikidata.org/wiki/Q2616305","display_name":"Obfuscation","level":2,"score":0.4731000065803528},{"id":"https://openalex.org/C10551718","wikidata":"https://www.wikidata.org/wiki/Q5227332","display_name":"Data pre-processing","level":2,"score":0.47099998593330383},{"id":"https://openalex.org/C61272859","wikidata":"https://www.wikidata.org/wiki/Q7834031","display_name":"Transferability","level":3,"score":0.451200008392334},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.3968000113964081},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.3555000126361847},{"id":"https://openalex.org/C43521106","wikidata":"https://www.wikidata.org/wiki/Q2165493","display_name":"Pipeline (software)","level":2,"score":0.3522000014781952},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.3253999948501587},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.2969000041484833},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.2964000105857849},{"id":"https://openalex.org/C519991488","wikidata":"https://www.wikidata.org/wiki/Q28865","display_name":"Python (programming language)","level":2,"score":0.288100004196167},{"id":"https://openalex.org/C2779696439","wikidata":"https://www.wikidata.org/wiki/Q7512811","display_name":"Signature (topology)","level":2,"score":0.2754000127315521},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.26840001344680786},{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.2653000056743622},{"id":"https://openalex.org/C136389625","wikidata":"https://www.wikidata.org/wiki/Q334384","display_name":"Supervised learning","level":3,"score":0.26260000467300415},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.25940001010894775}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.26632","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.26632","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.26632","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.26632","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Malware":[0],"continues":[1],"to":[2,16,54],"be":[3],"a":[4,35],"predominant":[5],"operational":[6],"risk":[7],"for":[8,67,127,129],"organizations,":[9],"especially":[10],"when":[11,46],"obfuscation":[12],"techniques":[13],"are":[14,116],"used":[15,126],"evade":[17],"detection.":[18],"Despite":[19],"the":[20,24,60,68,130],"ongoing":[21],"efforts":[22],"in":[23,40],"development":[25],"of":[26,37,62,70],"Machine":[27],"Learning":[28],"(ML)":[29],"detection":[30,69],"approaches,":[31],"there":[32],"is":[33,124],"still":[34],"lack":[36],"feature":[38],"compatibility":[39],"public":[41],"datasets.":[42,56],"This":[43,57],"limits":[44],"generalization":[45],"facing":[47],"distribution":[48],"shifts,":[49],"as":[50,52],"well":[51],"transferability":[53],"different":[55,63],"study":[58],"evaluates":[59],"suitability":[61],"data":[64],"preprocessing":[65,79],"approaches":[66],"Portable":[71],"Executable":[72],"(PE)":[73],"files":[74],"with":[75],"ML":[76],"models.":[77],"The":[78],"pipeline":[80],"unifies":[81],"EMBERv2":[82],"(2,381-dim)":[83],"features":[84],"datasets,":[85],"trains":[86],"paired":[87],"models":[88,115],"under":[89],"two":[90],"training":[91],"setups:":[92],"EMBER":[93,97,106,110,131],"+":[94,98,100,107,111,113,132],"BODMAS":[95,99,108,112,133],"and":[96,109,121],"ERMDS.":[101],"Regarding":[102],"model":[103],"evaluation,":[104],"both":[105],"ERMDS":[114,123],"tested":[117],"against":[118],"TRITIUM,":[119],"INFERNO":[120],"SOREL-20M.":[122],"also":[125],"testing":[128],"setup.":[134]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-31T00:00:00"}
