{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,27]],"date-time":"2026-05-27T14:44:05Z","timestamp":1779893045246,"version":"3.53.1"},"reference-count":61,"publisher":"IEEE","license":[{"start":{"date-parts":[[2022,5,2]],"date-time":"2022-05-02T00:00:00Z","timestamp":1651449600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2022,5,2]],"date-time":"2022-05-02T00:00:00Z","timestamp":1651449600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003009","name":"Science and Technology Development Fund","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003009","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,5,2]]},"DOI":"10.1109\/infocom48880.2022.9796786","type":"proceedings-article","created":{"date-parts":[[2022,6,20]],"date-time":"2022-06-20T21:18:49Z","timestamp":1655759929000},"page":"1998-2007","source":"Crossref","is-referenced-by-count":43,"title":["MalGraph: Hierarchical Graph Neural Networks for Robust Windows Malware Detection"],"prefix":"10.1109","author":[{"given":"Xiang","family":"Ling","sequence":"first","affiliation":[{"name":"Chinese Academy of Sciences,Institute of Software"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lingfei","family":"Wu","sequence":"additional","affiliation":[{"name":"JD.COM Silicon Valley Research Center"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Deng","sequence":"additional","affiliation":[{"name":"Zhejiang University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenqing","family":"Qu","sequence":"additional","affiliation":[{"name":"Zhejiang University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiangyu","family":"Zhang","sequence":"additional","affiliation":[{"name":"Zhejiang University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sheng","family":"Zhang","sequence":"additional","affiliation":[{"name":"Zhejiang University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tengfei","family":"Ma","sequence":"additional","affiliation":[{"name":"IBM Research"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bin","family":"Wang","sequence":"additional","affiliation":[{"name":"Hangzhou Hikvision Digital Technology Co., Ltd."}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chunming","family":"Wu","sequence":"additional","affiliation":[{"name":"Zhejiang University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"Zhejiang University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","article-title":"PEiD: PE iDentifier","year":"2020"},{"key":"ref38","article-title":"Upx: The ultimate packer for executables","year":"2020"},{"key":"ref33","article-title":"Deceiving end-to-end deep learning malware detectors using adversarial examples","author":"kreuk","year":"2018","journal-title":"arXiv 1802 04528"},{"key":"ref32","article-title":"Detection of malicious pdf files based on hierarchical document structure","author":"laskov","year":"2013","journal-title":"NDSS"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2014.02.053"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427261"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24310"},{"key":"ref36","article-title":"360 Total Security","year":"2020"},{"key":"ref35","article-title":"Black-box adversarial attacks against deep learning based malware binaries detection with GAN","author":"junkun","year":"2020","journal-title":"ECAI"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/DSC50466.2020.00066"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00073"},{"key":"ref61","article-title":"Evading machine learning malware detection","author":"anderson","year":"2017","journal-title":"Black Hat USA"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-08509-8_7"},{"key":"ref27","year":"2020"},{"key":"ref29","article-title":"AVCLASS: A tool for massive malware labeling","author":"sebasti\u00e1n","year":"2016","journal-title":"RAID"},{"key":"ref2","article-title":"Data mining methods for detection of new malicious executables","author":"schultz","year":"2000","journal-title":"S&P"},{"key":"ref1","article-title":"Malware statistics","year":"2021"},{"key":"ref20","article-title":"Graph attention networks","author":"velickovic","year":"2018","journal-title":"ICLRE"},{"key":"ref22","article-title":"Graph u-nets","author":"gao","year":"2019","journal-title":"ICML"},{"key":"ref21","article-title":"Hierarchical graph representation learning with differentiable pooling","author":"ying","year":"2018","journal-title":"NIPS"},{"key":"ref24","article-title":"Designing random graph models using variational autoencoders with applications to chemical design","author":"samanta","year":"2018","journal-title":"arXiv 1802 05283"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01418-6_41"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3447571"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3289600.3290967"},{"key":"ref50","article-title":"Fast graph representation learning with PyTorch Geometric","author":"fey","year":"2019","journal-title":"ICLR Workshop"},{"key":"ref51","article-title":"Decoupled weight decay regularization","author":"loshchilov","year":"2019","journal-title":"ICLRE"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2913439"},{"key":"ref58","article-title":"Adversarial EXEmples: A survey and experimental evaluation of practical attacks on machine learning for windows malware detection","author":"demetrio","year":"2020","journal-title":"arXiv 2008 07125"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.23919\/EUSIPCO.2018.8553214"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1145\/3411508.3421374"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00020"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1007\/s11633-019-1211-x"},{"key":"ref53","article-title":"Adversarial attacks against Windows PE malware detection: A survey of the state-of-the-art","author":"ling","year":"2021","journal-title":"arXiv preprint arXiv 2112 12310"},{"key":"ref52","article-title":"Masked label prediction: Unified massage passing model for semi-supervised classification","author":"shi","year":"2020","journal-title":"arXiv 2009 03509"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653736"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978370"},{"key":"ref40","article-title":"CAPE: Malware Configuration And Payload Extraction","author":"o\u2019reilly","year":"2020"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23185"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134018"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22038-9_15"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2021.3102234"},{"key":"ref16","article-title":"Semi-supervised classification with graph convolutional networks","author":"kipf","year":"2017","journal-title":"ICLRE"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3394486.3406474"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-16-6054-2_13"},{"key":"ref19","article-title":"Inductive representation learning on large graphs","author":"hamilton","year":"2017","journal-title":"NIPS"},{"key":"ref4","article-title":"A framework for efficient mining of structural information to detect zero-day malicious portable executables","author":"shafiq","year":"2009","journal-title":"1Next Generation Intelligent Networks Research Center (nexGIN RC) Tech Rep"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014105"},{"key":"ref6","article-title":"Malware detection by eating a whole exe","author":"raff","year":"2017","journal-title":"arXiv 1710 09435"},{"key":"ref5","article-title":"EMBER: an open dataset for training static PE malware machine learning models","author":"anderson","year":"2018","journal-title":"arXiv 1804 04637"},{"key":"ref8","article-title":"Malware detection with LSTM using opcode language","author":"lu","year":"2019","journal-title":"arXiv 1906 04593"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00022"},{"key":"ref49","article-title":"Automatic differentiation in pytorch","author":"paszke","year":"2017","journal-title":"NIPS Autodiff Workshop"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.1979.234183"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1016\/S0031-3203(96)00142-2"},{"key":"ref45","article-title":"Algorithms for hyper-parameter optimization","author":"bergstra","year":"2011","journal-title":"NIPS"},{"key":"ref48","article-title":"Textshield: Robust text classification based on multimodal embedding and neural machine translation","author":"li","year":"2020","journal-title":"Usenix Security"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00023"},{"key":"ref42","article-title":"IDA Pro","year":"2021"},{"key":"ref41","article-title":"YARA in a nutshell","year":"2020"},{"key":"ref44","article-title":"2020 machine learning security evasion competition","author":"azure","year":"2021"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2019.00020"}],"event":{"name":"IEEE INFOCOM 2022 - IEEE Conference on Computer Communications","location":"London, United Kingdom","start":{"date-parts":[[2022,5,2]]},"end":{"date-parts":[[2022,5,5]]}},"container-title":["IEEE INFOCOM 2022 - IEEE Conference on Computer Communications"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/9796607\/9796652\/09796786.pdf?arnumber=9796786","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,11]],"date-time":"2022-07-11T20:01:11Z","timestamp":1657569671000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9796786\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,5,2]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/infocom48880.2022.9796786","relation":{},"subject":[],"published":{"date-parts":[[2022,5,2]]}}}