{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,19]],"date-time":"2026-05-19T14:53:14Z","timestamp":1779202394152,"version":"3.51.4"},"reference-count":275,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T00:00:00Z","timestamp":1768867200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/100031478","name":"NextGenerationEU","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100031478","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100024370","name":"Ministero dell&apos;Istruzione dell&apos;Universita e della Ricerca","doi-asserted-by":"publisher","award":["PE00000014"],"award-info":[{"award-number":["PE00000014"]}],"id":[{"id":"10.13039\/501100024370","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100021856","name":"Ministero dell&apos;Universit\u00e0 e della Ricerca","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100021856","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100012352","name":"Universit\u00e0 degli Studi di Milano","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100012352","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Computer Science Review"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.cosrev.2026.100914","type":"journal-article","created":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T11:05:02Z","timestamp":1772190302000},"page":"100914","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":2,"special_numbering":"C","title":["Security through the eyes of AI: How visualization is shaping malware detection"],"prefix":"10.1016","volume":"61","author":[{"given":"Matteo","family":"Brosolo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Asmitha","family":"K. A.","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rafidha Rehiman","family":"K. A.","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Muhammed Shafi","family":"K. P.","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2719-9526","authenticated-orcid":false,"given":"Serena","family":"Nicolazzo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Antonino","family":"Nocera","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vinod","family":"P.","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.cosrev.2026.100914_bib0005","article-title":"TensorFlow","year":"2022","journal-title":"Zenodo"},{"key":"10.1016\/j.cosrev.2026.100914_bib0010","article-title":"Malware classification and composition analysis: A survey of recent developments","volume":"59","author":"Abusitta","year":"2021","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0015","series-title":"2021 12th International Conference on Computing Communication and Networking Technologies (ICCCNT)","first-page":"1","article-title":"Efficientnet-based convolutional neural networks for malware classification","author":"Acharya","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100914_bib0020","series-title":"Proceedings of the 17th International Conference on Availability, Reliability and Security, ARES \u201922","article-title":"Image-based neural network models for malware traffic classification using pcap to picture conversion","author":"Agrafiotis","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0025","series-title":"Proceedings of the sixth ACM conference on data and application security and privacy","first-page":"183","article-title":"Novel feature extraction, selection and fusion for effective malware family classification","author":"Ahmadi","year":"2016"},{"key":"10.1016\/j.cosrev.2026.100914_bib0030","first-page":"11","article-title":"An inception v3 approach for malware classification using machine learning and transfer learning","volume":"4","author":"Ahmed","year":"2023","journal-title":"Int. J. Intell. Netw."},{"key":"10.1016\/j.cosrev.2026.100914_bib0035","series-title":"2019 5th International Conference on Advanced Computing & Communication Systems (ICACCS)","first-page":"1059","article-title":"Deep learning framework and visualization for malware classification","author":"Akarsh","year":"2019"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib0040","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1007\/s10618-024-01078-z","article-title":"Miracle: Malware image recognition and classification by layered extraction","volume":"39","author":"Alam","year":"2025","journal-title":"Data Min. Knowl. Discov."},{"key":"10.1016\/j.cosrev.2026.100914_bib0045","doi-asserted-by":"crossref","first-page":"212","DOI":"10.1016\/j.cose.2014.10.011","article-title":"A framework for metamorphic malware analysis and real-time detection","volume":"48","author":"Alam","year":"2015","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0050","doi-asserted-by":"crossref","DOI":"10.1016\/j.jpdc.2025.105039","article-title":"Fasnet: Federated adversarial siamese networks for robust malware image classification","volume":"198","author":"Ambekar","year":"2025","journal-title":"J. Parallel Distrib. Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib0055","unstructured":"H. Analysis, Hybrid sandbox, 2026, https:\/\/www.hybrid-analysis.com"},{"key":"10.1016\/j.cosrev.2026.100914_bib0060","first-page":"1","article-title":"Malware visualization and detection using densenets","volume":"28","author":"Anandhi","year":"2021","journal-title":"Pers. Ubiquitous Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib0065","author":"Anderson"},{"key":"10.1016\/j.cosrev.2026.100914_bib0070","author":"Anderson"},{"key":"10.1016\/j.cosrev.2026.100914_bib0075","article-title":"An intelligent ransomware attack detection and classification using dual vision transformer with mantis search split attention network","volume":"119","author":"Ashwini","year":"2024","journal-title":"Comput. Electr. Eng."},{"key":"10.1016\/j.cosrev.2026.100914_bib0080","doi-asserted-by":"crossref","first-page":"6249","DOI":"10.1109\/ACCESS.2019.2963724","article-title":"A comprehensive review on malware detection approaches","volume":"8","author":"Aslan","year":"2020","journal-title":"IEEE Access"},{"issue":"7","key":"10.1016\/j.cosrev.2026.100914_bib0085","doi-asserted-by":"crossref","first-page":"9191","DOI":"10.1007\/s10586-024-04397-4","article-title":"Deep learning vs. adversarial noise: a battle in malware image analysis","volume":"27","author":"Asmitha","year":"2024","journal-title":"Cluster Computing"},{"key":"10.1016\/j.cosrev.2026.100914_bib0090","series-title":"2021 9th International Conference on Cyber and IT Service Management (CITSM)","first-page":"1","article-title":"Classification of malware using deep learning techniques","author":"Bagane","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100914_bib0095","unstructured":"D. Bahdanau, K. Cho, Y. Bengio, Neural machine translation by jointly learning to align and translate, arXiv preprint arXiv:1409.0473, 2016."},{"key":"10.1016\/j.cosrev.2026.100914_bib0100","series-title":"Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering","first-page":"1560","article-title":"Unsuccessful story about few shot malware family classification and siamese network to the rescue","author":"Bai","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100914_bib0105","doi-asserted-by":"crossref","first-page":"11499","DOI":"10.1007\/s00521-021-05816-y","article-title":"Deepvisdroid: android malware detection by hybridizing image-based features with deep learning techniques","volume":"33","author":"Bakour","year":"2021","journal-title":"Neural Comput. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0110","doi-asserted-by":"crossref","first-page":"3133","DOI":"10.1007\/s00521-020-05195-w","article-title":"Visdroid: Android malware classification based on local and global image features, bag of visual words and machine learning techniques","volume":"33","author":"Bakour","year":"2021","journal-title":"Neural Comput. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0115","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2023.108804","article-title":"Droidencoder: Malware detection using auto-encoder based feature extractor and machine learning algorithms","volume":"110","author":"Bak\u0131r","year":"2023","journal-title":"Comput. Electr. Eng."},{"key":"10.1016\/j.cosrev.2026.100914_bib0120","series-title":"2019 IEEE International Conference on Communications Workshops (ICC Workshops)","first-page":"1","article-title":"A novel malware detection system based on machine learning and binary visualization","author":"Baptista","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0125","series-title":"2022 IEEE Symposium on Security and Privacy (SP)","first-page":"805","article-title":"Transcending transcend: Revisiting malware classification in the presence of concept drift","author":"Barbero","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0130","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102785","article-title":"Malware-smell: A zero-shot learning strategy for detecting zero-day vulnerabilities","volume":"120","author":"Barros","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0135","series-title":"Proceedings of the 6th International Conference on Networking, Intelligent Systems & Security","first-page":"1","article-title":"Enhancing malware classification with vision transformers: a comparative study with traditional cnn models","author":"Ben abdel ouahab","year":"2023"},{"key":"10.1016\/j.cosrev.2026.100914_bib0140","article-title":"Deep multi-task learning for malware image classification","volume":"64","author":"Bensaoud","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0145","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1201\/9781003433958-3","article-title":"Android malware detection: A comprehensive review","author":"Bhavan","year":"2024","journal-title":"Res. Adv. Netw. Technol."