{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T03:01:34Z","timestamp":1784948494747,"version":"3.55.0"},"reference-count":106,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2024,1,22]],"date-time":"2024-01-22T00:00:00Z","timestamp":1705881600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2024,6,30]]},"abstract":"<jats:p>In this survey, we review the key developments in the field of malware detection using AI and analyze core challenges. We systematically survey state-of-the-art methods across five critical aspects of building an accurate and robust AI-powered malware-detection model: malware sophistication, analysis techniques, malware repositories, feature selection, and machine learning vs. deep learning. The effectiveness of an AI model is dependent on the quality of the features it is trained with. In turn, the quality and authenticity of these features is dependent on the quality of the dataset and the suitability of the analysis tool. Static analysis is fast but is limited by the widespread use of obfuscation. Dynamic analysis is not impacted by obfuscation but is defeated by ubiquitous anti-analysis techniques and requires more computational power. Sophisticated and evasive malware is challenging to extract authentic discriminatory features from and, combined with poor quality datasets, this can lead to a situation where a model achieves high accuracy with only one specific dataset.<\/jats:p>","DOI":"10.1145\/3638552","type":"journal-article","created":{"date-parts":[[2023,12,28]],"date-time":"2023-12-28T21:57:45Z","timestamp":1703800665000},"page":"1-33","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":112,"title":["Malware Detection with Artificial Intelligence: A Systematic Literature Review"],"prefix":"10.1145","volume":"56","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1684-1392","authenticated-orcid":false,"given":"Matthew G.","family":"Gaber","sequence":"first","affiliation":[{"name":"Edith Cowan University School of Science, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4559-4768","authenticated-orcid":false,"given":"Mohiuddin","family":"Ahmed","sequence":"additional","affiliation":[{"name":"Edith Cowan University School of Science, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1345-2829","authenticated-orcid":false,"given":"Helge","family":"Janicke","sequence":"additional","affiliation":[{"name":"Edith Cowan University School of Science, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,1,22]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Abuse.ch. 2023. Malware Bazaar. Retrieved from https:\/\/bazaar.abuse.ch"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/s40745-019-00237-0"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101760"},{"key":"e_1_3_2_5_2","article-title":"EMBER: An open dataset for training static PE malware machine learning models","author":"Anderson Hyrum S.","year":"2018","unstructured":"Hyrum S. Anderson and Phil Roth. 2018. EMBER: An open dataset for training static PE malware machine learning models. arXiv preprint arXiv:1804.04637 (2018).","journal-title":"arXiv preprint arXiv:1804.04637"},{"key":"e_1_3_2_6_2","unstructured":"Hyrum S. Anderson and Phil Roth. 2018. EMBER Elastic Malware Benchmark for Empowering Researchers. (2018). Retrieved from https:\/\/github.com\/elastic\/ember"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.23919\/CYCON.2018.8405026"},{"key":"e_1_3_2_8_2","article-title":"The role of machine learning in cybersecurity","author":"Apruzzese Giovanni","year":"2022","unstructured":"Giovanni Apruzzese, Pavel Laskov, Edgardo Montes de Oca, Wissam Mallouli, Luis B\u00fardalo Rapa, Athanasios Vasileios Grammatopoulos, and Fabio Di Franco. 2022. The role of machine learning in cybersecurity. Digital Threats: Research and Practice 4, 1 (2022), 1--38.","journal-title":"Digital Threats: Research and Practice"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2963724"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS56928.2023.10154293"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.7717\/peerj-cs.361"},{"key":"e_1_3_2_12_2","unstructured":"AV-Test. 2022. The Independant IT Security Institute. Retrieved from https:\/\/www.av-test.org\/en\/statistics\/malware\/"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/AICT52784.2021.9620415"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2984187"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3191790"},{"key":"e_1_3_2_16_2","unstructured":"Rodrigo Rubira Branco Gabriel Negeira Barbosa and Pedro Drimel Neto. 2012. Scientific