{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T11:44:11Z","timestamp":1783597451140,"version":"3.55.0"},"reference-count":45,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,6,1]],"date-time":"2025-06-01T00:00:00Z","timestamp":1748736000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2025,6,1]],"date-time":"2025-06-01T00:00:00Z","timestamp":1748736000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"name":"Siksha 'O' Anusandhan Deemed To Be University"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Discov Computing"],"DOI":"10.1007\/s10791-025-09615-0","type":"journal-article","created":{"date-parts":[[2025,6,1]],"date-time":"2025-06-01T17:29:29Z","timestamp":1748798969000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["An Ensemble technique for imbalanced multiclass malware classification by leveraging API call semantics"],"prefix":"10.1007","volume":"28","author":[{"given":"Sudhanshu Shekhar","family":"Bisoyi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Binayak","family":"Panda","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bichitrananda","family":"Patra","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pragnyaban","family":"Mishra","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,6,1]]},"reference":[{"issue":"1","key":"9615_CR1","doi-asserted-by":"publisher","first-page":"467","DOI":"10.1109\/COMST.2022.3225137","volume":"25","author":"S Yan","year":"2023","unstructured":"Yan S, Ren J, Wang W, Sun L, Zhang W, Yu Q. A survey of adversarial attack and defense methods for malware classification in cyber security. IEEE Commun Surv Tutor. 2023;25(1):467\u201396. https:\/\/doi.org\/10.1109\/COMST.2022.3225137.","journal-title":"IEEE Commun Surv Tutor"},{"key":"9615_CR2","unstructured":"Quick heal threat report Q1-2023. 2023. https:\/\/www.quickheal.co.in\/documents\/threat-report\/quick-heal-threat-report-q1-2023.pdf."},{"key":"9615_CR3","unstructured":"Quick heal annual threat report. 2022. https:\/\/www.quickheal.co.in\/documents\/threat-report\/Quick-Heal-Annual-Threat-Report-2022.pdf."},{"key":"9615_CR4","unstructured":"Quick heal annual threat report. 2023. https:\/\/www.quickheal.co.in\/documents\/threat-report\/quick-heal-annual-threat-report-2023.pdf."},{"issue":"1","key":"9615_CR5","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1016\/0167-4048(87)90122-2","volume":"6","author":"F Cohen","year":"1987","unstructured":"Cohen F. Computer viruses: theory and experiments. Comput Sec. 1987;6(1):22\u201335. https:\/\/doi.org\/10.1016\/0167-4048(87)90122-2.","journal-title":"Comput Sec"},{"key":"9615_CR6","first-page":"3451","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"B Cheng","year":"2021","unstructured":"Cheng B, Ming J, Leal EA, Zhang H, Fu J, Peng G, Marion J-Y. Obfuscation-Resilient executable payload extraction from packed malware. In: Cheng B, editor. 30th USENIX Security Symposium (USENIX Security 21). Berkeley: USENIX Association; 2021. p. 3451\u201368."},{"key":"9615_CR7","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11416-015-0261-z","volume":"13","author":"A Damodaran","year":"2017","unstructured":"Damodaran A, Di Troia F, Visaggio CA, Austin T, Stamp M. A comparison of static, dynamic, and hybrid analysis for malware detection. J Comput Virol Hack Tech. 2017;13:1\u20132. https:\/\/doi.org\/10.1007\/s11416-015-0261-z.","journal-title":"J Comput Virol Hack Tech"},{"key":"9615_CR8","first-page":"1","volume-title":"2016 IEEE global communications conference (GLOBECOM)","author":"T Shibahara","year":"2016","unstructured":"Shibahara T, Yagi T, Akiyama M, Chiba D, Yada T. Efficient dynamic malware analysis based on network behavior using deep learning. In: Shibahara T, editor. 2016 IEEE global communications conference (GLOBECOM). Washington: IEEE; 2016. p. 1\u20137."