{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:59:56Z","timestamp":1782316796503,"version":"3.54.5"},"reference-count":44,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2021,9,14]],"date-time":"2021-09-14T00:00:00Z","timestamp":1631577600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Key-Area Research and Development Program of Guangdong Province","award":["2019B010136001"],"award-info":[{"award-number":["2019B010136001"]}]},{"name":"Basic and Applied Basic Research Major Program for Guangdong Province","award":["2019B030302002"],"award-info":[{"award-number":["2019B030302002"]}]},{"DOI":"10.13039\/501100012245","name":"Science and Technology Planning Project of Guangdong Province","doi-asserted-by":"crossref","award":["LZC0023 and LZC0024"],"award-info":[{"award-number":["LZC0023 and LZC0024"]}],"id":[{"id":"10.13039\/501100012245","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Internet Technol."],"published-print":{"date-parts":[[2022,2,28]]},"abstract":"<jats:p>\n            With the construction of smart cities, the number of Internet of Things (IoT) devices is growing rapidly, leading to an explosive growth of malware designed for IoT devices. These malware pose a serious threat to the security of IoT devices. The traditional malware classification methods mainly rely on feature engineering. To improve accuracy, a large number of different types of features will be extracted from malware files in these methods. That brings a high complexity to the classification. To solve these issues, a malware classification method based on Word2Vec and\n            <jats:bold>Multilayer Perception (MLP)<\/jats:bold>\n            is proposed in this article. First, for one malware sample, Word2Vec is used to calculate a word vector for all bytes of the binary file and all instructions in the assembly file. Second, we combine these vectors into a 256x256x2-dimensional matrix. Finally, we designed a deep learning network structure based on MLP to train the model. Then the model is used to classify the testing samples. The experimental results prove that the method has a high accuracy of 99.54%.\n          <\/jats:p>","DOI":"10.1145\/3436751","type":"journal-article","created":{"date-parts":[[2021,9,14]],"date-time":"2021-09-14T16:03:26Z","timestamp":1631635406000},"page":"1-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":38,"title":["Malware Classification Based on Multilayer Perception and Word2Vec for IoT Security"],"prefix":"10.1145","volume":"22","author":[{"given":"Yanchen","family":"Qiao","sequence":"first","affiliation":[{"name":"Cyberspace Security Research Center, Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weizhe","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Harbin Institute of Technology, Harbin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaojiang","family":"Du","sequence":"additional","affiliation":[{"name":"Temple University, Philadelphia, USA, PA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohsen","family":"Guizani","sequence":"additional","affiliation":[{"name":"Qatar University, Doha, Qatar"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,9,14]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"VirusTotal. Retrieved","author":"Quintero Bernardo","year":"2021","unstructured":"Bernardo Quintero , Emiliano Mart\u00ednez , V\u00edctor Manuel \u00c1lvarez , Karl Hiramoto , Julio Canto , Alejandro Berm\u00fadez , and Juan A. Infantes . 2020 . VirusTotal. Retrieved July 29, 2021 from https:\/\/www.virustotal.com\/. Bernardo Quintero, Emiliano Mart\u00ednez, V\u00edctor Manuel \u00c1lvarez, Karl Hiramoto, Julio Canto, Alejandro Berm\u00fadez, and Juan A. Infantes. 2020. VirusTotal. Retrieved July 29, 2021 from https:\/\/www.virustotal.com\/."},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3190645.3190692"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/509907.509965"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2932228"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2013.6638293"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-017-3077-6"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1214\/aos\/1013203451"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSESS.2017.8342858"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2015.7165931"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2513228.2513294"},{"key":"e_1_2_1_11_1","first-page":"2278","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"Haykin Simon","year":"2009","unstructured":"Simon Haykin and Bart Kosko . 2009 . Gradient-based learning applied to document recognition . Proceedings of the IEEE 86 , 11 (1998), 2278 \u2013 2324 . Simon Haykin and Bart Kosko. 