{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T20:09:29Z","timestamp":1784059769347,"version":"3.55.0"},"reference-count":56,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,10,1]],"date-time":"2026-10-01T00:00:00Z","timestamp":1790812800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100008308","name":"Xuchang University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100008308","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003459","name":"Guizhou University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003459","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Engineering Applications of Artificial Intelligence"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1016\/j.engappai.2026.115559","type":"journal-article","created":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T16:10:03Z","timestamp":1783959003000},"page":"115559","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"P5","title":["A lightweight malware classification method based on short bit sequence visualization"],"prefix":"10.1016","volume":"181","author":[{"given":"Junyu","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chun","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guowei","family":"Shen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuan","family":"Ping","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunhe","family":"Cui","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yi","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.engappai.2026.115559_b1","series-title":"2020 IEEE 6th Intl Conference on Big Data Security on Cloud (BigDataSecurity), IEEE Intl Conference on High Performance and Smart Computing,(HPSC) and IEEE Intl Conference on Intelligent Data and Security","first-page":"231","article-title":"Detection efficiency of static analyzers against obfuscated android malware","author":"Ajiri","year":"2020"},{"key":"10.1016\/j.engappai.2026.115559_b2","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.101760","article-title":"A dynamic Windows malware detection and prediction method based on contextual understanding of API call sequence","volume":"92","author":"Amer","year":"2020","journal-title":"Comput. Secur."},{"key":"10.1016\/j.engappai.2026.115559_b3","series-title":"Malware Analysis Techniques: Tricks for the Triage of Adversarial Software","author":"Barker","year":"2021"},{"key":"10.1016\/j.engappai.2026.115559_b4","series-title":"2015 IEEE Conference on Communications and Network Security","first-page":"134","article-title":"Unknown malware detection using network traffic classification","author":"Bekerman","year":"2015"},{"key":"10.1016\/j.engappai.2026.115559_b5","doi-asserted-by":"crossref","unstructured":"Berlin, K., Slater, D., Saxe, J., 2015. Malicious behavior detection using windows audit logs. In: Proceedings of the 8th ACM Workshop on Artificial Intelligence and Security. pp. 35\u201344.","DOI":"10.1145\/2808769.2808773"},{"key":"10.1016\/j.engappai.2026.115559_b6","series-title":"Pattern Recognition and Machine Learning","author":"Bishop","year":"2006"},{"key":"10.1016\/j.engappai.2026.115559_b7","unstructured":"Blackthorne, J., Bulazel, A., Fasano, A., Biernat, P., Yener, B., 2016. {AVLeak}: fingerprinting antivirus emulators through {Black-Box} testing. In: 10th USENIX Workshop on Offensive Technologies. WOOT 16."},{"key":"10.1016\/j.engappai.2026.115559_b8","series-title":"Pefile","author":"Carrera Ventura","year":"2023"},{"key":"10.1016\/j.engappai.2026.115559_b9","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104397","article-title":"APIARY: An API-based automatic rule generator for yara to enhance malware detection","volume":"153","author":"Coscia","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.engappai.2026.115559_b10","series-title":"Security navigator 2024: Latest cybersecurity threats and trends","author":"Cyberdefense","year":"2024"},{"key":"10.1016\/j.engappai.2026.115559_b11","series-title":"Security navigator 2025: Latest cybersecurity threats and trends","author":"Cyberdefense","year":"2025"},{"key":"10.1016\/j.engappai.2026.115559_b12","doi-asserted-by":"crossref","first-page":"314","DOI":"10.1016\/j.future.2021.06.032","article-title":"Visualization and deep-learning-based malware variant detection using OpCode-level features","volume":"125","author":"Darem","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"10.1016\/j.engappai.2026.115559_b13","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.103084","article-title":"MCTVD: A malware classification method based on three-channel visualization and deep learning","volume":"126","author":"Deng","year":"2023","journal-title":"Comput. Secur."