{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T23:13:12Z","timestamp":1778109192530,"version":"3.51.4"},"publisher-location":"Cham","reference-count":31,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032160911","type":"print"},{"value":"9783032160928","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-16092-8_13","type":"book-chapter","created":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T22:40:43Z","timestamp":1778107243000},"page":"233-253","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["One Size Doesn\u2019t Fit All: A Dynamic Heterogeneous Learning Ensemble for\u00a0Malware Family Classification"],"prefix":"10.1007","author":[{"given":"Solomon Yekini","family":"Sonya","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muqi","family":"Zou","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Saastha","family":"Vasan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Christopher","family":"Kruegel","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giovanni","family":"Vigna","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dongyan","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,1]]},"reference":[{"key":"13_CR1","doi-asserted-by":"crossref","unstructured":"Anahideh, H., Nezami, N., Asudeh, A.: Finding representative group fairness metrics using correlation estimations. In: Expert Systems with Applications (2025), https:\/\/openreview.net\/forum?id=DEX3gP6RWm","DOI":"10.1016\/j.eswa.2024.125652"},{"key":"13_CR2","unstructured":"Anderson, H.S., Roth, P.: Ember: An open dataset for training static pe malware machine learning models. arXiv preprint arXiv:1804.04637 (2018)"},{"key":"13_CR3","unstructured":"ANY.RUN: Malware signatures explained: How security tools spot threats (2024), https:\/\/any.run\/cybersecurity-blog\/malware-signatures-explained\/, accessed: 2025-06-03"},{"key":"13_CR4","unstructured":"AV-TEST: Malware statistics. https:\/\/www.av-test.org\/en\/statistics\/malware\/, accessed: Mar. 13, 2025"},{"key":"13_CR5","doi-asserted-by":"crossref","unstructured":"Barbieri, M.M., Berger, J.O.: Optimal predictive model selection. The Annals of Statistics 32(3), 870\u2013897 (2004), https:\/\/arxiv.org\/pdf\/math\/0406464.pdf","DOI":"10.1214\/009053604000000238"},{"key":"13_CR6","doi-asserted-by":"publisher","unstructured":"Brezinski, K., Ferens, K.: Metamorphic malware and obfuscation: A survey of techniques, variants, and generation kits. Security and Communication Networks 2023 (2023). https:\/\/doi.org\/10.1155\/2023\/8227751, https:\/\/doi.org\/10.1155\/2023\/8227751","DOI":"10.1155\/2023\/8227751"},{"key":"13_CR7","doi-asserted-by":"publisher","unstructured":"Carlin, D., O\u2019Kane, P., Sezer, S.: A cost analysis of machine learning using dynamic runtime opcodes for malware detection 85, 138\u2013155.https:\/\/doi.org\/10.1016\/j.cose.2019.04.018","DOI":"10.1016\/j.cose.2019.04.018"},{"key":"13_CR8","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1016\/j.cose.2014.05.001","volume":"47","author":"L Cheng","year":"2014","unstructured":"Cheng, L., Zhang, Y., Han, Z., Deng, Y., Sun, X., Feng, D.: Evaluating and comparing the quality of access control in different operating systems. Computers & Security 47, 26\u201340 (2014)","journal-title":"Computers & Security"},{"key":"13_CR9","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2019.102526","volume":"153","author":"D Gibert","year":"2020","unstructured":"Gibert, D., Mateu, C., Planes, J.: The rise of machine learning for detection and classification of malware: Research developments, trends and challenges. J. Netw. Comput. Appl. 153, 102526 (2020)","journal-title":"J. Netw. Comput. Appl."},{"key":"13_CR10","unstructured":"Hsiao, S.W., Sun, Y.S., Chen, M.C.: Virtual machine introspection based malware behavior profiling and family grouping. arXiv preprint arXiv:1705.01697 (2017), https:\/\/arxiv.org\/abs\/1705.01697"},{"key":"13_CR11","doi-asserted-by":"crossref","unstructured":"Joyce, R.J., Miller, G., Roth, P., Zak, R., Zaresky-Williams, E., Anderson, H., Raff, E., Holt, J.: Ember2024 - a benchmark dataset for holistic evaluation of malware classifiers. In: Proceedings of the 31st ACM SIGKDD Conference on Knowledge Discovery and Data Mining (2025)","DOI":"10.1145\/3711896.3737431"},{"key":"13_CR12","doi-asserted-by":"crossref","unstructured":"Ko, A.H., Sabourin, R., Britto\u00a0Jr, A.d.S.: Dynamic classifier selection: Recent advances and perspectives. Pattern Recognition 41(12), 3460\u20133475 (2008)","DOI":"10.1016\/j.patcog.2007.10.015"},{"key":"13_CR13","doi-asserted-by":"publisher","DOI":"10.1002\/0471660264","volume-title":"Combining Pattern Classifiers: Methods and Algorithms","author":"LI Kuncheva","year":"2004","unstructured":"Kuncheva, L.I.: Combining Pattern Classifiers: Methods and Algorithms. Wiley, Hoboken, NJ (2004)"},{"key":"13_CR14","doi-asserted-by":"crossref","unstructured":"Li, B., Roundy, K., Gates, C., Vorobeychik, Y.: Large-scale identification of