2009. Gradient-based learning applied to document recognition. Proceedings of the IEEE 86, 11 (1998), 2278\u20132324.","journal-title":"Proceedings of the IEEE"},{"key":"e_1_2_1_12_1","volume-title":"Retrieved","author":"AV-TEST Institute","year":"2020","unstructured":"AV-TEST Institute . 2020 . Malware Statistics & Trends Report . Retrieved July 29, 2021 from http:\/\/www.av-test.org\/en\/statistics\/malware\/. AV-TEST Institute. 2020. Malware Statistics & Trends Report. Retrieved July 29, 2021 from http:\/\/www.av-test.org\/en\/statistics\/malware\/."},{"key":"e_1_2_1_13_1","volume-title":"Principles & Solutions. Retrieved","author":"Katrenko Anna","year":"2020","unstructured":"Anna Katrenko . 2020 . Malware Sandbox Evasion: Techniques , Principles & Solutions. Retrieved July 29, 2021 from https:\/\/www.apriorit.com\/dev-blog\/545-sandbox-evading-malware. Anna Katrenko. 2020. Malware Sandbox Evasion: Techniques, Principles & Solutions. Retrieved July 29, 2021 from https:\/\/www.apriorit.com\/dev-blog\/545-sandbox-evading-malware."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/NAECON.2017.8268747"},{"key":"e_1_2_1_15_1","series-title":"Lecture Notes in Computer Science","volume-title":"Advances in Computer Science and Ubiquitous Computing","author":"Kim Hae Jung","unstructured":"Hae Jung Kim . 2018. Image-based malware classification using convolutional neural network . In Advances in Computer Science and Ubiquitous Computing . Lecture Notes in Computer Science , Vol. 474 . Springer , 1352\u20131357. https:\/\/doi.org\/10.1007\/978-981-10-7605-3_215 Hae Jung Kim. 2018. Image-based malware classification using convolutional neural network. In Advances in Computer Science and Ubiquitous Computing. Lecture Notes in Computer Science, Vol. 474. Springer, 1352\u20131357. https:\/\/doi.org\/10.1007\/978-981-10-7605-3_215"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1014052.1014105"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.5555\/3044805.3045025"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2020.2993293"},{"key":"e_1_2_1_19_1","unstructured":"Tomas Mikolov Kai Chen Greg Corrado and Jeffrey Dean. 2013. Efficient estimation of word representations in vector space. arXiv:1301.3781.  Tomas Mikolov Kai Chen Greg Corrado and Jeffrey Dean. 2013. Efficient estimation of word representations in vector space. arXiv:1301.3781."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCNC.2013.6504162"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.09.006"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2015.7178304"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SSDSE.2017.8071952"},{"key":"e_1_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Yanchen Qiao Qingshan Jiang Zhenchao Jiang and Liang Gu. 2019. A multi-channel visualization method for malware classification based on deep learning. In Proceedings of the 2019 18th IEEE International Conference on Trust Security and Privacy in Computing and Communications and the 13th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE\u201919). IEEE Los Alamitos CA 757\u2013762.   Yanchen Qiao Qingshan Jiang Zhenchao Jiang and Liang Gu. 2019. A multi-channel visualization method for malware classification based on deep learning. In Proceedings of the 2019 18th IEEE International Conference on Trust Security and Privacy in Computing and Communications and the 13th IEEE International Conference on Big Data Science and Engineering (TrustCom\/BigDataSE\u201919). IEEE Los Alamitos CA 757\u2013762.","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00109"},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the 2020 IEEE International Conference on Communications (ICC\u201920)","author":"Qiao Y.","unstructured":"Y. Qiao , B. Zhang , and W. Zhang . 2020. Malware classification method based on word vector of bytes and multilayer perception . In Proceedings of the 2020 IEEE International Conference on Communications (ICC\u201920) . IEEE, Los Alamitos, CA, 1\u20136. Y. Qiao, B. Zhang, and W. Zhang. 2020. Malware classification method based on word vector of bytes and multilayer perception. In Proceedings of the 2020 IEEE International Conference on Communications (ICC\u201920). IEEE, Los Alamitos, CA, 1\u20136."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2977383"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2018.2861775"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2019.8761070"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.2017.1800112"},{"key":"e_1_2_1_30_1","volume-title":"Proceedings of the International Symposium on Security in Computing and Communication. 226\u2013235","author":"Rahul R. K.","unstructured":"R. K. Rahul , T. Anjali , Vijay Krishna Menon , and K. P. Soman . 