},{"key":"10.1016\/j.engappai.2026.115559_b14","series-title":"2019 IEEE National Aerospace and Electronics Conference","first-page":"226","article-title":"Static analysis through topic modeling and its application to malware programs classification","author":"Djaneye-Boundjou","year":"2019"},{"issue":"2","key":"10.1016\/j.engappai.2026.115559_b15","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2089125.2089126","article-title":"A survey on automated dynamic malware-analysis techniques and tools","volume":"44","author":"Egele","year":"2008","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.engappai.2026.115559_b16","series-title":"2022 5th International Conference on Signal Processing and Information Security","first-page":"26","article-title":"Comparison of feature extraction and classification techniques of PE malware","author":"El Neel","year":"2022"},{"key":"10.1016\/j.engappai.2026.115559_b17","series-title":"Detection of cyber malware attack based on network traffic features using neural network","author":"Engel","year":"2020"},{"key":"10.1016\/j.engappai.2026.115559_b18","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103788","article-title":"DawnGNN: Documentation augmented windows malware detection using graph neural","volume":"140","author":"Feng","year":"2024","journal-title":"Comput. Secur."},{"issue":"3","key":"10.1016\/j.engappai.2026.115559_b19","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1007\/s11416-015-0257-8","article-title":"Combinatorial detection of malware by IAT discrimination","volume":"12","author":"Ferrand","year":"2016","journal-title":"J. Comput. Virol. Hacking Tech."},{"issue":"1","key":"10.1016\/j.engappai.2026.115559_b20","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10207-014-0242-0","article-title":"Malware analysis using visualized images and entropy graphs","volume":"14","author":"Han","year":"2015","journal-title":"Int. J. Inf. Secur."},{"key":"10.1016\/j.engappai.2026.115559_b21","series-title":"2017 IEEE Symposium Series on Computational Intelligence","first-page":"1","article-title":"Malware classification using static analysis based features","author":"Hassen","year":"2017"},{"key":"10.1016\/j.engappai.2026.115559_b22","series-title":"Training compute-optimal large language models","author":"Hoffmann","year":"2022"},{"key":"10.1016\/j.engappai.2026.115559_b23","series-title":"2010 Second Cybercrime and Trustworthy Computing Workshop","first-page":"9","article-title":"Classification of malware based on string and function feature selection","author":"Islam","year":"2010"},{"key":"10.1016\/j.engappai.2026.115559_b24","doi-asserted-by":"crossref","first-page":"2487","DOI":"10.1109\/TIFS.2024.3350379","article-title":"Static multi feature-based malware detection using multi SPP-net in smart IoT environments","volume":"19","author":"Jeon","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.engappai.2026.115559_b25","series-title":"2019 2nd International Conference on Data Intelligence and Security","first-page":"53","article-title":"Malware detection using power consumption and network traffic data","author":"Jimenez","year":"2019"},{"key":"10.1016\/j.engappai.2026.115559_b26","series-title":"2018 9th IFIP International Conference on New Technologies, Mobility and Security","first-page":"1","article-title":"Malware classification with deep convolutional neural networks","author":"Kalash","year":"2018"},{"key":"10.1016\/j.engappai.2026.115559_b27","series-title":"PE format","author":"Karl-Bridge-Microsoft","year":"2024"},{"key":"10.1016\/j.engappai.2026.115559_b28","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2024.108374","article-title":"Image-based malware detection based on convolution neural network with autoencoder in Industrial Internet of Things using Software Defined Networking Honeypot","volume":"133","author":"Kumar","year":"2024","journal-title":"Eng. Appl. Artif. Intell."