},{"key":"9615_CR9","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11416-006-0028-7","volume":"2","author":"W Wong","year":"2006","unstructured":"Wong W, Stamp M. Hunting for metamorphic engines. J Comput Virol. 2006;2:211\u201329. https:\/\/doi.org\/10.1007\/s11416-006-0028-7.","journal-title":"J Comput Virol"},{"key":"9615_CR10","doi-asserted-by":"publisher","DOI":"10.7717\/peerj-cs.285","volume":"6","author":"C Ferhat Ozgur","year":"2020","unstructured":"Ferhat Ozgur C, Ahmet Faruk Y, Ogerta E, Javed A. Deep learning based sequential model for malware analysis using Windows exe API calls. PeerJ Comput Sci. 2020;6: e285. https:\/\/doi.org\/10.7717\/peerj-cs.285.","journal-title":"PeerJ Comput Sci"},{"key":"9615_CR11","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2022.100529","volume":"47","author":"M Gopinath","year":"2023","unstructured":"Gopinath M, Sethuraman SC. A comprehensive survey on deep learning based malware detection techniques. Comput Sci Rev. 2023;47: 100529. https:\/\/doi.org\/10.1016\/j.cosrev.2022.100529.","journal-title":"Comput Sci Rev"},{"issue":"6","key":"9615_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3638552","volume":"56","author":"MG Gaber","year":"2024","unstructured":"Gaber MG, Ahmed M, Janicke H. Malware detection with artificial intelligence: a systematic literature review. ACM Comput Surv. 2024;56(6):1\u201333. https:\/\/doi.org\/10.1145\/3638552.","journal-title":"ACM Comput Surv"},{"issue":"6","key":"9615_CR13","doi-asserted-by":"publisher","DOI":"10.1155\/2015\/659101","volume":"11","author":"Y Ki","year":"2015","unstructured":"Ki Y, Kim E, Kim HK. A novel approach to detect malware based on API call sequence analysis. Int J Distrib Sens Netw. 2015;11(6): 659101. https:\/\/doi.org\/10.1155\/2015\/659101.","journal-title":"Int J Distrib Sens Netw"},{"key":"9615_CR14","doi-asserted-by":"publisher","first-page":"323","DOI":"10.1007\/s11416-008-0082-4","volume":"4","author":"Y Ye","year":"2008","unstructured":"Ye Y, Wang D, Li T, Ye D, Jiang Q. An intelligent PE-malware detection system based on association mining. J Comput Virol. 2008;4:323\u201334. https:\/\/doi.org\/10.1007\/s11416-008-0082-4.","journal-title":"J Comput Virol"},{"key":"9615_CR15","doi-asserted-by":"publisher","DOI":"10.1145\/1854099.1854152","author":"P Vinod","year":"2010","unstructured":"Vinod P, Jain H, Golecha Y, Gaur M, Laxmi V. Medusa: metamorphic malware dynamic analysis using signature from API. ACM Dig Lib. 2010. https:\/\/doi.org\/10.1145\/1854099.1854152.","journal-title":"ACM Dig Lib"},{"key":"9615_CR16","doi-asserted-by":"publisher","DOI":"10.1145\/2487575.2488219","author":"D Kong","year":"2013","unstructured":"Kong D, Yan G. Discriminant malware distance learning on structural information for automated malware classification. ACM Dig Lib. 2013. https:\/\/doi.org\/10.1145\/2487575.2488219.","journal-title":"ACM Dig Lib"},{"key":"9615_CR17","doi-asserted-by":"publisher","first-page":"315","DOI":"10.1016\/j.cose.2013.08.008","volume":"39","author":"Y Ding","year":"2013","unstructured":"Ding Y, Yuan X, Tang K, Xiao X, Zhang Y. Malware detection based on objective-oriented association mining. Comput Sec. 2013;39:315\u201324. https:\/\/doi.org\/10.1016\/j.cose.2013.08.008.","journal-title":"Comput Sec"},{"key":"9615_CR18","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/CyberSA.2015.7166115","volume-title":"Analysis of malware behavior: Type classification using machine learning","author":"R Pirscoveanu","year":"2015","unstructured":"Pirscoveanu R, Hansen S, Larsen T, Stevanovic M, Pedersen J, Czech A. Analysis of malware behavior: Type classification using machine learning. London: IEEE; 2015. p. 1\u20137. https:\/\/doi.org\/10.1109\/CyberSA.2015.7166115."