{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T01:06:58Z","timestamp":1779325618302,"version":"3.51.4"},"publisher-location":"Cham","reference-count":35,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032061690","type":"print"},{"value":"9783032061706","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T00:00:00Z","timestamp":1757548800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,11]],"date-time":"2025-09-11T00:00:00Z","timestamp":1757548800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-06170-6_5","type":"book-chapter","created":{"date-parts":[[2025,9,10]],"date-time":"2025-09-10T20:57:11Z","timestamp":1757537831000},"page":"55-72","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["DMoE: A Semantic-Aware Engine with\u00a0Mixture of\u00a0Experts for\u00a0Detecting Zero-Day Malware"],"prefix":"10.1007","author":[{"given":"Chenming","family":"Yang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kejiang","family":"Ye","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,9,11]]},"reference":[{"issue":"17","key":"5_CR1","doi-asserted-by":"publisher","first-page":"8482","DOI":"10.3390\/app12178482","volume":"12","author":"FA Aboaoja","year":"2022","unstructured":"Aboaoja, F.A., Zainal, A., Ghaleb, F.A., Al-Rimy, B.A.S., Eisa, T.A.E., Elnour, A.A.H.: Malware detection issues, challenges, and future directions: a survey. Appl. Sci. 12(17), 8482 (2022)","journal-title":"Appl. Sci."},{"key":"5_CR2","doi-asserted-by":"crossref","unstructured":"Al-Dujaili, A., Huang, A., Hemberg, E., O\u2019Reilly, U.M.: Adversarial deep learning for robust detection of binary encoded malware. In: 2018 IEEE Security and Privacy Workshops (SPW), pp. 76\u201382. IEEE (2018)","DOI":"10.1109\/SPW.2018.00020"},{"issue":"3","key":"5_CR3","doi-asserted-by":"publisher","first-page":"143","DOI":"10.3390\/bdcc7030143","volume":"7","author":"A Alraizza","year":"2023","unstructured":"Alraizza, A., Algarni, A.: Ransomware detection using machine learning: a survey. Big Data Cogn. Comput. 7(3), 143 (2023)","journal-title":"Big Data Cogn. Comput."},{"key":"5_CR4","unstructured":"Alvarez, V.M.: Yara \u2013 the pattern matching swiss knife for malware researchers. https:\/\/virustotal.github.io\/yara\/ (2020)"},{"issue":"11","key":"5_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3664649","volume":"56","author":"T Bilot","year":"2024","unstructured":"Bilot, T., El Madhoun, N., Al Agha, K., Zouaoui, A.: A survey on malware detection with graph representation learning. ACM Comput. Surv. 56(11), 1\u201336 (2024)","journal-title":"ACM Comput. Surv."},{"issue":"5","key":"5_CR6","first-page":"4754","volume":"35","author":"Y Chai","year":"2022","unstructured":"Chai, Y., Du, L., Qiu, J., Yin, L., Tian, Z.: Dynamic prototype network based on sample adaptation for few-shot malware detection. IEEE Trans. Knowl. Data Eng. 35(5), 4754\u20134766 (2022)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"5_CR7","doi-asserted-by":"publisher","first-page":"788","DOI":"10.1109\/TIFS.2022.3152360","volume":"17","author":"X Chen","year":"2022","unstructured":"Chen, X., et al.: CruParamer: learning on parameter-augmented API sequences for malware detection. IEEE Trans. Inf. Forensics Secur. 17, 788\u2013803 (2022)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"5_CR8","unstructured":"Clark, A., et\u00a0al.: Unified scaling laws for routed language models. In: International Conference on Machine Learning, pp. 4057\u20134086. PMLR (2022)"},{"key":"5_CR9","doi-asserted-by":"crossref","unstructured":"Cui, L., Cui, J., Ji, Y., Hao, Z., Li, L., Ding, Z.: API2Vec: learning representations of API sequences for malware detection. In: Proceedings of the 32nd ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 261\u2013273 (2023)","DOI":"10.1145\/3597926.3598054"},{"key":"5_CR10","doi-asserted-by":"crossref","unstructured":"Dai, D., et al.: DeepSeekMoE: Towards ultimate expert specialization in mixture-of-experts language models. arXiv preprint arXiv:2401.06066 (2024)","DOI":"10.18653\/v1\/2024.acl-long.70"},{"key":"5_CR11","unstructured":"DeepSeek-AI: DeepSeek-V2: A strong, economical, and efficient mixture-of-experts language model (2024)"},{"issue":"2","key":"5_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3605775","volume":"56","author":"F Deldar","year":"2023","unstructured":"Deldar, F., Abadi, M.: Deep learning for zero-day malware detection and classification: a survey. ACM Comput. Surv. 56(2), 1\u201337 (2023)","journal-title":"ACM Comput. Surv."