},{"key":"10.1016\/j.cosrev.2026.100914_bib0150","series-title":"Proceedings of the 4th International Conference on Networking, Information Systems &; Security, NISS2021","first-page":"1","article-title":"Transfer learning and smote algorithm for image-based malware classification","author":"Bouchaib","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100914_bib0155","article-title":"SMOTE: synthetic minority over-sampling technique","volume":"abs\/1106.1813","author":"Bowyer","year":"2011","journal-title":"CoRR"},{"key":"10.1016\/j.cosrev.2026.100914_bib0160","series-title":"2019 27th Signal Processing and Communications Applications Conference (SIU)","first-page":"1","article-title":"Utilization and comparision of convolutional neural networks in malware recognition","author":"Bozkir","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0165","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.102166","article-title":"Catch them alive: A malware detection approach through memory forensics, manifold learning and computer vision","volume":"103","author":"Bozkir","year":"2021","journal-title":"Comput. & Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0170","series-title":"Proceedings. Compression and Complexity of SEQUENCES 1997 (Cat. No.97TB100171)","first-page":"21","article-title":"On the resemblance and containment of documents","author":"Broder","year":"1997"},{"key":"10.1016\/j.cosrev.2026.100914_bib0175","series-title":"Proceedings of the 19th International Conference on Availability, Reliability and Security","first-page":"1","article-title":"Sok: Visualization-based malware detection techniques","author":"Brosolo","year":"2024"},{"key":"10.1016\/j.cosrev.2026.100914_bib0180","article-title":"Through the static: Demystifying malware visualization via explainability","volume":"91","author":"Brosolo","year":"2025","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0185","series-title":"2019 IEEE 10th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON)","first-page":"0660","article-title":"Data augmentation with generative models for improved malware detection: A comparative study","author":"Burks","year":"2019"},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib0190","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3371924","article-title":"Assessing and improving malware detection sustainability through app evolution studies","volume":"29","author":"Cai","year":"2020","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib0195","first-page":"44","article-title":"Dynamic mobile malware detection through system call-based image representation","volume":"12","author":"Casolare","year":"2021","journal-title":"J. Wirel. Mob. Netw. Ubiquitous Comput. Dependable Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0200","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.102133","article-title":"Random capsnet forest model for imbalanced malware type classification task","volume":"102","author":"\u00c7ay\u0131r","year":"2021","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0205","article-title":"Image-based malware representation approach with efficientnet convolutional neural networks for effective malware classification","volume":"69","author":"Chaganti","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0210","article-title":"A multi-view feature fusion approach for effective malware classification using deep learning","volume":"72","author":"Chaganti","year":"2023","journal-title":"J. Inf. Secur. Appl."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100914_bib0215","doi-asserted-by":"crossref","first-page":"4248","DOI":"10.1109\/TNSM.2022.3200866","article-title":"From data and model levels: Improve the performance of few-shot malware classification","volume":"19","author":"Chai","year":"2022","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.cosrev.2026.100914_bib0220","series-title":"Proceedings of the Thiry-Fourth Annual ACM Symposium on Theory of Computing, STOC \u201902","first-page":"380","article-title":"Similarity estimation techniques from rounding algorithms","author":"Charikar","year":"2002"},{"key":"10.1016\/j.cosrev.2026.100914_bib0225","series-title":"2019 IEEE 10th International Conference on Awareness Science and Technology (iCAST)","first-page":"1","article-title":"Applying convolutional neural network for malware detection","author":"Chen","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0230","author":"Chen"},{"key":"10.1016\/j.cosrev.2026.100914_bib0235","series-title":"2022 IEEE 10th International Conference on Information, Communication and Networks (ICICN)","first-page":"704","article-title":"Malicious code family classification method based on vision transformer","author":"Chen","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0240","doi-asserted-by":"crossref","first-page":"987","DOI":"10.1109\/TIFS.2019.2932228","article-title":"Android hiv: A study of repackaging malware for evading machine-learning detection","volume":"15","author":"Chen","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0245","series-title":"2008 IEEE International Conference on Dependable Systems and Networks With FTCS and DCC (DSN)","first-page":"177","article-title":"Towards an understanding of anti-virtualization and anti-debugging behavior in modern malware","author":"Chen","year":"2008"},{"key":"10.1016\/j.cosrev.2026.100914_bib0250","series-title":"2017 International Conference on Information and Communication Technology Convergence (ICTC)","first-page":"1193","article-title":"Malware detection using malware image and deep learning","author":"Choi","year":"2017"},{"key":"10.1016\/j.cosrev.2026.100914_bib0255","unstructured":"F. Chollet, et al., Keras, 2026, https:\/\/keras.io"},{"key":"10.1016\/j.cosrev.2026.100914_bib0260","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102887","article-title":"A few-shot malware classification approach for unknown family recognition using malware feature visualization","volume":"122","author":"Conti","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0265","unstructured":"A. Cortesi, binvis.io: Visual analysis of binary files, 2026. http:\/\/binvis.io\/#\/"},{"key":"10.1016\/j.cosrev.2026.100914_bib0270","series-title":"2019 2nd International Conference on Data Intelligence and Security (ICDIS)","first-page":"108","article-title":"Robust pdf malware detection with image visualization and processing techniques","author":"Corum","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0275","unstructured":"cuckoosandbo.org. Cuckoo sandbox, 2026, https:\/\/cuckoosandbox.org"},{"issue":"7","key":"10.1016\/j.cosrev.2026.100914_bib0280","doi-asserted-by":"crossref","first-page":"3187","DOI":"10.1109\/TII.2018.2822680","article-title":"Detection of malicious code variants based on deep learning","volume":"14","author":"Cui","year":"2018","journal-title":"IEEE Trans. Ind. Inf."},{"key":"10.1016\/j.cosrev.2026.100914_bib0285","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1016\/j.diin.2018.09.006","article-title":"A malware classification method based on memory dump grayscale image","volume":"27","author":"Dai","year":"2018","journal-title":"Digit. Investig."},{"key":"10.1016\/j.cosrev.2026.100914_bib0290","series-title":"2005 IEEE Computer Society Conference on Computer Vision and Pattern Recognition (CVPR\u201905)","first-page":"886","article-title":"Histograms of oriented gradients for human detection","volume":"vol. 1","author":"Dalal","year":"2005"},{"key":"10.1016\/j.cosrev.2026.100914_bib0295","first-page":"1573","article-title":"Lessons learnt on reproducibility in machine learning based android malware detection","volume":"26","author":"Allix","year":"2021","journal-title":"Empir. Softw. Eng."},{"key":"10.1016\/j.cosrev.2026.100914_bib0300","series-title":"Deployable Machine Learning for Security Defense: Second International Workshop, MLHat 2021, Virtual Event, August 15, 2021, Proceedings 2","first-page":"81","article-title":"Dexray: a simple, yet effective deep learning approach to android malware detection based on image representation of bytecode","author":"Daoudi","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100914_bib0305","doi-asserted-by":"crossref","first-page":"314","DOI":"10.1016\/j.future.2021.06.032","article-title":"Visualization and deep-learning-based malware variant detection using opcode-level features","volume":"125","author":"Darem","year":"2021","journal-title":"Futur. Gener. Comput. Syst."},{"key":"10.1016\/j.cosrev.2026.100914_bib0310","series-title":"2018 Cyber Resilience Conference (CRC)","first-page":"1","article-title":"Android malware detection using machine learning on image patterns","author":"Darus","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib0315","series-title":"2019 IEEE National Aerospace and Electronics Conference (NAECON)","first-page":"273","article-title":"Convolutional neural networks as classification tools and feature extractors for distinguishing malware programs","author":"Davuluru","year":"2019"},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib0320","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3605775","article-title":"Deep learning for zero-day malware detection and classification: A survey","volume":"56","author":"Deldar","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.cosrev.2026.100914_bib0325","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.103084","article-title":"Mctvd: A malware classification method based on three-channel visualization and deep learning","volume":"126","author":"Deng","year":"2023","journal-title":"Comput. Secur."