},{"key":"9615_CR19","doi-asserted-by":"publisher","first-page":"668","DOI":"10.1109\/CSNT.2015.62","volume-title":"2015 Fifth international conference on communication systems and network technologies","author":"V Mehra","year":"2015","unstructured":"Mehra V, Jain V, Uppal D. Dacomm: Detection and classification of metamorphic malware. In: Mehra V, editor. 2015 Fifth international conference on communication systems and network technologies. Gwalior: IEEE; 2015. p. 668\u201373. https:\/\/doi.org\/10.1109\/CSNT.2015.62."},{"key":"9615_CR20","doi-asserted-by":"publisher","unstructured":"Zhang, Y., Huang, Q., Ma, X., Yang, Z., Jiang, J.: Using multi-features and ensemble learning method for imbalanced malware classification. In: 2016 IEEE Trustcom\/BigDataSE\/ISPA, pp. 965\u2013973 (2016). https:\/\/doi.org\/10.1109\/TrustCom.2016.0163.","DOI":"10.1109\/TrustCom.2016.0163"},{"key":"9615_CR21","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/978-3-319-50127-7_11","volume-title":"AI 2016: Advances in Artificial Intelligence","author":"B Kolosnjaji","year":"2016","unstructured":"Kolosnjaji B, Zarras A, Webster G, Eckert C. Deep learning for classification of malware system call sequences. In: Kang BH, Bai Q, editors. AI 2016: Advances in Artificial Intelligence. Cham: Springer; 2016. p. 137\u201349."},{"issue":"3","key":"9615_CR22","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3073559","volume":"50","author":"Y Ye","year":"2017","unstructured":"Ye Y, Li T, Adjeroh D, Iyengar SS. A survey on malware detection using data mining techniques. ACM Comput Surv. 2017;50(3):1\u201340. https:\/\/doi.org\/10.1145\/3073559.","journal-title":"ACM Comput Surv"},{"key":"9615_CR23","doi-asserted-by":"publisher","first-page":"208","DOI":"10.1016\/j.cose.2019.02.007","volume":"83","author":"W Han","year":"2019","unstructured":"Han W, Xue J, Wang Y, Huang L, Kong Z, Mao L. Maldae: Detecting and explaining malware based on correlation and fusion of static and dynamic characteristics. Comput Secur. 2019;83:208\u201333. https:\/\/doi.org\/10.1016\/j.cose.2019.02.007.","journal-title":"Comput Secur"},{"key":"9615_CR24","doi-asserted-by":"publisher","first-page":"376","DOI":"10.1016\/j.future.2014.06.001","volume":"55","author":"S Huda","year":"2016","unstructured":"Huda S, Abawajy J, Alazab M, Abdollalihian M, Islam R, Yearwood J. Hybrids of support vector machine wrapper and filter based framework for malware detection. Futur Gener Comput Syst. 2016;55:376\u201390. https:\/\/doi.org\/10.1016\/j.future.2014.06.001.","journal-title":"Futur Gener Comput Syst"},{"key":"9615_CR25","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1016\/j.cose.2018.11.001","volume":"81","author":"D Ucci","year":"2019","unstructured":"Ucci D, Aniello L, Baldoni R. Survey of machine learning techniques for malware analysis. Comput Secur. 2019;81:123\u201347. https:\/\/doi.org\/10.1016\/j.cose.2018.11.001.","journal-title":"Comput Secur"},{"issue":"5","key":"9615_CR26","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3329786","volume":"52","author":"O Or-Meir","year":"2019","unstructured":"Or-Meir O, Nissim N, Elovici Y, Rokach L. Dynamic malware analysis in the modern era\u2013a state of the art survey. ACM Comput Surv. 2019;52(5):1\u201348. https:\/\/doi.org\/10.1145\/3329786.","journal-title":"ACM Comput Surv"},{"key":"9615_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11416-018-0314-1","volume":"15","author":"H Hashemi","year":"2019","unstructured":"Hashemi H, Hamzeh A. Visual malware detection using local malicious pattern. J Comput Virol Hack Techn. 