},{"key":"5_CR13","volume":"55","author":"X Gao","year":"2020","unstructured":"Gao, X., Hu, C., Shan, C., Liu, B., Niu, Z., Xie, H.: Malware classification for the cloud via semi-supervised transfer learning. J. Inf. Secur. Appl. 55, 102661 (2020)","journal-title":"J. Inf. Secur. Appl."},{"key":"5_CR14","doi-asserted-by":"crossref","unstructured":"Hansen, S.S., Larsen, T.M.T., Stevanovic, M., Pedersen, J.M.: An approach for detection and family classification of malware based on behavioral analysis. In: 2016 International Conference on Computing, Networking and Communications (ICNC), pp.\u00a01\u20135. IEEE (2016)","DOI":"10.1109\/ICCNC.2016.7440587"},{"key":"5_CR15","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"issue":"3","key":"5_CR16","doi-asserted-by":"publisher","first-page":"3900","DOI":"10.1109\/TNSM.2023.3251282","volume":"20","author":"C Kim","year":"2023","unstructured":"Kim, C., Chang, S.Y., Kim, J., Lee, D., Kim, J.: Automated, reliable zero-day malware detection based on autoencoding architecture. IEEE Trans. Netw. Serv. Manage. 20(3), 3900\u20133914 (2023)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"5_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102872","volume":"122","author":"C Li","year":"2022","unstructured":"Li, C., et al.: DMalNet: dynamic malware analysis based on API feature engineering and graph learning. Comput. Secur. 122, 102872 (2022)","journal-title":"Comput. Secur."},{"key":"5_CR18","unstructured":"Liu, C., Li, B., Zhao, J., Zhen, Z., Liu, X., Zhang, Q.: FewM-HGCL: few-shot malware variants detection via heterogeneous graph contrastive learning. IEEE Transactions on Dependable and Secure Computing (2022)"},{"key":"5_CR19","unstructured":"Liu, Y., et al.: RoBERTa: a robustly optimized BERT pretraining approach. In: International Conference on Learning Representations (2020)"},{"key":"5_CR20","unstructured":"Lucas, K., Pai, S., Lin, W., Bauer, L., Reiter, M.K., Sharif, M.: Adversarial training for $$\\{$$Raw-Binary$$\\}$$ malware classifiers. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 1163\u20131180 (2023)"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Muennighoff, N., Tazi, N., Magne, L., Reimers, N.: MTEB: massive text embedding benchmark. In: Proceedings of the 17th Conference of the European Chapter of the Association for Computational Linguistics, pp. 2014\u20132037 (2023)","DOI":"10.18653\/v1\/2023.eacl-main.148"},{"key":"5_CR22","doi-asserted-by":"crossref","unstructured":"Raff, E., Fleshman, W., Zak, R., Anderson, H.S., Filar, B., McLean, M.: Classifying sequences of extreme length with constant memory applied to malware detection. In: Proceedings of the AAAI Conference on Artificial Intelligence. vol.\u00a035, pp. 9386\u20139394 (2021)","DOI":"10.1609\/aaai.v35i11.17131"},{"key":"5_CR23","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103735","volume":"139","author":"S Rohini","year":"2024","unstructured":"Rohini, S., Ramesh, G., Nair, A.R.: MAGIC: malware behaviour analysis and impact quantification through signature co-occurrence and regression. Comput. Secur. 139, 103735 (2024)","journal-title":"Comput. Secur."