},{"issue":"1","key":"10.1016\/j.engappai.2026.115559_b29","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1186\/s42400-021-00083-9","article-title":"Hypervisor-assisted dynamic malware analysis","volume":"4","author":"Leon","year":"2021","journal-title":"Cybersecurity"},{"key":"10.1016\/j.engappai.2026.115559_b30","doi-asserted-by":"crossref","first-page":"9038","DOI":"10.1007\/s10489-021-02347-w","article-title":"2-SPIFF: a 2-stage packer identification method based on function call graph and file attributes","volume":"51","author":"Liu","year":"2021","journal-title":"Appl. Intell."},{"key":"10.1016\/j.engappai.2026.115559_b31","doi-asserted-by":"crossref","first-page":"603","DOI":"10.1016\/j.future.2024.03.051","article-title":"An efficient cloud-integrated distributed deep neural network framework for IoT malware classification","volume":"157","author":"Mosleh","year":"2024","journal-title":"Future Gener. Comput. Syst."},{"key":"10.1016\/j.engappai.2026.115559_b32","series-title":"2013 International Conference on Computing, Networking and Communications","first-page":"642","article-title":"Automated malware classification based on network behavior","author":"Nari","year":"2013"},{"key":"10.1016\/j.engappai.2026.115559_b33","doi-asserted-by":"crossref","first-page":"871","DOI":"10.1016\/j.cose.2018.04.005","article-title":"Malware identification using visualization images and deep learning","volume":"77","author":"Ni","year":"2018","journal-title":"Comput. Secur."},{"key":"10.1016\/j.engappai.2026.115559_b34","series-title":"Microsoft malware classification challenge (BIG 2015)","author":"Panconesi","year":"2015"},{"key":"10.1016\/j.engappai.2026.115559_b35","series-title":"A survey of machine learning methods and challenges for windows malware classification","author":"Raff","year":"2020"},{"key":"10.1016\/j.engappai.2026.115559_b36","doi-asserted-by":"crossref","unstructured":"Raff, E., Sylvester, J., Nicholas, C., 2017. Learning the pe header, malware detection with minimal domain knowledge. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. pp. 121\u2013132.","DOI":"10.1145\/3128572.3140442"},{"issue":"1","key":"10.1016\/j.engappai.2026.115559_b37","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s11416-016-0283-1","article-title":"An investigation of byte n-gram features for malware classification","volume":"14","author":"Raff","year":"2018","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"10.1016\/j.engappai.2026.115559_b38","series-title":"2017 16th IEEE International Conference on Machine Learning and Applications","first-page":"1011","article-title":"Malicious software classification using transfer learning of resnet-50 deep neural network","author":"Rezende","year":"2017"},{"key":"10.1016\/j.engappai.2026.115559_b39","doi-asserted-by":"crossref","first-page":"578","DOI":"10.1016\/j.cose.2018.05.010","article-title":"Early-stage malware prediction using recurrent neural networks","volume":"77","author":"Rhode","year":"2018","journal-title":"Comput. Secur."},{"key":"10.1016\/j.engappai.2026.115559_b40","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1016\/j.engappai.2016.12.016","article-title":"MAAR: Robust features to detect malicious activity based on API calls, their arguments and return values","volume":"59","author":"Salehi","year":"2017","journal-title":"Eng. Appl. Artif. Intell."},{"key":"10.1016\/j.engappai.2026.115559_b41","series-title":"Computational Science and Technology: 5th ICCST 2018, Kota Kinabalu, Malaysia, 29-30 August 2018","first-page":"423","article-title":"Malicious software family classification using machine learning multi-class classifiers","author":"San","year":"2018"},{"key":"10.1016\/j.engappai.2026.115559_b42","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2023.106030","article-title":"A novel deep learning-based approach for malware detection","volume":"122","author":"Shaukat","year":"2023","journal-title":"Eng. Appl. Artif. Intell."