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib0330","doi-asserted-by":"crossref","first-page":"2756","DOI":"10.1109\/JSYST.2023.3238678","article-title":"Obfuscated malware detection in iot android applications using markov images and cnn","volume":"17","author":"Dhanya","year":"2023","journal-title":"IEEE Syst. J."},{"key":"10.1016\/j.cosrev.2026.100914_bib0335","series-title":"2022 IEEE 8th International Conference on Computing, Engineering and Design (ICCED)","first-page":"1","article-title":"Improved malware detection results using visualization-based detection techniques ant convolutional neural network","author":"Dharmalaksana","year":"2022"},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib0340","doi-asserted-by":"crossref","first-page":"1165","DOI":"10.1109\/TNSM.2021.3075315","article-title":"A multi-dimensional deep learning framework for iot malware classification and family attribution","volume":"18","author":"Dib","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"10.1016\/j.cosrev.2026.100914_bib0345","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2024.101258","article-title":"Image-based malware analysis for enhanced iot security in smart cities","volume":"27","author":"Dong","year":"2024","journal-title":"Internet of Things"},{"key":"10.1016\/j.cosrev.2026.100914_bib0350","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.jpdc.2019.11.001","article-title":"Malware detection in mobile environments based on autoencoders and api-images","volume":"137","author":"D\u2019Angelo","year":"2020","journal-title":"J. Parallel Distrib. Comput."},{"issue":"5","key":"10.1016\/j.cosrev.2026.100914_bib0355","doi-asserted-by":"crossref","first-page":"1968","DOI":"10.1016\/j.jksuci.2022.02.026","article-title":"Mal-detect: An intelligent visualization approach for malware detection","volume":"34","author":"Falana","year":"2022","journal-title":"J. King Saud Univ. - Comput. Inf. Sci."},{"key":"10.1016\/j.cosrev.2026.100914_bib0360","doi-asserted-by":"crossref","first-page":"838","DOI":"10.1109\/TIFS.2020.3021924","article-title":"Can we trust your explanations? sanity checks for interpreters in android malware analysis","volume":"16","author":"Fan","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100914_bib0365","first-page":"594","article-title":"Perona, 2006 fei-fei l, fergus r, perona p","volume":"28","author":"Fei-Fei","year":"2006","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"10.1016\/j.cosrev.2026.100914_bib0370","series-title":"2020 international joint conference on neural networks (IJCNN)","first-page":"1","article-title":"When explainability meets adversarial learning: Detecting adversarial examples using shap signatures","author":"Fidel","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100914_bib0375","doi-asserted-by":"crossref","first-page":"14510","DOI":"10.1109\/ACCESS.2018.2805301","article-title":"Malware visualization for fine-grained classification","volume":"6","author":"Fu","year":"2018","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib0380","unstructured":"A.N.Y.R.U.N. FZCO, Any.run, 2026, https:\/\/any.run"},{"issue":"5","key":"10.1016\/j.cosrev.2026.100914_bib0385","doi-asserted-by":"crossref","first-page":"5995","DOI":"10.3934\/mbe.2021300","article-title":"Malware detection based on semi-supervised learning with malware visualization","volume":"18","author":"Gao","year":"2021","journal-title":"Math. Biosci. Eng."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100914_bib0390","doi-asserted-by":"crossref","first-page":"305","DOI":"10.22363\/2658-4670-2019-27-4-305-315","article-title":"Review and comparative analysis of machine learning libraries for machine learning","volume":"27","author":"Gevorkyan","year":"2019","journal-title":"Discrete and Continuous Models and Applied Computational Science"},{"key":"10.1016\/j.cosrev.2026.100914_bib0395","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102543","article-title":"Enhancing the insertion of nop instructions to obfuscate malware via deep reinforcement learning","volume":"113","author":"Gibert","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0400","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.101873","article-title":"Hydra: A multimodal deep learning framework for malware classification","volume":"95","author":"Gibert","year":"2020","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0405","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2019.102526","article-title":"The rise of machine learning for detection and classification of malware: Research developments, trends and challenges","volume":"153","author":"Gibert","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0410","doi-asserted-by":"crossref","first-page":"15","DOI":"10.1007\/s11416-018-0323-0","article-title":"Using convolutional neural networks for classification of malware represented as images","volume":"15","author":"Gibert","year":"2019","journal-title":"J. Comput. Virol. Hack. Tech."},{"key":"10.1016\/j.cosrev.2026.100914_bib0415","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.117957","article-title":"Fusing feature engineering and deep learning: A case study for malware classification","volume":"207","author":"Gibert","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0420","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104495","article-title":"Assessing the impact of packing on static machine learning-based malware detection and classification systems","volume":"156","author":"Gibert","year":"2025","journal-title":"Comput. & Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0425","series-title":"2020 IEEE Congress on Evolutionary Computation (CEC)","first-page":"1","article-title":"Visualization approach for malware classification with resnext","author":"Go","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100914_bib0430","series-title":"2021 7th International Conference on Web Research (ICWR)","first-page":"71","article-title":"Android malware detection and classification based on network traffic using deep learning","author":"Gohari","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100914_bib0435","author":"Goodfellow"},{"key":"10.1016\/j.cosrev.2026.100914_bib0440","author":"Goodfellow"},{"key":"10.1016\/j.cosrev.2026.100914_bib0445","article-title":"A comprehensive survey on deep learning based malware detection techniques","volume":"47","author":"Gopinath","year":"2023","journal-title":"Comput. Sci. Rev."},{"issue":"10","key":"10.1016\/j.cosrev.2026.100914_bib0450","doi-asserted-by":"crossref","first-page":"1160","DOI":"10.1109\/TIP.2002.804262","article-title":"Comparison of texture features based on gabor filters","volume":"11","author":"Grigorescu","year":"2002","journal-title":"IEEE Trans. Image Process."},{"key":"10.1016\/j.cosrev.2026.100914_bib0455","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.117200","article-title":"Android malware concept drift using system calls: detection, characterization and challenges","volume":"206","author":"Guerra-Manzanares","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0460","doi-asserted-by":"crossref","unstructured":"J. Guo, Y. Xu, W. Xu, Y. Zhan, Y. Sun, S. Guo, Mdenet: Multi-modal dual-embedding networks for malware open-set recognition, 2026.","DOI":"10.1109\/TNNLS.2024.3373809"},{"key":"10.1016\/j.cosrev.2026.100914_bib0465","series-title":"proceedings of the 2018 ACM SIGSAC conference on computer and communications security","first-page":"364","article-title":"Lemna: Explaining deep learning based security applications","author":"Guo","year":"2018"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib0470","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10207-014-0242-0","article-title":"Malware analysis using visualized images and entropy graphs","volume":"14","author":"Han","year":"2015","journal-title":"Int. J. Inf. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0475","series-title":"Proceedings of the 2013 Research in Adaptive and Convergent Systems","first-page":"317","article-title":"Malware analysis method using visualization of binary files","author":"Han","year":"2013"},{"key":"10.1016\/j.cosrev.2026.100914_bib0480","doi-asserted-by":"crossref","first-page":"610","DOI":"10.1109\/TSMC.1973.4309314","article-title":"Textural features for image classification","volume":"6","author":"Haralick","year":"1973","journal-title":"IEEE Trans. Syst. Man Cybern."},{"key":"10.1016\/j.cosrev.2026.100914_bib0485","series-title":"2018 IEEE 14th International Colloquium on Signal Processing & Its Applications (CSPA)","first-page":"99","article-title":"One-dimensional convolutional neural networks for android malware detection","author":"Hasegawa","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib0490","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11416-018-0314-1","article-title":"Visual malware detection using local malicious pattern","volume":"15","author":"Hashemi","year":"2019","journal-title":"J. Comput. Virol. Hack. Tech."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib0495","doi-asserted-by":"crossref","first-page":"271","DOI":"10.1007\/s11416-022-00445-y","article-title":"Ifmd: image fusion for malware detection","volume":"19","author":"Hashemi","year":"2023","journal-title":"J. Comput. Virol. Hack. Tech."},{"issue":"6","key":"10.1016\/j.cosrev.2026.100914_bib0500","doi-asserted-by":"crossref","first-page":"417","DOI":"10.1037\/h0071325","article-title":"Analysis of a complex of statistical variables into principal components","volume":"24","author":"Hotelling","year":"1933","journal-title":"J. Educ. Psychol."},{"key":"10.1016\/j.cosrev.2026.100914_bib0505","doi-asserted-by":"crossref","first-page":"1863","DOI":"10.1016\/j.procs.2019.09.358","article-title":"Malware image classification using one-shot learning with siamese networks","volume":"159","author":"Hsiao","year":"2019","journal-title":"Procedia Comput. Sci."