2019;15:1\u201314. https:\/\/doi.org\/10.1007\/s11416-018-0314-1.","journal-title":"J Comput Virol Hack Techn"},{"key":"9615_CR28","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1016\/j.jisa.2018.11.007","volume":"44","author":"S Mohammadi","year":"2019","unstructured":"Mohammadi S, Mirvaziri H, Ghazizadeh-Ahsaee M, Karimipour H. Cyber intrusion detection by combined feature selection algorithm. J Inform Sec Appl. 2019;44:80\u20138. https:\/\/doi.org\/10.1016\/j.jisa.2018.11.007.","journal-title":"J Inform Sec Appl"},{"key":"9615_CR29","doi-asserted-by":"publisher","first-page":"14510","DOI":"10.1109\/ACCESS.2018.2805301","volume":"6","author":"J Fu","year":"2018","unstructured":"Fu J, Xue J, Wang Y, Liu Z, Shan C. Malware visualization for fine-grained classification. IEEE Access. 2018;6:14510\u201323.","journal-title":"IEEE Access"},{"key":"9615_CR30","first-page":"87","volume":"1","author":"J Mathew","year":"2020","unstructured":"Mathew J, Kumara M. API call based malware detection approach using recurrent neural network. LSTM. 2020;1:87\u201399.","journal-title":"LSTM"},{"key":"9615_CR31","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102448","volume":"110","author":"Z Halim","year":"2021","unstructured":"Halim Z, Yousaf MN, Waqas M, Sulaiman M, Abbas G, Hussain M, Ahmad I, Hanif M. An effective genetic algorithm-based feature selection method for intrusion detection systems. Comput Sec. 2021;110: 102448. https:\/\/doi.org\/10.1016\/j.cose.2021.102448.","journal-title":"Comput Sec"},{"issue":"14","key":"9615_CR32","doi-asserted-by":"publisher","first-page":"11453","DOI":"10.1007\/s00521-020-05347-y","volume":"34","author":"M Tahir","year":"2022","unstructured":"Tahir M, Tubaishat A, Al-Obeidat F, Shah B, Halim Z, Waqas M. A novel binary chaotic genetic algorithm for feature selection and its utility in affective computing and healthcare. Neural Comput Appl. 2022;34(14):11453\u201374. https:\/\/doi.org\/10.1007\/s00521-020-05347-y.","journal-title":"Neural Comput Appl"},{"issue":"11","key":"9615_CR33","doi-asserted-by":"publisher","first-page":"8309","DOI":"10.1007\/s00521-020-05101-4","volume":"34","author":"Al-Obeidat F Uzma","year":"2022","unstructured":"Uzma Al-Obeidat F, Tubaishat A, Shah B, Halim Z. Gene encoder: a feature selection technique through unsupervised deep learning-based clustering for large gene expression data. Neural Comput Appl. 2022;34(11):8309\u201331. https:\/\/doi.org\/10.1007\/s00521-020-05101-4.","journal-title":"Neural Comput Appl"},{"key":"9615_CR34","doi-asserted-by":"publisher","first-page":"285","DOI":"10.1007\/s11416-021-00414-x","volume":"18","author":"F Manavi","year":"2022","unstructured":"Manavi F, Hamzeh A. A novel approach for ransomware detection based on PE header using graph embedding. J Comput Virol Hack Tech. 2022;18:285\u201396. https:\/\/doi.org\/10.1007\/s11416-021-00414-x.","journal-title":"J Comput Virol Hack Tech"},{"issue":"1","key":"9615_CR35","doi-asserted-by":"publisher","first-page":"283","DOI":"10.7717\/peerj-cs.346","volume":"18","author":"G Sun","year":"2021","unstructured":"Sun G, Qian Q. Deep learning and visualization for identifying malware families. IEEE Comput Soc Press. 2021;18(1):283\u201395. https:\/\/doi.org\/10.7717\/peerj-cs.346.","journal-title":"IEEE Comput Soc Press"},{"key":"9615_CR36","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103277","volume":"130","author":"P Bhat","year":"2023","unstructured":"Bhat P, Behal S, Dutta K. A system call-based android malware detection approach with homogeneous & heterogeneous ensemble machine learning. Comput Sec. 2023;130: 103277. https:\/\/doi.org\/10.1016\/j.cose.2023.103277.","journal-title":"Comput Sec"},{"key":"9615_CR37","doi-asserted-by":"publisher","first-page":"3979","DOI":"10.1007\/s11042-017-5104-0","volume":"78","author":"X Xiao","year":"2019","unstructured":"Xiao X, Zhang S, Mercaldo F, Hu G, Sangaiah AK. Android malware detection based on system call sequences and LSTM. Multimed Tools Appl. 2019;78:3979\u201399.","journal-title":"Multimed Tools Appl"},{"issue":"3","key":"9615_CR38","doi-asserted-by":"publisher","first-page":"617","DOI":"10.13052\/jcsm2245-1439.1036","volume":"10","author":"C