{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T16:14:38Z","timestamp":1774541678677,"version":"3.50.1"},"reference-count":38,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2020,6,1]],"date-time":"2020-06-01T00:00:00Z","timestamp":1590969600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2020,6,1]],"date-time":"2020-06-01T00:00:00Z","timestamp":1590969600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"}],"funder":[{"DOI":"10.13039\/501100010829","name":"Department of Education, Xinjiang Uygur Autonomous Region","doi-asserted-by":"publisher","award":["XJ2019G065"],"award-info":[{"award-number":["XJ2019G065"]}],"id":[{"id":"10.13039\/501100010829","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010829","name":"Department of Education, Xinjiang Uygur Autonomous Region","doi-asserted-by":"publisher","award":["XJWX-1-Z-2019-1021"],"award-info":[{"award-number":["XJWX-1-Z-2019-1021"]}],"id":[{"id":"10.13039\/501100010829","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010829","name":"Department of Education, Xinjiang Uygur Autonomous Region","doi-asserted-by":"publisher","award":["NGII20190412"],"award-info":[{"award-number":["NGII20190412"]}],"id":[{"id":"10.13039\/501100010829","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010829","name":"Department of Education, Xinjiang Uygur Autonomous Region","doi-asserted-by":"publisher","award":["NGII20170420"],"award-info":[{"award-number":["NGII20170420"]}],"id":[{"id":"10.13039\/501100010829","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computers &amp; Security"],"published-print":{"date-parts":[[2020,6]]},"DOI":"10.1016\/j.cose.2020.101792","type":"journal-article","created":{"date-parts":[[2020,3,17]],"date-time":"2020-03-17T07:00:20Z","timestamp":1584428420000},"page":"101792","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":95,"special_numbering":"C","title":["AMalNet: A deep learning framework based on graph convolutional networks for malware detection"],"prefix":"10.1016","volume":"93","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4772-7525","authenticated-orcid":false,"given":"Xinjun","family":"Pei","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Long","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0447-8242","authenticated-orcid":false,"given":"Shengwei","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.cose.2020.101792_bib0001","series-title":"International Conference on Security and Privacy in Communication Systems","first-page":"86","article-title":"Droidapiminer: Mining api-level features for robust malware detection in android","author":"Aafer","year":"2013"},{"key":"10.1016\/j.cose.2020.101792_bib0002","series-title":"2016 IEEE\/ACM 13th Working Conference on Mining Software Repositories (MSR)","first-page":"468","article-title":"Androzoo: collecting millions of android apps for the research community","author":"Allix","year":"2016"},{"key":"10.1016\/j.cose.2020.101792_bib0003","series-title":"Proceeding. 2014 Network Distribution System Security Symposium","article-title":"Drebin: effective and explainable detection of android malware in your pocket","volume":"45","author":"Arp","year":"2014"},{"issue":"6","key":"10.1016\/j.cose.2020.101792_bib0004","doi-asserted-by":"crossref","first-page":"1455","DOI":"10.1109\/TIFS.2018.2879302","article-title":"Droidcat: effective android malware detection and categorization via app-level profiling","volume":"14","author":"Cai","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"10.1016\/j.cose.2020.101792_bib0005","doi-asserted-by":"crossref","first-page":"166","DOI":"10.1504\/IJHPCN.2018.094367","article-title":"Malicious URL detection with feature extraction based on machine learning","volume":"12","author":"Cui","year":"2018","journal-title":"Int. J. High Performance Comput. Netw."},{"key":"10.1016\/j.cose.2020.101792_bib0006","series-title":"2016 IEEE Security and Privacy Workshops (SPW)","first-page":"252","article-title":"Droidscribe: classifying android malware based on runtime behavior","author":"Dash","year":"2016"},{"issue":"8","key":"10.1016\/j.cose.2020.101792_bib0007","doi-asserted-by":"crossref","first-page":"1890","DOI":"10.1109\/TIFS.2018.2806891","article-title":"Android malware familial classification and representative sample selection via frequent subgraph analysis","volume":"13","author":"Fan","year":"2018","journal-title":"IEEE Trans.Inf. Forensics Secur."},{"key":"10.1016\/j.cose.2020.101792_bib0008","series-title":"Proceedings of the 24th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining","first-page":"1416","article-title":"Large-scale learnable graph convolutional networks","author":"Gao","year":"2018"},{"key":"10.1016\/j.cose.2020.101792_bib0009","doi-asserted-by":"crossref","first-page":"25","DOI":"10.1016\/j.diin.2018.01.001","article-title":"An in-depth analysis of android malware using hybrid techniques","volume":"24","author":"Kabakus","year":"2018","journal-title":"Digital Investig."