},{"key":"10.1016\/j.cosrev.2026.100914_bib0510","article-title":"Densely connected convolutional networks","volume":"abs\/1608.06993","author":"Huang","year":"2016","journal-title":"CoRR"},{"key":"10.1016\/j.cosrev.2026.100914_bib0515","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1007\/s11265-020-01588-1","article-title":"A method for windows malware detection based on deep learning","volume":"93","author":"Huang","year":"2021","journal-title":"J. Signal Process. Syst."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100914_bib0520","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1109\/MCSE.2007.55","article-title":"Matplotlib: A 2d graphics environment","volume":"9","author":"Hunter","year":"2007","journal-title":"Comput. Sci. Eng."},{"key":"10.1016\/j.cosrev.2026.100914_bib0525","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102198","article-title":"Towards an interpretable deep learning model for mobile malware detection and family identification","volume":"105","author":"Iadarola","year":"2021","journal-title":"Comput. Secur."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100914_bib0530","doi-asserted-by":"crossref","first-page":"245","DOI":"10.1007\/s11416-018-0316-z","article-title":"The duplication issue within the drebin dataset","volume":"14","author":"Irolla","year":"2018","journal-title":"J. Comput. Virol. Hack. Tech."},{"key":"10.1016\/j.cosrev.2026.100914_bib0535","doi-asserted-by":"crossref","first-page":"229","DOI":"10.1007\/s11416-020-00354-y","article-title":"Convolutional neural networks and extreme learning machines for malware classification","volume":"16","author":"Jain","year":"2020","journal-title":"J. Comput. Virol. Hack. Tech."},{"key":"10.1016\/j.cosrev.2026.100914_bib0540","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102400","article-title":"A novel framework for image-based malware detection with a deep neural network","volume":"109","author":"Jian","year":"2021","journal-title":"Comput. Secur."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100914_bib0545","doi-asserted-by":"crossref","first-page":"2785","DOI":"10.1007\/s12652-023-04522-y","article-title":"A pyramid stripe pooling-based convolutional neural network for malware detection and classification","volume":"14","author":"Jiang","year":"2023","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"issue":"11","key":"10.1016\/j.cosrev.2026.100914_bib0550","doi-asserted-by":"crossref","first-page":"6839","DOI":"10.3390\/app13116839","article-title":"A malware detection and extraction method for the related information using the vit attention mechanism on android operating system","volume":"13","author":"Jo","year":"2023","journal-title":"Appl. Sci."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib0555","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1007\/s10586-024-04723-w","article-title":"Deep learning fusion for effective malware detection: leveraging visual features","volume":"28","author":"Johny","year":"2025","journal-title":"Cluster Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib0560","series-title":"26th USENIX security symposium (USENIX security 17)","first-page":"625","article-title":"Transcend: Detecting concept drift in malware classification models","author":"Jordaney","year":"2017"},{"key":"10.1016\/j.cosrev.2026.100914_bib0565","series-title":"2018 9th IFIP international conference on new technologies, mobility and security (NTMS)","first-page":"1","article-title":"Malware classification with deep convolutional neural networks","author":"Kalash","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib0570","series-title":"2013 IEEE symposium on computational intelligence in cyber security (CICS)","first-page":"40","article-title":"Image visualization based malware detection","author":"Kancherla","year":"2013"},{"key":"10.1016\/j.cosrev.2026.100914_bib0575","doi-asserted-by":"crossref","DOI":"10.1016\/j.iot.2019.100153","article-title":"Analysis of internet of things malware using image texture features and machine learning techniques","volume":"9","author":"Karanja","year":"2020","journal-title":"Internet of Things"},{"key":"10.1016\/j.cosrev.2026.100914_bib0580","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.120017","article-title":"Swiftr: Cross-platform ransomware fingerprinting using hierarchical neural networks on hybrid features","volume":"225","author":"Karbab","year":"2023","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0585","unstructured":"K. Kerr, Trustwave\u2019s 2025 cybersecurity predictions: AI-powered attacks, critical infrastructure risks, and regulatory challenges, 2026."},{"key":"10.1016\/j.cosrev.2026.100914_bib0590","series-title":"2021 Reconciling Data Analytics, Automation, Privacy, and Security: A Big Data Challenge (RDAAPS)","first-page":"1","article-title":"Entroplyzer: android malware classification and characterization using entropy analysis of dynamic characteristics","author":"Keyes","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100914_bib0595","author":"Khormali"},{"key":"10.1016\/j.cosrev.2026.100914_bib0600","doi-asserted-by":"crossref","first-page":"22889","DOI":"10.1109\/ACCESS.2023.3253770","article-title":"Attention-based cross-modal cnn using non-disassembled files for malware classification","volume":"11","author":"Kim","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib0605","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102501","article-title":"Obfuscated malware detection using deep generative model based on global\/local features","volume":"112","author":"Kim","year":"2022","journal-title":"Comput. & Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0610","author":"Kingma"},{"key":"10.1016\/j.cosrev.2026.100914_bib0615","series-title":"2016 10th international conference on intelligent systems and control (ISCO)","first-page":"1","article-title":"Machine learning based malware classification for android applications using multimodal image representations","author":"Kumar","year":"2016"},{"key":"10.1016\/j.cosrev.2026.100914_bib0620","series-title":"2019 10th International Conference on Computing, Communication and Networking Technologies (ICCCNT)","first-page":"1","article-title":"Texture-based malware family classification","author":"Kumar","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0625","series-title":"Proceedings of the 2018 International Conference on Computing and Artificial Intelligence, ICCAI 2018","first-page":"81","article-title":"Malicious code detection based on image processing using deep learning","author":"Kumar","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib0630","article-title":"Dtmic: Deep transfer learning for malware image classification","volume":"64","author":"Kumar","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0635","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.118073","article-title":"Identification of malware families using stacking of textural features and machine learning","volume":"208","author":"Kumar","year":"2022","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0640","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.comcom.2023.12.036","article-title":"Imcnn: Intelligent malware classification using deep convolution neural networks as transfer learning and ensemble learning in honeypot enabled organizational network","volume":"216","author":"Kumar","year":"2024","journal-title":"Comput. Commun."},{"key":"10.1016\/j.cosrev.2026.100914_bib0645","unstructured":"Malicia Lab, Avclass, 2026, https:\/\/github.com\/malicialab\/avclass"},{"issue":"6","key":"10.1016\/j.cosrev.2026.100914_bib0650","first-page":"30","article-title":"Malware classification with improved convolutional neural network model","volume":"12","author":"Lad","year":"2020","journal-title":"Int. J. Comput. Netw. Inf. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0655","doi-asserted-by":"crossref","first-page":"S118","DOI":"10.1016\/j.diin.2018.04.024","article-title":"Deep learning at the shallow end: Malware classification for non-domain experts","volume":"26","author":"Le","year":"2018","journal-title":"Digit. Investig."},{"key":"10.1016\/j.cosrev.2026.100914_bib0660","doi-asserted-by":"crossref","first-page":"18855","DOI":"10.1109\/ACCESS.2023.3247344","article-title":"Robust iot malware detection and classification using opcode category features on machine learning","volume":"11","author":"Lee","year":"2023","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib0665","doi-asserted-by":"crossref","first-page":"144786","DOI":"10.1109\/ACCESS.2021.3122083","article-title":"A classification system for visualized malware based on multiple autoencoder models","volume":"9","author":"Lee","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib0670","series-title":"15th International Conference on Software Technologies","first-page":"606","article-title":"A novel approach for android malware detection and classification using convolutional neural networks","author":"Lekssays","year":"2020"},{"issue":"5","key":"10.1016\/j.cosrev.2026.100914_bib0675","doi-asserted-by":"crossref","first-page":"3357","DOI":"10.1109\/TDSC.2021.3094824","article-title":"Backdoor attack on machine learning based android malware detectors","volume":"19","author":"Li","year":"2021","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"23","key":"10.1016\/j.cosrev.2026.100914_bib0680","doi-asserted-by":"crossref","first-page":"16946","DOI":"10.1109\/JIOT.2021.3075694","article-title":"Cnn-based malware variants detection method for internet of