{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T11:05:45Z","timestamp":1779793545040,"version":"3.53.1"},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,4,1]],"date-time":"2026-04-01T00:00:00Z","timestamp":1775001600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["61862022"],"award-info":[{"award-number":["61862022"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["62172182"],"award-info":[{"award-number":["62172182"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003453","name":"Guangdong Provincial Natural Science Foundation","doi-asserted-by":"crossref","award":["2023A1515011084"],"award-info":[{"award-number":["2023A1515011084"]}],"id":[{"id":"10.13039\/501100003453","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Guangdong Provincial Key Research Project for General Universities","award":["2022ZDZX1011"],"award-info":[{"award-number":["2022ZDZX1011"]}]},{"name":"Zhejiang Provincial Key Laboratory of Information Security","award":["KF202306"],"award-info":[{"award-number":["KF202306"]}]},{"name":"Doctoral Program Construction Project of Guangdong Polytechnic Normal University","award":["22GPNUZDJS27"],"award-info":[{"award-number":["22GPNUZDJS27"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Appl Intell"],"published-print":{"date-parts":[[2026,4]]},"DOI":"10.1007\/s10489-026-07229-7","type":"journal-article","created":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T09:15:10Z","timestamp":1775812510000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Ensemble multi-stream threshold network for malware open-set recognition"],"prefix":"10.1007","volume":"56","author":[{"given":"Zhanyu","family":"Chi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuanquan","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qingzhong","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,4,10]]},"reference":[{"issue":"1","key":"7229_CR1","doi-asserted-by":"publisher","first-page":"467","DOI":"10.1109\/COMST.2022.3225137","volume":"25","author":"Y Senming","year":"2023","unstructured":"Senming Y, Jing R, Wei W, Limin S, Wei Z, Quan Y et al (2023) A survey of adversarial attack and defense methods for malware classification in cyber security. IEEE Commun Surv Tutor 25(1):467\u2013496","journal-title":"IEEE Commun Surv Tutor"},{"key":"7229_CR2","unstructured":"Deqiang L, Qianmu L, Yanfang Y, Shouhuai X et al (2023) Arms race in adversarial malware detection: A survey. ACM Comput Surv, 55, 1"},{"issue":"4","key":"7229_CR3","doi-asserted-by":"publisher","first-page":"1320","DOI":"10.28991\/ESJ-2024-08-04-06","volume":"8","author":"H Constantinos","year":"2024","unstructured":"Constantinos H, Anastasios P, Yannis CS, Leonidas T, Vasileios V et al (2024) A Digital Service for Citizens: Multi-Parameter Optimization Model for Cost-Benefit Analysis of Cybercrime and Cyberdefense[J]. Emerg Sci J 8(4):1320\u20131344","journal-title":"Emerg Sci J"},{"issue":"3","key":"7229_CR4","doi-asserted-by":"publisher","first-page":"534","DOI":"10.28991\/HIJ-2024-05-03-01","volume":"5","author":"A Malak","year":"2024","unstructured":"Malak A, Afrah S, Fatima A, Asalah S, Dorieh A, Menna A, Walla A, Areej A et al (2024) IoT Attacks Detection Using Supervised Machine Learning Techniques. HighTech and Innovation Journal 5(3):534\u2013550","journal-title":"HighTech and Innovation Journal"},{"key":"7229_CR5","doi-asserted-by":"crossref","unstructured":"Zhou T, Wang W, Liang Z, Shen J (2021) Face forensics in the wild, in Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR), Jun. pp. 5774\u20135784","DOI":"10.1109\/CVPR46437.2021.00572"},{"key":"7229_CR6","unstructured":"Kaspersky Lab The cyber surge: Kaspersky detected 467,000 malicious files daily in 2024, Press