},{"key":"10.1016\/j.engappai.2026.115559_b43","series-title":"Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software","author":"Sikorski","year":"2012"},{"key":"10.1016\/j.engappai.2026.115559_b44","series-title":"2017 3rd IEEE International Conference on Computer and Communications","first-page":"507","article-title":"Malware family classification method based on static feature extraction","author":"Sun","year":"2017"},{"key":"10.1016\/j.engappai.2026.115559_b45","series-title":"International Workshop on Recent Advances in Intrusion Detection","first-page":"109","article-title":"Unsupervised anomaly-based malware detection using hardware features","author":"Tang","year":"2014"},{"key":"10.1016\/j.engappai.2026.115559_b46","doi-asserted-by":"crossref","first-page":"6155","DOI":"10.1109\/TIFS.2024.3409083","article-title":"Nebula: Self-attention for dynamic malware analysis","volume":"19","author":"Trizna","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"10.1016\/j.engappai.2026.115559_b47","series-title":"International Conference on Artificial Intelligence and Security","first-page":"573","article-title":"A novel malware detection and classification method based on capsule network","author":"Wang","year":"2019"},{"key":"10.1016\/j.engappai.2026.115559_b48","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2021.102420","article-title":"Image-based malware classification using section distribution information","volume":"110","author":"Xiao","year":"2021","journal-title":"Comput. Secur."},{"key":"10.1016\/j.engappai.2026.115559_b49","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1016\/j.jpdc.2020.03.012","article-title":"MalFCS: An effective malware classification framework with automated feature extraction based on deep convolutional neural networks","volume":"141","author":"Xiao","year":"2020","journal-title":"J. Parallel Distrib. Comput."},{"key":"10.1016\/j.engappai.2026.115559_b50","first-page":"1","article-title":"Prompt engineering-assisted malware dynamic analysis using GPT-4","author":"Yan","year":"2025","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"10.1016\/j.engappai.2026.115559_b51","series-title":"2021 IEEE Security and Privacy Workshops","first-page":"78","article-title":"BODMAS: An open dataset for learning based temporal analysis of PE malware","author":"Yang","year":"2021"},{"key":"10.1016\/j.engappai.2026.115559_b52","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2020.101740","article-title":"Byte-level malware classification based on markov images and deep learning","volume":"92","author":"Yuan","year":"2020","journal-title":"Comput. Secur."},{"issue":"5","key":"10.1016\/j.engappai.2026.115559_b53","doi-asserted-by":"crossref","first-page":"3770","DOI":"10.1109\/JIOT.2021.3100063","article-title":"IoT malware classification based on lightweight convolutional neural networks","volume":"9","author":"Yuan","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.engappai.2026.115559_b54","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1016\/j.aej.2024.10.055","article-title":"IMCMK-CNN: A lightweight convolutional neural network with Multi-scale Kernels for Image-based Malware Classification","volume":"111","author":"Zhang","year":"2025","journal-title":"Alex. Eng. J."},{"key":"10.1016\/j.engappai.2026.115559_b55","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.104262","article-title":"MPDroid: A multimodal pre-training Android malware detection method with static and dynamic features","volume":"150","author":"Zhang","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.engappai.2026.115559_b56","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2025.110524","article-title":"A novel malware detection method based on audit logs and graph neural network","volume":"152","author":"Zhen","year":"2025","journal-title":"Eng. Appl. Artif. Intell."}],"container-title":["Engineering Applications of Artificial Intelligence"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0952197626018439?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0952197626018439?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T19:37:20Z","timestamp":1784057840000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0952197626018439"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,10]]},"references-count":56,"alternative-id":["S0952197626018439"],"URL":"https:\/\/doi.org\/10.1016\/j.engappai.2026.115559","relation":{},"ISSN":["0952-1976"],"issn-type":[{"value":"0952-1976","type":"print"}],"subject":[],"published":{"date-parts":[[2026,10]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A lightweight malware classification method based on short bit sequence visualization","name":"articletitle","label":"Article Title"},{"value":"Engineering Applications of Artificial Intelligence","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.engappai.2026.115559","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"115559"}}