things","volume":"8","author":"Li","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.cosrev.2026.100914_bib0685","author":"Lin"},{"key":"10.1016\/j.cosrev.2026.100914_bib0690","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103134","article-title":"Adversarial attacks against windows pe malware detection: A survey of the state-of-the-art","volume":"128","author":"Ling","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0695","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2019.101682","article-title":"A novel method for malware detection on ml-based visualization technique","volume":"89","author":"Liu","year":"2020","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0700","series-title":"Proceedings of the International Symposium on Quality of Service","first-page":"1","article-title":"Atmpa: attacking machine learning-based malware visualization detection methods via adversarial examples","author":"Liu","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0705","doi-asserted-by":"crossref","first-page":"13015","DOI":"10.1109\/ACCESS.2019.2892500","article-title":"A new learning approach to malware classification using discriminative feature extraction","volume":"7","author":"Liu","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib0710","series-title":"Proceedings of the Seventh IEEE International Conference on Computer vision","first-page":"1150","article-title":"Object recognition from local scale-invariant features","volume":"vol. 2","author":"Lowe","year":"1999"},{"key":"10.1016\/j.cosrev.2026.100914_bib0715","series-title":"2019 Winter Simulation Conference (WSC)","first-page":"584","article-title":"Generative adversarial network for improving deep learning based malware classification","author":"Lu","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0720","series-title":"2017 IEEE International Conference on Big Data (Big Data)","first-page":"4664","article-title":"Binary malware image classification using machine learning with local binary pattern","author":"Luo","year":"2017"},{"key":"10.1016\/j.cosrev.2026.100914_bib0725","article-title":"A survey on visualization-based malware detection","volume":"4","author":"Ahmad","year":"2022","journal-title":"J. Cyber Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0730","article-title":"A comprehensive survey on deep learning based malware detection techniques","volume":"47","author":"Gopinath","year":"2023","journal-title":"Comput. Sci. Rev."},{"key":"10.1016\/j.cosrev.2026.100914_bib0735","series-title":"2022 International Conference on Networking and Network Applications (NaNA)","first-page":"247","article-title":"Visualizable malware detection based on multi-dimension dynamic behaviors","author":"Ma","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0740","doi-asserted-by":"crossref","first-page":"228818","DOI":"10.1109\/ACCESS.2020.3044277","article-title":"Stochastic modeling of iot botnet spread: A short survey on mobile malware spread modeling","volume":"8","author":"Mahboubi","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib0745","series-title":"2015 International conference on trends in automation, communications and computing technology (I-TACT-15)","first-page":"1","article-title":"Malware analysis and classification using artificial neural network","author":"Makandar","year":"2015"},{"key":"10.1016\/j.cosrev.2026.100914_bib0750","doi-asserted-by":"crossref","first-page":"297","DOI":"10.1007\/s11416-022-00416-3","article-title":"Conrec: malware classification using convolutional recurrence","volume":"18","author":"Mallik","year":"2022","journal-title":"J. Comput. Virol. Hack. Tech."},{"key":"10.1016\/j.cosrev.2026.100914_bib0755","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.future.2021.11.030","article-title":"A study on malicious software behaviour analysis and detection techniques: Taxonomy, current trends and challenges","volume":"130","author":"Maniriho","year":"2022","journal-title":"Futur. Gener. Comput. Syst."},{"key":"10.1016\/j.cosrev.2026.100914_bib0760","series-title":"Intelligent Computing","first-page":"1269","article-title":"Explainable artificial intelligence applications in nlp, biomedical, and malware classification: A literature review","author":"Mathews","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0765","doi-asserted-by":"crossref","first-page":"2915","DOI":"10.1109\/TIFS.2025.3547301","article-title":"Detecting android malware by visualizing app behaviors from multiple complementary views","volume":"20","author":"Meng","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0770","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1007\/s11416-019-00346-7","article-title":"Deep learning for image-based mobile malware detection","volume":"16","author":"Mercaldo","year":"2020","journal-title":"J. Comput. Virol. Hack. Tech."},{"key":"10.1016\/j.cosrev.2026.100914_bib0775","author":"Mikolov"},{"key":"10.1016\/j.cosrev.2026.100914_bib0780","author":"Mohammed"},{"key":"10.1016\/j.cosrev.2026.100914_bib0785","series-title":"MILCOM 2022-2022 IEEE Military Communications Conference (MILCOM)","first-page":"279","article-title":"Malgrid: Visualization of binary features in large malware corpora","author":"Mohammed","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0790","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"2574","article-title":"Deepfool: a simple and accurate method to fool deep neural networks","author":"Moosavi-Dezfooli","year":"2016"},{"key":"10.1016\/j.cosrev.2026.100914_bib0795","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103265","article-title":"Improving ransomware detection based on portable executable header using xception convolutional neural network","volume":"130","author":"Moreira","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0800","doi-asserted-by":"crossref","DOI":"10.1155\/2022\/7671967","article-title":"Explainable artificial Intelligence-Based IoT device malware detection mechanism using image visualization and Fine-Tuned CNN-Based transfer learning model","volume":"2022","author":"Naeem","year":"2022","journal-title":"Comput. Intell. Neurosci."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100914_bib0805","article-title":"Android device malware classification framework using multistep image feature extraction and multihead deep neural ensemble","volume":"39","author":"Naeem","year":"2022","journal-title":"Trait. du Signal"},{"key":"10.1016\/j.cosrev.2026.100914_bib0810","doi-asserted-by":"crossref","first-page":"225","DOI":"10.1016\/j.compeleceng.2019.03.015","article-title":"Identification of malicious code variants based on image visualization","volume":"76","author":"Naeem","year":"2019","journal-title":"Comput. Electr. Eng."},{"issue":"6","key":"10.1016\/j.cosrev.2026.100914_bib0815","first-page":"73","article-title":"Visual malware classification using local and global malicious pattern","volume":"30","author":"Naeem","year":"2019","journal-title":"J. Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib0820","doi-asserted-by":"crossref","DOI":"10.1016\/j.adhoc.2020.102154","article-title":"Malware detection in industrial internet of things based on hybrid image visualization and deep learning model","volume":"105","author":"Naeem","year":"2020","journal-title":"Ad Hoc Netw."},{"key":"10.1016\/j.cosrev.2026.100914_bib0825","series-title":"2021 5th International Conference on Electrical, Electronics, Communication, Computer Technologies and Optimization Techniques (ICEECCOT)","first-page":"111","article-title":"Malware classification approaches using machine learning techniques: A review","author":"Naik","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100914_bib0830","article-title":"The malicia dataset: identification and analysis of drive-by download operations","volume":"14","author":"Nappa","year":"2014","journal-title":"Int. J. Inf. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0835","series-title":"Proceedings of the 8th international symposium on visualization for cyber security","first-page":"1","article-title":"Malware images: visualization and automatic classification","author":"Nataraj","year":"2011"},{"key":"10.1016\/j.cosrev.2026.100914_bib0840","series-title":"Proceedings of the 4th ACM Workshop on Security and Artificial Intelligence","first-page":"21","article-title":"A comparative assessment of malware classification using binary texture analysis and dynamic analysis","author":"Nataraj","year":"2011"},{"issue":"4","key":"10.1016\/j.cosrev.2026.100914_bib0845","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1016\/j.icte.2020.04.005","article-title":"A survey of iot malware and detection methods based on static features","volume":"6","author":"Ngo","year":"2020","journal-title":"ICT Express"},{"key":"10.1016\/j.cosrev.2026.100914_bib0850","doi-asserted-by":"crossref","first-page":"871","DOI":"10.1016\/j.cose.2018.04.005","article-title":"Malware identification using visualization images and deep learning","volume":"77","author":"Ni","year":"2018","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0855","series-title":"Proceedings of 12th international conference on pattern recognition","first-page":"582","article-title":"Performance evaluation of texture measures with classification based on kullback discrimination of distributions","volume":"vol. 1","author":"Ojala","year":"1994"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib0860","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1016\/0031-3203(95)00067-4","article-title":"A comparative study of texture measures with classification based on featured distributions","volume":"29","author":"Ojala","year":"1996","journal-title":"Pattern Recognit."