release, Dec. 4, 2024. [Online]. Available: https:\/\/www.kaspersky.com\/about\/press-releases\/the-cyber-surge-kaspersky-detected-467000-malicious-files-daily-in-2024"},{"key":"7229_CR7","unstructured":"ANY.RUN Malware trends overview report: 2024, Jan. 16, 2025. [Online]. Available: https:\/\/any.run\/cybersecurity-blog\/malware-trends-overview-report-2024"},{"issue":"7","key":"7229_CR8","doi-asserted-by":"publisher","first-page":"1757","DOI":"10.1109\/TPAMI.2012.256","volume":"35","author":"WJ Scheirer","year":"2013","unstructured":"Scheirer WJ, de Rezende Rocha A, Sapkota A, Boult TE (2013) Toward open set recognition. IEEE Transactions on Pattern Analysis and Machine Intelligence 35(7):1757\u20131772","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"7229_CR9","doi-asserted-by":"crossref","unstructured":"Liu Z, Miao Z, Zhan X, Wang J, Gong B, Yu SX (2019) Large-scale long-tailed recognition in an open world, in Proc. IEEE\/CVF Conf. Comput. Vis. Pattern Recognit. (CVPR), Jun. pp. 2537\u20132546","DOI":"10.1109\/CVPR.2019.00264"},{"key":"7229_CR10","doi-asserted-by":"publisher","first-page":"524","DOI":"10.1109\/TMM.2020.2984091","volume":"23","author":"J Guo","year":"2021","unstructured":"Guo J, Guo S (2021) A novel perspective to zero-shot learning: towards an alignment of manifold structures via semantic feature expansion. IEEE Trans Multimedia 23:524\u2013537","journal-title":"IEEE Trans Multimedia"},{"key":"7229_CR11","doi-asserted-by":"crossref","unstructured":"Guo J, Guo S, Zhou Q, Liu Z, Lu X, Huo F (2023) Graph knows unknowns: Reformulate zero-shot learning as sample-level graph recognition, in Proc. AAAI Conf. Artif. Intell., vol. 37, no. 6, pp. 7775\u20137783","DOI":"10.1609\/aaai.v37i6.25942"},{"key":"7229_CR12","doi-asserted-by":"publisher","first-page":"871","DOI":"10.1016\/j.cose.2018.04.005","volume":"77","author":"S Ni","year":"2018","unstructured":"Ni S, Qian Q, Zhang R (2018) Malware identification using visualization images and deep learning. Comput. Secur. 77:871\u2013885","journal-title":"Comput. Secur."},{"key":"7229_CR13","doi-asserted-by":"crossref","unstructured":"Cordonsky I, Rosenberg I, Sicard G, David EO (2018) DeepOrigin: End-to-end deep learning for detection of new malware families, in Proc. Int. Joint Conf. Neural Netw. (IJCNN), Jul. pp. 1\u20137","DOI":"10.1109\/IJCNN.2018.8489667"},{"key":"7229_CR14","unstructured":"Anderson HS, Roth P (2018) EMBER: An open dataset for training static PE malware machine learning models. arXiv preprint arXiv:1804.04637"},{"key":"7229_CR15","unstructured":"VirusTotal APIdocumentation (2023) [Online]. Available: https:\/\/docs.virustotal.com"},{"key":"7229_CR16","unstructured":"Grootendorst M (2022) BERTopic: Neural topic modeling with a class-based TF-IDF procedure, arXiv preprint arXiv:2203.05794"},{"key":"7229_CR17","doi-asserted-by":"crossref","unstructured":"Kenter T, Borisov A, De Rijke M Sia-mese cbow: Optimizing word embeddings for sentence representations. arXiv preprint arXiv:1606.04640, 2016.","DOI":"10.18653\/v1\/P16-1089"},{"key":"7229_CR18","unstructured":"Sandbox, Qianxin [Online]. Available: https:\/\/sandbox.qianxin.com\/sscc-tq-web\/"},{"issue":"1","key":"7229_CR19","doi-asserted-by":"publisher","first-page":"617","DOI":"10.1109\/TCYB.2022.3164625","volume":"53","author":"Q Junyang","year":"2023","unstructured":"Junyang Q, Qing-Long H-L, Wei L, Lei P, Surya N, Jun Z, Yang X et al (2023) Cyber code intelligence for android malware detection. IEEE Trans Cybern 53(1):617\u2013627","journal-title":"IEEE Trans Cybern"},{"key":"7229_CR20","unstructured":"Muhammad IY, Izza A, Ayesha R, Khawaja TZ, Suhyun K et al (2023) Windows malware detection based on static analysis with multiple