},{"key":"10.1016\/j.cose.2020.101792_bib0010","series-title":"2016 11th International Conference on Malicious and Unwanted Software (MALWARE)","first-page":"1","article-title":"DySign: dynamic fingerprinting for the automatic detection of android malware","author":"Karbab","year":"2016"},{"issue":"3","key":"10.1016\/j.cose.2020.101792_bib0012","doi-asserted-by":"crossref","first-page":"773","DOI":"10.1109\/TIFS.2018.2866319","article-title":"A multimodal deep learning method for android malware detection using various features","volume":"14","author":"Kim","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cose.2020.101792_bib0013","series-title":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","first-page":"174","article-title":"Detecting malicious code by model checking","author":"Kinder","year":"2005"},{"issue":"6","key":"10.1016\/j.cose.2020.101792_bib0014","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1109\/MIS.2016.45","article-title":"How to generate a good word embedding","volume":"31","author":"Lai","year":"2016","journal-title":"IEEE Intell. Syst."},{"key":"10.1016\/j.cose.2020.101792_bib0015","doi-asserted-by":"crossref","first-page":"S118","DOI":"10.1016\/j.diin.2018.04.024","article-title":"Deep learning at the shallow end: malware classification for non-domain experts","volume":"26","author":"Le","year":"2018","journal-title":"Digital Investig."},{"issue":"1","key":"10.1016\/j.cose.2020.101792_bib0016","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1109\/TSP.2018.2879624","article-title":"Cayleynets: graph convolutional neural networks with complex rational spectral filters","volume":"67","author":"Levie","year":"2018","journal-title":"IEEE Trans. Signal Process."},{"key":"10.1016\/j.cose.2020.101792_bib0018","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"5457","article-title":"Independently recurrent neural network (indrnn): building a longer and deeper rnn","author":"Li","year":"2018"},{"key":"10.1016\/j.cose.2020.101792_bib0019","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.cose.2015.02.007","article-title":"Stealth attacks: An extended insight into the obfuscation effects on android malware","volume":"51","author":"Maiorca","year":"2015","journal-title":"Comput.Secur."},{"issue":"12","key":"10.1016\/j.cose.2020.101792_bib0020","doi-asserted-by":"crossref","first-page":"1506","DOI":"10.18653\/v1\/D17-1159","article-title":"Encoding sentences with graph convolutional networks for semantic role labeling","volume":"18","author":"Marcheggiani","year":"2017","journal-title":"Proceedings of the 2017 Conference on Empirical Methods in Natural Language Processing"},{"issue":"June","key":"10.1016\/j.cose.2020.101792_bib0021","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1016\/j.engappai.2018.06.006","article-title":"CANDYMAN: classifying android malware families by modelling dynamic traces with markov chains","volume":"74","author":"Mart\u00edn","year":"2018","journal-title":"Eng. Appl. Artif. Intell."},{"issue":"3","key":"10.1016\/j.cose.2020.101792_bib0022","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1109\/TETCI.2017.2699220","article-title":"Context-aware, adaptive and scalable android malware detection through online learning (extended version)","volume":"1","author":"Narayanan","year":"2017","journal-title":"IEEE Trans. Emerg. Top. Computational Intell."},{"key":"10.1016\/j.cose.2020.101792_bib0023","doi-asserted-by":"crossref","first-page":"871","DOI":"10.1016\/j.cose.2018.04.005","article-title":"Malware identification using visualization images and deep learning","volume":"77","author":"Ni","year":"2018","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cose.2020.101792_bib0024","series-title":"International conference on machine learning","first-page":"2014","article-title":"Learning convolutional neural networks for graphs","author":"Niepert","year":"2016"},{"key":"10.1016\/j.cose.2020.101792_bib0025","series-title":"2018 16th Annual Conference on Privacy, Security and Trust (PST)","first-page":"1","article-title":"A family of droids-android malware detection via behavioral modeling: static vs dynamic analysis","author":"Onwuzurike","year":"2018"},{"key":"10.1016\/j.cose.2020.101792_bib0026","doi-asserted-by":"crossref","first-page":"828","DOI":"10.1016\/j.compeleceng.2017.11.028","article-title":"Machine learning-assisted signature and heuristic-based detection of malwares in Android devices","volume":"69","author":"Rehman","year":"2018","journal-title":"Comput. Electr. Eng."