},{"issue":"3","key":"10.1016\/j.cosrev.2026.100914_bib0865","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1023\/A:1011139631724","article-title":"Modeling the shape of the scene: A holistic representation of the spatial envelope","volume":"42","author":"Oliva","year":"2001","journal-title":"Int. J. Comput. Vis."},{"key":"10.1016\/j.cosrev.2026.100914_bib0870","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102660","article-title":"Image-based malware classification hybrid framework based on space-filling curves","volume":"116","author":"O\u2019Shaughnessy","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0875","series-title":"2022 IEEE Congress on Evolutionary Computation (CEC)","first-page":"1","article-title":"Designing deep convolutional neural networks using a genetic algorithm for image-based malware classification","author":"Paardekooper","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0880","series-title":"2016 IEEE European symposium on security and privacy (EuroS&P)","first-page":"372","article-title":"The limitations of deep learning in adversarial settings","author":"Papernot","year":"2016"},{"key":"10.1016\/j.cosrev.2026.100914_bib0885","series-title":"2019 18th IEEE International Conference On Machine Learning And Applications (ICMLA)","first-page":"1283","article-title":"Generation & evaluation of adversarial examples for malware obfuscation","author":"Park","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0890","series-title":"Advances in Neural Information Processing Systems 32","first-page":"8024","article-title":"Pytorch: An imperative style, high-performance deep learning library","author":"Paszke","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0895","series-title":"2022 International Wireless Communications and Mobile Computing (IWCMC)","first-page":"278","article-title":"Deep learning and blockchain-based framework to detect malware in autonomous vehicles","author":"Patel","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0900","first-page":"2825","article-title":"Scikit-learn: Machine learning in Python","volume":"12","author":"Pedregosa","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"10.1016\/j.cosrev.2026.100914_bib0905","series-title":"proceedings of the 26th Symposium on Operating Systems Principles","first-page":"1","article-title":"Deepxplore: Automated whitebox testing of deep learning systems","author":"Pei","year":"2017"},{"key":"10.1016\/j.cosrev.2026.100914_bib0910","series-title":"2020 IEEE Symposium on Security and Privacy (SP)","first-page":"1332","article-title":"Intriguing properties of adversarial ML attacks in the problem space","author":"Pierazzi","year":"2020"},{"key":"10.1016\/j.cosrev.2026.100914_bib0915","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102247","article-title":"Malware detection employed by visualization and deep neural network","volume":"105","author":"Pinhero","year":"2021","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0920","series-title":"2022 International Conference on Advanced Computer Science and Information Systems (ICACSIS)","first-page":"75","article-title":"Malware classification and visualization using efficientnet and b2img algorithm","author":"Pratama","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0925","doi-asserted-by":"crossref","first-page":"16277","DOI":"10.1109\/TITS.2024.3433480","article-title":"A blockchain-powered malicious node detection in internet of autonomous vehicles","volume":"25","author":"Prathiba","year":"2024","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"10.1016\/j.cosrev.2026.100914_bib0930","series-title":"2019 18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications\/13th IEEE International Conference On Big Data Science And Engineering (TrustCom\/BigDataSE)","first-page":"757","article-title":"A multi-channel visualization method for malware classification based on deep learning","author":"Qiao","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib0935","series-title":"2022 3rd International Conference on Computer Vision, Image and Deep Learning & International Conference on Computer Engineering and Applications (CVIDL & ICCEA)","first-page":"1047","article-title":"Malware classification based on a light-weight architecture of cnn: Malshufflenet","author":"Qiu","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib0940","author":"Raff"},{"issue":"5s","key":"10.1016\/j.cosrev.2026.100914_bib0945","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3609112","article-title":"Vit4mal: Lightweight vision transformer for malware detection on edge devices","volume":"22","author":"Ravi","year":"2023","journal-title":"ACM Trans. Embed. Comput. Syst."},{"key":"10.1016\/j.cosrev.2026.100914_bib0950","doi-asserted-by":"crossref","first-page":"24891","DOI":"10.1007\/s11042-022-14236-6","article-title":"Efficientnet deep learning meta-classifier approach for image-based android malware detection","volume":"82","author":"Ravi","year":"2023","journal-title":"Multimed. Tools Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib0955","unstructured":"J. Reiser, MS Windows NT kernel description, 2026, https:\/\/github.com\/upx\/upx"},{"key":"10.1016\/j.cosrev.2026.100914_bib0960","doi-asserted-by":"crossref","DOI":"10.1016\/j.adhoc.2020.102098","article-title":"End-to-end malware detection for android iot devices using deep learning","volume":"101","author":"Ren","year":"2020","journal-title":"Ad Hoc Netw."},{"issue":"4","key":"10.1016\/j.cosrev.2026.100914_bib0965","doi-asserted-by":"crossref","first-page":"639","DOI":"10.3233\/JCS-2010-0410","article-title":"Automatic analysis of malware behavior using machine learning","volume":"19","author":"Rieck","year":"2011","journal-title":"J. Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib0970","author":"Ronen"},{"key":"10.1016\/j.cosrev.2026.100914_bib0975","series-title":"2021 International Joint Conference on Neural Networks (IJCNN)","first-page":"1","article-title":"Umvd-fsl: unseen malware variants detection using few-shot learning","author":"Rong","year":"2021"},{"key":"10.1016\/j.cosrev.2026.100914_bib0980","doi-asserted-by":"crossref","first-page":"206303","DOI":"10.1109\/ACCESS.2020.3036491","article-title":"Intelligent vision-based malware detection and classification using deep random forest paradigm","volume":"8","author":"Roseline","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib0985","series-title":"2019 International Carnahan Conference on Security Technology (ICCST)","first-page":"1","article-title":"Towards efficient malware detection and classification using multilayered random forest ensemble technique","author":"Roseline","year":"2019"},{"issue":"5","key":"10.1016\/j.cosrev.2026.100914_bib0990","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3453158","article-title":"Adversarial machine learning attacks and defense methods in the cyber security domain","volume":"54","author":"Rosenberg","year":"2021","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.cosrev.2026.100914_bib0995","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1016\/j.jpdc.2022.10.001","article-title":"Malware detection using image representation of malware data and transfer learning","volume":"172","author":"Rustam","year":"2023","journal-title":"J. Parallel Distrib. Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib1000","series-title":"2015 10th international conference on malicious and unwanted software (MALWARE)","first-page":"11","article-title":"Deep neural network based malware detection using two dimensional binary program features","author":"Saxe","year":"2015"},{"key":"10.1016\/j.cosrev.2026.100914_bib1005","series-title":"30th USENIX security symposium (USENIX security 21)","first-page":"1487","article-title":"{Explanation-Guided} backdoor poisoning attacks against malware classifiers","author":"Severi","year":"2021"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib1010","doi-asserted-by":"crossref","first-page":"16","DOI":"10.1016\/j.istr.2009.03.003","article-title":"Detection of malicious code by applying machine learning classifiers on static features: A state-of-the-art survey","volume":"14","author":"Shabtai","year":"2009","journal-title":"Inf. Secur. Tech. Rep."},{"key":"10.1016\/j.cosrev.2026.100914_bib1015","series-title":"2022 17th International Conference on Emerging Technologies (ICET)","first-page":"200","article-title":"Performance comparison of visualization-based malware detection and classification techniques","author":"Shah","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib1020","series-title":"2014 International Symposium on Biometrics and Security Technologies (ISBAST)","first-page":"238","article-title":"Malware behavior image for malware variant identification","author":"Shaid","year":"2014"},{"key":"10.1016\/j.cosrev.2026.100914_bib1025","doi-asserted-by":"crossref","first-page":"379","DOI":"10.1002\/j.1538-7305.1948.tb01338.x","article-title":"A mathematical theory of communication","volume":"27","author":"Shannon","year":"1948","journal-title":"Bell Syst. Tech. J."},{"key":"10.1016\/j.cosrev.2026.100914_bib1030","first-page":"1","article-title":"Windows and iot malware visualization and classification with deep cnn and xception cnn using markov images","volume":"60","author":"Sharma","year":"2022","journal-title":"J. Intell. Inf. Syst."},{"key":"10.1016\/j.cosrev.2026.100914_bib1035","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.122678","article-title":"Migan: Gan for facilitating malware image synthesis with improved malware classification on novel dataset","volume":"241","author":"Sharma","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib1040","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2023.106030","article-title":"A novel deep learning-based approach for malware detection","volume":"122","author":"Shaukat","year":"2023","journal-title":"Eng. Appl. Artif. Intell."