features. PeerJ Comput Sci, 9"},{"issue":"1","key":"7229_CR21","doi-asserted-by":"publisher","first-page":"673","DOI":"10.1007\/s40747-021-00560-1","volume":"8","author":"SKJ Rizvi","year":"2021","unstructured":"Rizvi SKJ, Aslam W, Shahzad M, Saleem S, Fraz MM (2021) PROUD-MAL: Static analysis-based progressive framework for deep unsupervised malware classification of windows portable executable. Complex & Intelligent Systems 8(1):673\u2013685","journal-title":"Complex & Intelligent Systems"},{"key":"7229_CR22","doi-asserted-by":"publisher","first-page":"108266","DOI":"10.1016\/j.knosys.2022.108266","volume":"241","author":"I Finder","year":"2022","unstructured":"Finder I, Sheetrit E, Nissim N (2022) Time-interval temporal patterns can beat and explain the malware. Knowl-Based Syst 241:108266","journal-title":"Knowl-Based Syst"},{"key":"7229_CR23","doi-asserted-by":"crossref","unstructured":"Deqiang L, Shicheng C, Yun L, Jia X, Fu X, Shouhuai X et al (2024) PAD: Towards principled adversarial malware detection against evasion attacks, IEEE Trans. Dependable Secure Comput., vol. 21, no. 2, pp. 920\u2013936","DOI":"10.1109\/TDSC.2023.3265665"},{"key":"7229_CR24","doi-asserted-by":"publisher","first-page":"118590","DOI":"10.1016\/j.eswa.2022.118590","volume":"212","author":"C Fabricio","year":"2023","unstructured":"Fabricio C, Marcus B, Heitor MG, Felipe P, Luiz SO, Andre G et al (2023) Fast & furious: On the modelling of malware detection as an evolving data stream. Expert Syst Appl 212:118590","journal-title":"Expert Syst Appl"},{"issue":"7","key":"7229_CR25","doi-asserted-by":"publisher","first-page":"4830","DOI":"10.1109\/TII.2021.3119778","volume":"18","author":"J Jueun","year":"2022","unstructured":"Jueun J, Byeonghui J, Seungyeon B, Young-Sik J et al (2022) Hybrid malware detection based on bi-LSTM and SPP-Net for smart IoT. IEEE Trans Ind Informat 18(7):4830\u20134837","journal-title":"IEEE Trans Ind Informat"},{"issue":"1","key":"7229_CR26","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1109\/TR.2019.2924677","volume":"69","author":"Z Weizhe","year":"2020","unstructured":"Weizhe Z, Huanran W, Hui H, Peng L et al (2020) DAMBA: Detecting Android malware by ORGB analysis. IEEE Trans Reliab 69(1):55\u201369","journal-title":"IEEE Trans Reliab"},{"key":"7229_CR27","doi-asserted-by":"publisher","first-page":"2782","DOI":"10.1109\/TIFS.2020.2976556","volume":"15","author":"A Mohannad","year":"2020","unstructured":"Mohannad A, Qiben Y, Hamid B, Hao Z, Yutaka T, Wit-awas S, Xiapu L et al (2020) DINA: Detecting hidden android inter-app communication in dynamic loaded code. IEEE Trans Inf Forensics Secur 15:2782\u20132797","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"7229_CR28","doi-asserted-by":"crossref","unstructured":"Geli F, Bing L (2016) Breaking the closed world assumption in text classification, in Proc. North Am. Chapter Assoc. Comput. Linguist., pp. 506\u2013514","DOI":"10.18653\/v1\/N16-1061"},{"issue":"8","key":"7229_CR29","doi-asserted-by":"publisher","first-page":"1690","DOI":"10.1109\/TPAMI.2016.2613924","volume":"39","author":"H Zhang","year":"2017","unstructured":"Zhang H, Patel VM (2017) Sparse representation-based open set recognition. IEEE Trans Pattern Anal Mach Intell 39(8):1690\u20131696","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"issue":"12","key":"7229_CR30","doi-asserted-by":"publisher","first-page":"7706","DOI":"10.1109\/TNNLS.2021.3087104","volume":"33","author":"J Leo","year":"2021","unstructured":"Leo J, Kalita J (2021) Incremental deep neural network learning using classification confidence thresholding. IEEE Trans. Neural Netw. Learn. Syst. 33(12):7706\u20137716","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"7229_CR31","doi-asserted-by":"crossref","unstructured":"Jia