malicious singleton files. In: Proceedings of 7th ACM Conference on Data and Application Security and Privacy (2017)","DOI":"10.1145\/3029806.3029815"},{"key":"13_CR15","unstructured":"MalwareBazaar: Malwarebazaar: A repository for sharing malware samples (2025), https:\/\/bazaar.abuse.ch"},{"key":"13_CR16","doi-asserted-by":"crossref","unstructured":"Maniriho, P., Mahmood, A.N., Chowdhury, M.J.M.: A systematic literature review on windows malware detection: Techniques, research issues, and future directions. Journal of Systems and Software 192 (2024)","DOI":"10.1016\/j.jss.2023.111921"},{"key":"13_CR17","doi-asserted-by":"publisher","unstructured":"Maniriho, P., Mahmood, A.N., Chowdhury, M.J.M.: A systematic literature review on windows malware detection: Techniques, research issues, and future directions. Journal of Systems and Software 209, 111921 (March 2024https:\/\/doi.org\/10.1016\/j.jss.2023.111921","DOI":"10.1016\/j.jss.2023.111921"},{"key":"13_CR18","doi-asserted-by":"publisher","unstructured":"Nelson, T., O\u2019Brien, A., Noteboom, C.: Machine learning applications in malware classification: A meta-analysis literature review. International Journal on Cybernetics and Informatics (IJCI) 12(1) (Feb 2023).https:\/\/doi.org\/10.5121\/ijci.2023.120109","DOI":"10.5121\/ijci.2023.120109"},{"key":"13_CR19","unstructured":"NSF Action AI Institute: Mabel: [m]alware [a]nalysis [be]nchmark for artificial intelligence and machine [l]earning; malware dataset family - ready for modeling (2024), https:\/\/github.com\/action-ai-institute\/MABEL-dataset\/tree\/main\/release\/malware_family\/ready_for_modeling"},{"key":"13_CR20","volume-title":"Python Machine Learning","author":"S Raschka","year":"2015","unstructured":"Raschka, S.: Python Machine Learning. Packt Publishing, Birmingham, UK (2015)"},{"key":"13_CR21","unstructured":"Sasa Software: Payload obfuscation: How attackers hide malware in plain sight (2024), https:\/\/www.sasa-software.com\/learning\/payload-obfuscation-how-attackers-hide-malware\/, accessed: 2025-06-16"},{"key":"13_CR22","unstructured":"Scarfone, K., Mell, P.: Guide to malware incident prevention and handling for desktops and laptops. Tech. Rep. NIST SP 800-83 Revision 1, National Institute of Standards and Technology (2013), https:\/\/nvlpubs.nist.gov\/nistpubs\/specialpublications\/nist.sp.800-83r1.pdf, definition of malware on p. 2"},{"key":"13_CR23","unstructured":"SentinelOne: What is a malware file signature and how does it work? (2024), https:\/\/www.sentinelone.com\/blog\/what-is-a-malware-file-signature-and-how-does-it-work\/, accessed: 2025-06-03"},{"key":"13_CR24","unstructured":"Sun, M., Li, X., Lui, J.C.S., Ma, R.T.B., Liang, Z.: Monet: A user-oriented behavior-based malware variants detection system for android. IEEE Trans. Inf. Forensics Secur. 11(11), 2278\u20132290 (2016)"},{"key":"13_CR25","doi-asserted-by":"crossref","unstructured":"Tahir, R.: A study on malware and malware detection techniques. International Journal of Education and Management Engineering (IJEME) 8(2), 20\u201330 (2018)","DOI":"10.5815\/ijeme.2018.02.03"},{"key":"13_CR26","unstructured":"VirusShare: Virusshare: A repository of malware samples for researchers (2025), https:\/\/virusshare.com"},{"key":"13_CR27","unstructured":"VirusTotal: 2023 emerging threats report. https:\/\/assets.virustotal.com\/reports\/2023emerging.pdf"},{"key":"13_CR28","unstructured":"VirusTotal: How it works. https:\/\/docs.virustotal.com\/docs\/how-it-works (2024), accessed: Mar. 12, 2025"},{"key":"13_CR29","unstructured":"VX-Underground: Vx-underground: The largest collection of malware source code, samples, and papers (2025), https:\/\/vx-underground.org"},{"key":"13_CR30","doi-asserted-by":"crossref","unstructured":"Yang, L., Ciptadi, A., Laziuk, I., Ahmadzadeh, A., Wang, G.: Bodmas: An open dataset for learning-based temporal analysis of pe malware. https:\/\/liminyang.web.illinois.edu\/data\/DLS21_BODMAS.pdf (2021)","DOI":"10.1109\/SPW53761.2021.00020"},{"key":"13_CR31","unstructured":"Zealots, T.: Pe (portable executable) structure \u2013 malware analysis part 2 (2023), https:\/\/tech-zealots.com\/malware-analysis\/pe-portable-executable-structure-malware-analysis-part-2\/, accessed: 2025-06-03"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2025 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-16092-8_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T22:40:49Z","timestamp":1778107249000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-16092-8_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032160911","9783032160928"],"references-count":31,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-16092-8_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of the Air Force, the Department of Defense or the U.S. Government.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toulouse","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.esorics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}