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib1045","doi-asserted-by":"crossref","first-page":"683","DOI":"10.1007\/s10489-022-03523-2","article-title":"Self-attention based convolutional-lstm for android malware detection using network traffics grayscale image","volume":"53","author":"Shen","year":"2023","journal-title":"Applied Intelligence"},{"key":"10.1016\/j.cosrev.2026.100914_bib1050","doi-asserted-by":"crossref","first-page":"90102","DOI":"10.1109\/ACCESS.2021.3090998","article-title":"Classification and analysis of android malware images using feature fusion technique","volume":"9","author":"Singh","year":"2021","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib1055","series-title":"2017 5th International Symposium on Computational and Business Intelligence (ISCBI)","first-page":"20","article-title":"Glcm and its application in pattern recognition","author":"Singh","year":"2017"},{"key":"10.1016\/j.cosrev.2026.100914_bib1060","unstructured":"H. Sistemas, Virus total, 2026, https:\/\/www.virustotal.com"},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib1065","doi-asserted-by":"crossref","first-page":"1057","DOI":"10.1109\/TETC.2019.2910086","article-title":"Windows malware detector using convolutional neural network based on visualization images","volume":"9","author":"Shiva Darshan","year":"2021","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib1070","article-title":"Learning structured output representation using deep conditional generative models","volume":"28","author":"Sohn","year":"2015","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.cosrev.2026.100914_bib1075","series-title":"2019 42nd International Convention on Information and Communication Technology, Electronics and Microelectronics (MIPRO)","first-page":"977","article-title":"An overview and comparison of free python libraries for data mining and big data analysis","author":"Stan\u010din","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib1080","series-title":"2018 IEEE 42nd Annual Computer Software and Applications Conference (COMPSAC)","first-page":"664","article-title":"Lightweight classification of iot malware based on image recognition","volume":"vol. 2","author":"Su","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib1085","series-title":"2019 IEEE Security and Privacy Workshops (SPW)","first-page":"8","article-title":"Exploring adversarial examples in malware detection","author":"Suciu","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib1090","doi-asserted-by":"crossref","first-page":"334","DOI":"10.1016\/j.future.2021.06.029","article-title":"Mcft-cnn: Malware classification with fine-tune convolution neural networks using traditional and transfer learning in internet of things","volume":"125","author":"Kumar","year":"2021","journal-title":"Futur. Gener. Comput. Syst."},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib1095","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1109\/TDSC.2018.2884928","article-title":"Deep learning and visualization for identifying malware families","volume":"18","author":"Sun","year":"2021","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib1100","series-title":"Proceedings of the 8th ACM Conference on Security & Privacy in Wireless and Mobile Networks","first-page":"1","article-title":"Droideagle: Seamless detection of visually similar android apps","author":"Sun","year":"2015"},{"key":"10.1016\/j.cosrev.2026.100914_bib1105","author":"Szegedy"},{"key":"10.1016\/j.cosrev.2026.100914_bib1110","article-title":"Efficientnet: Rethinking model scaling for convolutional neural networks","volume":"abs\/1905.11946","author":"Tan","year":"2019","journal-title":"CoRR"},{"key":"10.1016\/j.cosrev.2026.100914_bib1115","doi-asserted-by":"crossref","DOI":"10.1049\/iet-ifs.2018.5268","article-title":"Dynamic api call sequence visualization for malware classification","author":"Tang","year":"2019","journal-title":"IET Inf. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1120","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102515","article-title":"A novel malware classification and augmentation model based on convolutional neural network","volume":"112","author":"Tekerek","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1125","unstructured":"V. Total, Virus total global statistics, 2026, https:\/\/www.virustotal.com\/gui\/stats"},{"key":"10.1016\/j.cosrev.2026.100914_bib1130","doi-asserted-by":"crossref","first-page":"27815","DOI":"10.1007\/s11042-020-09376-6","article-title":"Automated malware recognition method based on local neighborhood binary pattern","volume":"79","author":"Tuncer","year":"2020","journal-title":"Multimed. Tools Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib1135","doi-asserted-by":"crossref","first-page":"123","DOI":"10.1016\/j.cose.2018.11.001","article-title":"Survey of machine learning techniques for malware analysis","volume":"81","author":"Ucci","year":"2019","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1140","article-title":"Image processing in python","volume":"23","author":"Umesh","year":"2012","journal-title":"CSI Commun."},{"key":"10.1016\/j.cosrev.2026.100914_bib1145","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s42452-020-3132-2","article-title":"Android malware detection based on image-based features and machine learning techniques","volume":"2","author":"\u00dcnver","year":"2020","journal-title":"SN Appl. Sci."},{"key":"10.1016\/j.cosrev.2026.100914_bib1150","doi-asserted-by":"crossref","first-page":"85127","DOI":"10.1109\/ACCESS.2022.3198072","article-title":"An attention mechanism for combination of cnn and vae for image-based malware classification","volume":"10","author":"Van Dao","year":"2022","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib1155","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2020.107138","article-title":"Imcfn: Image-based malware classification using fine-tuned convolutional neural network architecture","volume":"171","author":"Vasan","year":"2020","journal-title":"Comput. Netw."},{"key":"10.1016\/j.cosrev.2026.100914_bib1160","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.101748","article-title":"Image-based malware classification using ensemble of cnn architectures (imcec)","volume":"92","author":"Vasan","year":"2020","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1165","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2024.111401","article-title":"Broad learning: A gpu-free image-based malware classification","volume":"154","author":"Vasan","year":"2024","journal-title":"Appl. Soft Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib1170","article-title":"Attention is all you need","volume":"30","author":"Vaswani","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.cosrev.2026.100914_bib1175","first-page":"377","article-title":"A hybrid deep learning image-based analysis for effective malware detection","volume":"47","author":"Venkatraman","year":"2019","journal-title":"J. Inf. Secur. Appl."},{"key":"10.1016\/j.cosrev.2026.100914_bib1180","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.101895","article-title":"Multiclass malware classification via first-and second-order texture statistics","volume":"97","author":"Verma","year":"2020","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1185","doi-asserted-by":"crossref","first-page":"46717","DOI":"10.1109\/ACCESS.2019.2906934","article-title":"Robust intelligent malware detection using deep learning","volume":"7","author":"Vinayakumar","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib1190","series-title":"Big Data in Engineering Applications","first-page":"113","article-title":"Scalable framework for cyber threat situational awareness based on domain name systems data analysis","author":"Vinayakumar","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib1195","unstructured":"VirusTotal, Yara rules, 2026, https:\/\/virustotal.github.io\/yara"},{"key":"10.1016\/j.cosrev.2026.100914_bib1200","series-title":"A Practical Guide","first-page":"10","article-title":"The eu general data protection regulation (gdpr)","volume":"vol. 10","author":"Voigt","year":"2017"},{"issue":"11","key":"10.1016\/j.cosrev.2026.100914_bib1205","article-title":"Hit4mal: Hybrid image transformation for malware classification","volume":"31","author":"Vu","year":"2020","journal-title":"Trans. Emerg. Telecommun. Technol."},{"key":"10.1016\/j.cosrev.2026.100914_bib1210","series-title":"Proceedings of the 3rd International Conference on Advanced Information Science and System, AISS \u201921","article-title":"Image-based ransomware classification with classifier combination","author":"Wang","year":"2022"},{"key":"10.1016\/j.cosrev.2026.100914_bib1215","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102273","article-title":"A novel few-shot malware classification approach for unknown family recognition with multi-prototype modeling","volume":"106","author":"Wang","year":"2021","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1220","first-page":"5","article-title":"11 adversarial perturbations of deep neural networks","volume":"311","author":"Warde-Farley","year":"2016","journal-title":"Perturb. Optim. Stat."},{"key":"10.1016\/j.cosrev.2026.100914_bib1225","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2024.110039","article-title":"Cnn-vit synergy: An efficient android malware detection approach through deep learning","volume":"123","author":"Wasif","year":"2025","journal-title":"Comput. Electr. Eng."