J, Chan PK (2022) Representation learning with function call graph transformations for malware open set recognition, in Proc. IEEE World Congr. Comput. Intell., pp. 1\u20138","DOI":"10.1109\/IJCNN55064.2022.9892931"},{"key":"7229_CR32","doi-asserted-by":"crossref","unstructured":"Huaifeng B, Wen W, Feng L (2023) Towards open-set APT malware classification under few-shot setting, in Proc. Global Commun. Conf., pp. 6844\u20136849","DOI":"10.1109\/GLOBECOM54140.2023.10437265"},{"key":"7229_CR33","doi-asserted-by":"crossref","unstructured":"Limin Y, Arridhana C, Ihar L, Ali A, Gang W et al (2021) BODMAS: An open dataset for learning based temporal analysis of PE malware, in Proc. IEEE Symp. Secur. Priv., pp. 78\u201384","DOI":"10.1109\/SPW53761.2021.00020"},{"key":"7229_CR34","unstructured":"https:\/\/practicalsecurityanalytics.com\/pe-malware-machine-learning-dataset\/?utm_source=chatgpt.com"},{"key":"7229_CR35","doi-asserted-by":"publisher","first-page":"111830","DOI":"10.1109\/ACCESS.2022.3215267","volume":"10","author":"G Yun","year":"2022","unstructured":"Yun G, Hirokazu H, Yukiko Y, Hajime S et al (2022) Malware detection by control-flow graph level representation learning with graph isomorphism network. IEEE Access 10:111830\u2013111841","journal-title":"IEEE Access"},{"key":"7229_CR36","unstructured":"Hermans A, Beyer L, Leibe B (2017) In defense of the triplet loss for person re-identification. arXiv preprint arXiv:1703.07737"},{"key":"7229_CR37","unstructured":"Xin M, Wenting W, Yuanbin W, Man L et al (2021) Boosting the speed of entity alignment 10\u00d7: Dual attention matching network with normalized hard sample mining, in Proc. The Web Conf., arXiv:2103.15452"},{"key":"7229_CR38","doi-asserted-by":"crossref","unstructured":"Vijaya BS, Nellore MTMK, Neha S et al (2022) K. L. S,., Statistical analysis of big data models in android malware detection, in Proc. 2022 Int. Conf. Edge Comput. Appl. (ICECAA), pp. 185\u2013189","DOI":"10.1109\/ICECAA55415.2022.9936326"},{"key":"7229_CR39","first-page":"3","volume":"11999","author":"Z Lixin","year":"2019","unstructured":"Lixin Z, Lijun C, Aimin Y, Zhen X, Dan M et al (2019) Prototype-based malware traffic classification withnovelty detection. Lecture Notes Comput Sci 11999:3\u201317","journal-title":"Lecture Notes Comput Sci"},{"key":"7229_CR40","doi-asserted-by":"crossref","unstructured":"Schroff F, Kalenichenko D, Philbin J (2015) FaceNet: A unified embedding for face recognition and clustering, in Proc. IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR), pp. 815\u2013823","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"7229_CR41","doi-asserted-by":"publisher","first-page":"4881","DOI":"10.1109\/TIFS.2024.3389614","volume":"19","author":"P Hao","year":"2024","unstructured":"Hao P, Jieshuai Y, Dandan Z, Xiaogang X, Yuwen P, Jianmin H, Xing Y, Ming Z, Shouling J et al (2024) MalGNE: Enhancing the performance and efficiency of CFG-based malware detector by graph node embedding in low dimension space. IEEE Trans Inf Forensics Secur 19:4881\u20134896","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"7229_CR42","doi-asserted-by":"crossref","unstructured":"Qinqin W, Hanbing Y, Chang Z, Rui M, Zhihui H, Yu Z et al (2022) Measurement of malware family classification on a large-scale real-world dataset, in Proc. Int. Conf. Trust, Secur. Priv. Comput. Commun., pp. 1390\u20131397","DOI":"10.1109\/TrustCom56396.2022.00196"},{"key":"7229_CR43","doi-asserted-by":"publisher","first-page":"95970","DOI":"10.1109\/ACCESS.2022.3202952","volume":"10","author":"L Qikai","year":"2022","unstructured":"Qikai L, Hongwen Z, Husam K, Di N et al (2022) Self-attentive models