Li","year":"2021","unstructured":"Li C, Zheng J. API call-based malware classification using recurrent neural networks. J Cyber Sec Mob. 2021;10(3):617\u201340. https:\/\/doi.org\/10.13052\/jcsm2245-1439.1036.","journal-title":"J Cyber Sec Mob"},{"issue":"6","key":"9615_CR39","doi-asserted-by":"publisher","first-page":"7581","DOI":"10.1002\/cpe.7581","volume":"35","author":"C Avci","year":"2023","unstructured":"Avci C, Tekinerdogan B, Catal C. Analyzing the performance of long short-term memory architectures for malware detection models. Concurr Comput Pract Exp. 2023;35(6):7581. https:\/\/doi.org\/10.1002\/cpe.7581.","journal-title":"Concurr Comput Pract Exp"},{"key":"9615_CR40","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103842","volume":"141","author":"A Galli","year":"2024","unstructured":"Galli A, La Gatta V, Moscato V, Postiglione M, Sperl\u00ec G. Explainability in AI-based behavioral malware detection systems. Comput Sec. 2024;141: 103842. https:\/\/doi.org\/10.1016\/j.cose.2024.103842.","journal-title":"Comput Sec"},{"key":"9615_CR41","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102846","volume":"121","author":"F Demirkiran","year":"2022","unstructured":"Demirkiran F, Cayir A, Unal U, Dag H. An ensemble of pre-trained transformer models for imbalanced multiclass malware classification. Comput Secur. 2022;121: 102846. https:\/\/doi.org\/10.1016\/j.cose.2022.102846.","journal-title":"Comput Secur"},{"issue":"24","key":"9615_CR42","doi-asserted-by":"publisher","first-page":"2227","DOI":"10.3390\/math12244009","volume":"12","author":"C Miao","year":"2024","unstructured":"Miao C, Kou L, Zhang J, Dong G. A lightweight malware detection model based on knowledge distillation. Mathematics. 2024;12(24):2227\u20137390. https:\/\/doi.org\/10.3390\/math12244009.","journal-title":"Mathematics"},{"key":"9615_CR43","unstructured":"Cannarile, A., Carrera, F., Galantucci, S., Iannacone, A., Pirlo, G.: A study on malware detection and classification using the analysis of api calls sequences through shallow learning and recurrent neural networks. In: Italian Conference on Cybersecurity. 2022. https:\/\/api.semanticscholar.org\/CorpusID:253270019."},{"issue":"2","key":"9615_CR44","doi-asserted-by":"publisher","first-page":"580","DOI":"10.3390\/s24020580","volume":"24","author":"L Qian","year":"2024","unstructured":"Qian L, Cong L. Channel features and API frequency-based transformer model for malware identification. Sensors. 2024;24(2):580. https:\/\/doi.org\/10.3390\/s24020580.","journal-title":"Sensors"},{"key":"9615_CR45","unstructured":"Mikolov T, Chen K, Corrado G, Dean J. Efficient estimation of word representations in vector space. CoRR. 2013. arXiv:1301.3781."}],"container-title":["Discover Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10791-025-09615-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10791-025-09615-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10791-025-09615-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,1]],"date-time":"2025-06-01T17:29:31Z","timestamp":1748798971000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10791-025-09615-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,1]]},"references-count":45,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["9615"],"URL":"https:\/\/doi.org\/10.1007\/s10791-025-09615-0","relation":{},"ISSN":["2948-2992"],"issn-type":[{"value":"2948-2992","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,1]]},"assertion":[{"value":"19 November 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 May 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 June 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"Not applicable","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"The authors declare no competing of interest.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"100"}}