},{"key":"10.1016\/j.cose.2020.101792_bib0027","unstructured":"Rui Zhu., Chenglin Li., Di Niu., Hongwen Zhang., & Husam Kinawi. (2018). Android malware detection using large-scale network representation learning. Retrieved from http:\/\/arxiv.org\/abs\/1806.04847."},{"key":"10.1016\/j.cose.2020.101792_bib0017","unstructured":"Li, C., Mills, K., Zhu, R., Niu, D., Zhang, H., & Kinawi, H.. (2018). Android malware detection based on factorization machine. Retrieved from http:\/\/arxiv.org\/abs\/1805.11843."},{"key":"10.1016\/j.cose.2020.101792_bib0028","series-title":"2019 15th International Wireless Communications & Mobile Computing Conference (IWCMC)","first-page":"561","article-title":"Benchmarking convolutional and recurrent neural networks for malware classification","author":"Safa","year":"2019"},{"key":"10.1016\/j.cose.2020.101792_bib0029","series-title":"Proceedings of the 13th International Conference on Availability, Reliability and Security","first-page":"26","article-title":"An investigation of a deep learning based malware detection system","author":"Sewak","year":"2018"},{"key":"10.1016\/j.cose.2020.101792_bib0030","article-title":"EEG emotion recognition using dynamical graph convolutional neural networks","author":"Song","year":"2018","journal-title":"IEEE Trans. Affect. Computing"},{"key":"10.1016\/j.cose.2020.101792_bib0031","series-title":"2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC)","first-page":"664","article-title":"Lightweight classification of IoT malware based on image recognition","volume":"2","author":"Su","year":"2018"},{"key":"10.1016\/j.cose.2020.101792_bib0032","series-title":"Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy","first-page":"309","article-title":"Droidsieve: fast and accurate classification of obfuscated android malware","author":"Suarez-Tangil","year":"2017"},{"key":"10.1016\/j.cose.2020.101792_bib0034","series-title":"2017 International Conference on Information Networking (ICOIN)","first-page":"712","article-title":"Malware traffic classification using convolutional neural network for representation learning","author":"Wang","year":"2017"},{"key":"10.1016\/j.cose.2020.101792_bib0035","series-title":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","first-page":"252","article-title":"Deep ground truth analysis of current android malware","author":"Wei","year":"2017"},{"issue":"6","key":"10.1016\/j.cose.2020.101792_bib0036","doi-asserted-by":"crossref","first-page":"1252","DOI":"10.1109\/TIFS.2016.2523912","article-title":"ICCDetector: ICC-based malware detection on Android[J]","volume":"11","author":"Xu","year":"2016","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cose.2020.101792_bib0037","series-title":"Proceedings of the AAAI Conference on Artificial Intelligence","first-page":"7370","article-title":"Graph convolutional networks for text classification","volume":"33","author":"Yao","year":"2019"},{"issue":"1","key":"10.1016\/j.cose.2020.101792_bib0038","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/TST.2016.7399288","article-title":"Droiddetector: android malware characterization and detection using deep learning","volume":"21","author":"Yuan","year":"2016","journal-title":"Tsinghua Sci. Technol."},{"key":"10.1016\/j.cose.2020.101792_bib0039","series-title":"2017 Seventh International Conference on Emerging Security Technologies (EST)","first-page":"122","article-title":"A new mobile botnet classification based on permission and API calls","author":"Yusof","year":"2017"},{"key":"10.1016\/j.cose.2020.101792_bib0040","doi-asserted-by":"crossref","first-page":"308","DOI":"10.1016\/j.patcog.2019.06.012","article-title":"Learning graph structure via graph convolutional networks","volume":"95","author":"Zhang","year":"2019","journal-title":"Pattern Recognit."}],"container-title":["Computers &amp; Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404820300778?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0167404820300778?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T19:07:32Z","timestamp":1759086452000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0167404820300778"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6]]},"references-count":38,"alternative-id":["S0167404820300778"],"URL":"https:\/\/doi.org\/10.1016\/j.cose.2020.101792","relation":{},"ISSN":["0167-4048"],"issn-type":[{"value":"0167-4048","type":"print"}],"subject":[],"published":{"date-parts":[[2020,6]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"AMalNet: A deep learning framework based on graph convolutional networks for malware detection","name":"articletitle","label":"Article Title"},{"value":"Computers & Security","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cose.2020.101792","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2020 Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"101792"}}