2017. Deep learning for network flow analysis and malware classification . In Proceedings of the International Symposium on Security in Computing and Communication. 226\u2013235 . R. K. Rahul, T. Anjali, Vijay Krishna Menon, and K. P. Soman. 2017. Deep learning for network flow analysis and malware classification. In Proceedings of the International Symposium on Security in Computing and Communication. 226\u2013235."},{"key":"e_1_2_1_31_1","unstructured":"Royi Ronen Marian Radu Corina Feuerstein Elad Yom-Tov and Mansour Ahmadi. 2018. Microsoft malware classification challenge. arXiv:1802.10135.  Royi Ronen Marian Radu Corina Feuerstein Elad Yom-Tov and Mansour Ahmadi. 2018. Microsoft malware classification challenge. arXiv:1802.10135."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/AISP.2012.6313810"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.5555\/882495.884439"},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the International Symposium on Biometrics and Security Technologies. 238\u2013243","author":"Mohd Shaid Syed Zainudeen","year":"2015","unstructured":"Syed Zainudeen Mohd Shaid . 2015 . Malware behavior image for malware variant identification . In Proceedings of the International Symposium on Biometrics and Security Technologies. 238\u2013243 . Syed Zainudeen Mohd Shaid. 2015. Malware behavior image for malware variant identification. In Proceedings of the International Symposium on Biometrics and Security Technologies. 238\u2013243."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-010-0141-5"},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the 2008 3rd International Conference on Malicious and Unwanted Software (MALWARE\u201908)","author":"Tian Ronghua","unstructured":"Ronghua Tian , Lynn Margaret Batten , and S. C. Versteeg . 2008. Function length as a tool for malware classification . In Proceedings of the 2008 3rd International Conference on Malicious and Unwanted Software (MALWARE\u201908) . IEEE, Los Alamitos, CA, 69\u201376. Ronghua Tian, Lynn Margaret Batten, and S. C. Versteeg. 2008. Function length as a tool for malware classification. In Proceedings of the 2008 3rd International Conference on Malicious and Unwanted Software (MALWARE\u201908). IEEE, Los Alamitos, CA, 69\u201376."},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/IESYS.2017.8233569"},{"key":"e_1_2_1_38_1","volume-title":"Demadroid: Object reference graph-based malware detection in Android. Security and Communication Networks 2018","author":"Wang Huanran","year":"2018","unstructured":"Huanran Wang , Hui He , and Weizhe Zhang . 2018 . Demadroid: Object reference graph-based malware detection in Android. Security and Communication Networks 2018 (2018), Article 7064131. Huanran Wang, Hui He, and Weizhe Zhang. 2018. Demadroid: Object reference graph-based malware detection in Android. Security and Communication Networks 2018 (2018), Article 7064131."},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_20"},{"key":"e_1_2_1_40_1","volume-title":"Proceedings of the 2008 IEEE International Conference on Dependable Systems and Networks with FTCS and DCC (DSN\u201908)","author":"Chen Xu","unstructured":"Xu Chen , J. Andersen , Z. M. Mao , M. Bailey , and J. Nazario . 2008 . In Proceedings of the 2008 IEEE International Conference on Dependable Systems and Networks with FTCS and DCC (DSN\u201908) . IEEE, Los Alamitos, CA. Xu Chen, J. Andersen, Z. M. Mao, M. Bailey, and J. Nazario. 2008. In Proceedings of the 2008 IEEE International Conference on Dependable Systems and Networks with FTCS and DCC (DSN\u201908). IEEE, Los Alamitos, CA."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.09.025"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2014.09.011"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2019.2924677"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2019.2956173"}],"container-title":["ACM Transactions on Internet Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3436751","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3436751","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T17:45:04Z","timestamp":1750268704000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3436751"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,14]]},"references-count":44,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,2,28]]}},"alternative-id":["10.1145\/3436751"],"URL":"https:\/\/doi.org\/10.1145\/3436751","relation":{},"ISSN":["1533-5399","1557-6051"],"issn-type":[{"value":"1533-5399","type":"print"},{"value":"1557-6051","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,14]]},"assertion":[{"value":"2020-05-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-11-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-09-14","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}