},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib1230","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3423096","article-title":"Why an android app is classified as malware: Toward malware classification interpretation","volume":"30","author":"Wu","year":"2021","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"10.1016\/j.cosrev.2026.100914_bib1235","series-title":"Data Science: Third International Conference of Pioneering Computer Scientists, Engineers and Educators, ICPCSEE 2017, Changsha, China, September 22\u201324, 2017, Proceedings, Part I","first-page":"262","article-title":"Android malware detection using local binary pattern and principal component analysis","author":"Wu","year":"2017"},{"key":"10.1016\/j.cosrev.2026.100914_bib1240","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1016\/j.jpdc.2020.03.012","article-title":"Malfcs: An effective malware classification framework with automated feature extraction based on deep convolutional neural networks","volume":"141","author":"Xiao","year":"2020","journal-title":"J. Parallel Distrib. Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib1245","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102420","article-title":"Image-based malware classification using section distribution information","volume":"110","author":"Xiao","year":"2021","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1250","series-title":"2019 34th IEEE\/ACM International Conference on Automated Software Engineering (ASE)","first-page":"1259","article-title":"An image-inspired and cnn-based android malware detection approach","author":"Xiao","year":"2019"},{"key":"10.1016\/j.cosrev.2026.100914_bib1255","author":"Xu"},{"key":"10.1016\/j.cosrev.2026.100914_bib1260","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103734","article-title":"Bitcn-taefficientnet malware classification approach based on sequence and rgb fusion","volume":"139","author":"Xuan","year":"2024","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1265","series-title":"Icissp","first-page":"553","article-title":"Deep learning versus gist descriptors for image-based malware classification","author":"Yajamanam","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib1270","series-title":"Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy, CODASPY \u201918","first-page":"127","article-title":"Malware analysis of imaged binary samples by convolutional neural network with attention mechanism","author":"Yakura","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib1275","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2019.101592","article-title":"Neural malware analysis with attention mechanism","volume":"87","author":"Yakura","year":"2019","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1280","series-title":"2019 49th annual IEEE\/IFIP international conference on dependable systems and networks (DSN)","first-page":"52","article-title":"Classifying malware represented as control flow graphs using deep graph convolutional neural network","author":"Yan","year":"2019"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib1285","doi-asserted-by":"crossref","first-page":"467","DOI":"10.1109\/COMST.2022.3225137","article-title":"A survey of adversarial attack and defense methods for malware classification in cyber security","volume":"25","author":"Yan","year":"2022","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"10.1016\/j.cosrev.2026.100914_bib1290","series-title":"Proceedings of the 1st Workshop on Security-Oriented Designs of Computer Architectures and Processors, SecArch\u201918","first-page":"15","article-title":"A convolutional neural network based classifier for uncompressed malware samples","author":"Yang","year":"2018"},{"key":"10.1016\/j.cosrev.2026.100914_bib1295","doi-asserted-by":"crossref","first-page":"148853","DOI":"10.1109\/ACCESS.2019.2946482","article-title":"A novel solutions for malicious code detection and family clustering based on machine learning","volume":"7","author":"Yang","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.cosrev.2026.100914_bib1300","doi-asserted-by":"crossref","DOI":"10.1016\/j.neucom.2025.130053","article-title":"Sac: Collaborative learning of structure and content features for android malware detection framework","volume":"637","author":"Yang","year":"2025","journal-title":"Neurocomputing"},{"key":"10.1016\/j.cosrev.2026.100914_bib1305","series-title":"2023 IEEE Symposium on Security and Privacy (SP)","first-page":"719","article-title":"Jigsaw puzzle: Selective backdoor attack to subvert malware classifiers","author":"Yang","year":"2023"},{"key":"10.1016\/j.cosrev.2026.100914_bib1310","doi-asserted-by":"crossref","DOI":"10.1109\/TCSS.2025.3545112","article-title":"A variant-sensitive malware detection method based on feature contrast enhancement","volume":"12","author":"Yang","year":"2025","journal-title":"IEEE Trans. Comput. Soc. Syst."},{"key":"10.1016\/j.cosrev.2026.100914_bib1315","series-title":"2010 International conference on broadband, wireless computing, communication and applications","first-page":"297","article-title":"Malware obfuscation techniques: A brief survey","author":"You","year":"2010"},{"issue":"1","key":"10.1016\/j.cosrev.2026.100914_bib1320","doi-asserted-by":"crossref","first-page":"7997","DOI":"10.1038\/s41598-025-88130-0","article-title":"Semantic lossless encoded image representation for malware classification","volume":"15","author":"Yu","year":"2025","journal-title":"Sci. Rep."},{"key":"10.1016\/j.cosrev.2026.100914_bib1325","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.101740","article-title":"Byte-level malware classification based on markov images and deep learning","volume":"92","author":"Yuan","year":"2020","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1330","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103103","article-title":"Amgmal: Adaptive mask-guided adversarial attack against malware detection with minimal perturbation","volume":"127","author":"Zhan","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1335","doi-asserted-by":"crossref","first-page":"5431","DOI":"10.1109\/TDSC.2025.3566708","article-title":"Game-rl: Generating adversarial malware examples against api call based detection via reinforcement learning","volume":"22","author":"Zhan","year":"2025","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib1340","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104280","article-title":"Practical clean-label backdoor attack against static malware detection","volume":"150","author":"Zhan","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.cosrev.2026.100914_bib1345","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1016\/j.aej.2024.10.055","article-title":"Imcmk-cnn: A lightweight convolutional neural network with multi-scale kernels for image-based malware classification","volume":"111","author":"Zhang","year":"2025","journal-title":"Alex. Eng. J."},{"issue":"7","key":"10.1016\/j.cosrev.2026.100914_bib1350","doi-asserted-by":"crossref","first-page":"1107","DOI":"10.3390\/sym13071107","article-title":"Android malware detection using tcn with bytecode image","volume":"13","author":"Zhang","year":"2021","journal-title":"Symmetry"},{"issue":"3","key":"10.1016\/j.cosrev.2026.100914_bib1355","doi-asserted-by":"crossref","first-page":"1838","DOI":"10.1109\/COMST.2021.3086475","article-title":"A review of computer vision methods in network security","volume":"23","author":"Zhao","year":"2021","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"10.1016\/j.cosrev.2026.100914_bib1360","doi-asserted-by":"crossref","first-page":"166630","DOI":"10.1109\/ACCESS.2020.3022722","article-title":"A malware detection method of code texture visualization based on an improved faster rcnn combining transfer learning","volume":"8","author":"Zhao","year":"2020","journal-title":"IEEE Access"},{"issue":"2","key":"10.1016\/j.cosrev.2026.100914_bib1365","doi-asserted-by":"crossref","first-page":"438","DOI":"10.1109\/TC.2022.3160357","article-title":"Malware-on-the-brain: Illuminating malware byte codes with images for malware classification","volume":"72","author":"Zhong","year":"2022","journal-title":"IEEE Trans. Comput."},{"key":"10.1016\/j.cosrev.2026.100914_bib1370","series-title":"2012 IEEE symposium on security and privacy","first-page":"95","article-title":"Dissecting android malware: Characterization and evolution","author":"Zhou","year":"2012"},{"key":"10.1016\/j.cosrev.2026.100914_bib1375","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102691","article-title":"A few-shot meta-learning based siamese neural network using entropy features for ransomware classification","volume":"117","author":"Zhu","year":"2022","journal-title":"Comput. Secur."}],"container-title":["Computer Science Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1574013726000237?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1574013726000237?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T07:24:36Z","timestamp":1777620276000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S1574013726000237"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":275,"alternative-id":["S1574013726000237"],"URL":"https:\/\/doi.org\/10.1016\/j.cosrev.2026.100914","relation":{},"ISSN":["1574-0137"],"issn-type":[{"value":"1574-0137","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Security through the eyes of AI: How visualization is shaping malware detection","name":"articletitle","label":"Article Title"},{"value":"Computer Science Review","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.cosrev.2026.100914","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Author(s). Published by Elsevier Inc.","name":"copyright","label":"Copyright"}],"article-number":"100914"}}