},{"key":"5_CR24","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"336","DOI":"10.1007\/978-3-540-70500-0_25","volume-title":"Information Security and Privacy","author":"VS Sathyanarayan","year":"2008","unstructured":"Sathyanarayan, V.S., Kohli, P., Bruhadeshwar, B.: Signature generation and detection of malware families. In: Mu, Y., Susilo, W., Seberry, J. (eds.) ACISP 2008. LNCS, vol. 5107, pp. 336\u2013349. Springer, Heidelberg (2008). https:\/\/doi.org\/10.1007\/978-3-540-70500-0_25"},{"key":"5_CR25","unstructured":"Scott, J.: Signature based malware detection is dead. Institute for Critical Infrastructure Technology (2017)"},{"key":"5_CR26","doi-asserted-by":"crossref","unstructured":"Shalaginov, A., Banin, S., Dehghantanha, A., Franke, K.: Machine learning aided static malware analysis: A survey and tutorial. Cyber threat intelligence, pp. 7\u201345 (2018)","DOI":"10.1007\/978-3-319-73951-9_2"},{"key":"5_CR27","unstructured":"Shazeer, N., et al.: Outrageously large neural networks: The sparsely-gated mixture-of-experts layer. arXiv preprint arXiv:1701.06538 (2017)"},{"key":"5_CR28","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2023.127063","volume":"568","author":"J Su","year":"2024","unstructured":"Su, J., Ahmed, M., Lu, Y., Pan, S., Bo, W., Liu, Y.: RoFormer: enhanced transformer with rotary position embedding. Neurocomputing 568, 127063 (2024)","journal-title":"Neurocomputing"},{"key":"5_CR29","doi-asserted-by":"crossref","unstructured":"Suciu, O., Coull, S.E., Johns, J.: Exploring adversarial examples in malware detection. In: 2019 IEEE Security and Privacy Workshops (SPW), pp. 8\u201314. IEEE (2019)","DOI":"10.1109\/SPW.2019.00015"},{"key":"5_CR30","unstructured":"Tong, L., Li, B., Hajaj, C., Xiao, C., Zhang, N., Vorobeychik, Y.: Improving robustness of $$\\{$$ML$$\\}$$ classifiers against realizable evasion attacks using conserved features. In: 28th USENIX Security Symposium (USENIX Security 19), pp. 285\u2013302 (2019)"},{"key":"5_CR31","doi-asserted-by":"publisher","first-page":"212","DOI":"10.1016\/j.cose.2017.09.001","volume":"72","author":"W Tounsi","year":"2018","unstructured":"Tounsi, W., Rais, H.: A survey on technical threat intelligence in the age of sophisticated cyber attacks. Comput. Secur. 72, 212\u2013233 (2018)","journal-title":"Comput. Secur."},{"key":"5_CR32","unstructured":"Veli\u010dkovi\u0107, P., Cucurull, G., Casanova, A., Romero, A., Lio, P., Bengio, Y.: Graph attention networks. arXiv preprint arXiv:1710.10903 (2017)"},{"key":"5_CR33","unstructured":"Yang, A., et\u00a0al.: Qwen2 technical report. arXiv preprint arXiv:2407.10671 (2024)"},{"issue":"3","key":"5_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3073559","volume":"50","author":"Y Ye","year":"2017","unstructured":"Ye, Y., Li, T., Adjeroh, D., Iyengar, S.S.: A survey on malware detection using data mining techniques. ACM Comput. Surv. (CSUR) 50(3), 1\u201340 (2017)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"5_CR35","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Qi, P., Wang, W.: Dynamic malware analysis with feature engineering and feature learning. In: Proceedings of the AAAI Conference on Artificial Intelligence. vol.\u00a034, pp. 1210\u20131217 (2020)","DOI":"10.1609\/aaai.v34i01.5474"}],"container-title":["Lecture Notes in Computer Science","Internet of Things \u2013 ICIOT 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-06170-6_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T00:30:09Z","timestamp":1779323409000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-06170-6_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,11]]},"ISBN":["9783032061690","9783032061706"],"references-count":35,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-06170-6_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,11]]},"assertion":[{"value":"11 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICIOT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Internet of Things","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hong Kong","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hong Kong","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iciot2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.servicessociety.org\/iciot","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}