for real-time malware classification. IEEE Access 10:95970\u201395985","journal-title":"IEEE Access"},{"key":"7229_CR44","doi-asserted-by":"crossref","unstructured":"Jia Y, Xiangkun J, Lingyun Y, Puru S et al (2022) Understanding and Mitigating Label Bias in Malware Classification: an Empirical Study[C], International Conference on Software Quality, Reliability and Security, : 492\u2013503","DOI":"10.1109\/QRS57517.2022.00057"},{"issue":"1","key":"7229_CR45","doi-asserted-by":"publisher","first-page":"309","DOI":"10.1109\/TR.2020.3020954","volume":"71","author":"Y Zhang","year":"2020","unstructured":"Zhang Y, Liu Z, Jiang Y (2020) The classification and detection of malware using soft relevance evaluation. IEEE Trans Reliab 71(1):309\u2013320","journal-title":"IEEE Trans Reliab"},{"key":"7229_CR46","doi-asserted-by":"crossref","unstructured":"Burnaev E, Smolyakov D (2016) One-class SVM with privileged information and its application to malware detection, in Proc. IEEE 16th Int. Conf. Data Mining Workshops (ICDMW), Dec. pp. 273\u2013280","DOI":"10.1109\/ICDMW.2016.0046"},{"issue":"2","key":"7229_CR47","doi-asserted-by":"publisher","first-page":"2327","DOI":"10.1109\/TNNLS.2022.3189996","volume":"35","author":"J Jang","year":"2024","unstructured":"Jang J, Kim CO (2024) Collective decision of one-vs-rest networks for open-set recognition. IEEE Transactions on Neural Networks and Learning Systems 35(2):2327\u20132338","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"},{"key":"7229_CR48","doi-asserted-by":"crossref","unstructured":"Kim J-Y, Bu S-J, Cho S-B (2017) Malware detection using deep transferred generative adversarial networks, in Proc. Int. Conf. Neural Inf. Process. Guangzhou, China: Springer, pp. 556\u2013564","DOI":"10.1007\/978-3-319-70087-8_58"},{"key":"7229_CR49","doi-asserted-by":"crossref","unstructured":"Bendale A, Boult TE (2016) Towards open set deep networks, in Proc. IEEE Conf. Comput. Vis. Pattern Recognit., Jun. pp. 1563\u20131572","DOI":"10.1109\/CVPR.2016.173"},{"issue":"3","key":"7229_CR50","doi-asserted-by":"publisher","first-page":"762","DOI":"10.1109\/TPAMI.2017.2707495","volume":"40","author":"EM Rudd","year":"2018","unstructured":"Rudd EM, Jain LP, Scheirer WJ, Boult TE (2018) The extreme value machine. IEEE Transactions on Pattern Analysis and Machine Intelligence 40(3):762\u2013768","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"7229_CR51","unstructured":"Hassen M, Chan PK (2018) Learning to identify known and unknown classes: A case study in open world malware classification, in Proc. 31st Int. Flairs Conf., pp. 26\u201331"}],"container-title":["Applied Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-026-07229-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10489-026-07229-7","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10489-026-07229-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,26]],"date-time":"2026-05-26T10:48:33Z","timestamp":1779792513000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10489-026-07229-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4]]},"references-count":51,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,4]]}},"alternative-id":["7229"],"URL":"https:\/\/doi.org\/10.1007\/s10489-026-07229-7","relation":{},"ISSN":["0924-669X","1573-7497"],"issn-type":[{"value":"0924-669X","type":"print"},{"value":"1573-7497","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4]]},"assertion":[{"value":"8 July 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 February 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 April 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"None.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interest"}}],"article-number":"198"}}