but Not Academical Overview of Malware Anti-Debugging Anti-Disassembly and AntiVM Technologies. Retrieved from https:\/\/kernelhacking.com\/rodrigo\/docs\/blackhat2012-paper.pdf"},{"key":"e_1_3_2_17_2","volume-title":"34th International Conference on Neural Information Processing Systems (NIPS\u201920)","author":"Brown Tom B.","year":"2020","unstructured":"Tom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah, Jared Kaplan, Prafulla Dhariwal, Arvind Neelakantan, Pranav Shyam, Girish Sastry, Amanda Askell, Sandhini Agarwal, Ariel Herbert-Voss, Gretchen Krueger, Tom Henighan, Rewon Child, Aditya Ramesh, Daniel M. Ziegler, Jeffrey Wu, Clemens Winter, Christopher Hesse, Mark Chen, Eric Sigler, Mateusz Litwin, Scott Gray, Benjamin Chess, Jack Clark, Christopher Berner, Sam McCandlish, Alec Radford, Ilya Sutskever, and Dario Amodei. 2020. Language models are few-shot learners. In 34th International Conference on Neural Information Processing Systems (NIPS\u201920). Curran Associates Inc., Red Hook, NY, Article 159, 25 pages."},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.04.018"},{"key":"e_1_3_2_19_2","unstructured":"Ero Carrera. 2022. Pefile. Retrieved from https:\/\/github.com\/erocarrera\/pefile"},{"key":"e_1_3_2_20_2","unstructured":"Ferhat Ozgur Catak and Ahmet Faruk Yaz\u0131. 2021. A Benchmark API Call Dataset for Windows PE Malware Classification. (2021). arxiv:cs.CR\/1905.01999"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3048319"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2008.4630086"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10723-020-09510-6"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3321705.3329819"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.5555\/3158815"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3008081"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3025436"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3165809"},{"key":"e_1_3_2_29_2","unstructured":"Mohamed Amine Ferrag Mthandazo Ndhlovu Norbert Tihanyi Lucas C. Cordeiro Merouane Debbah and Thierry Lestable. 2023. Revolutionizing Cyber Threat Detection with Large Language Models. (2023). arxiv:cs.CR\/2306.14263"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3480463"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102550"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102845"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2019.2927886"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2019.102526"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102159"},{"key":"e_1_3_2_36_2","unstructured":"Claudio Guarnieri Alessandro Tanasi Jurriaan Bremer Mark Schloesser Koen Houtman Ricardo van Zutphen and Ben de Graaff. 2023. Cuckoo Automated Malware Analysis. Retrieved from https:\/\/cuckoosandbox.org\/"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3300381"},{"key":"e_1_3_2_38_2","unstructured":"Richard Harang and Ethan M. Rudd. 2020. SOREL-20M: A Large Scale Benchmark Dataset for Malicious PE Detection. (2020). arxiv:cs.CR\/2012.07634"},{"key":"e_1_3_2_39_2","unstructured":"Richard E. Harang and Ethan M. Rudd. 2022. SoReL-20M. Retrieved from https:\/\/github.com\/sophos\/SOREL-20M"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102396"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2021.301314"},{"key":"e_1_3_2_42_2","doi-asserted-by":"crossref","unstructured":"IBMSecurity. 2022. Cost of a Data Breach Report 2022. Retrieved from https:\/\/www.ibm.com\/downloads\/cas\/3R8N1DZJ","DOI":"10.12968\/S1353-4858(22)70049-9"},{"key":"e_1_3_2_43_2","unstructured":"Technology Innovation Institute. 2023. Falcon LLM. Retrieved from https:\/\/falconllm.tii.ae\/index.html"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICWT55831.2022.9935463"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359835"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1587\/transinf.2021EDP7067"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372823"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCT.2019.8711324"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3003785"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1155\/2015\/659101"},{"key":"e_1_3_2_51_2","unstructured":"Chan Woo Kim. 2018. NtMalDetect: A Machine Learning Approach to Malware Detection Using Native API System Calls. (2018). arxiv:cs.CR\/1802.05412"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3190978"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.3390\/sym13010035"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2866319"},{"key":"e_1_3_2_55_2","unstructured":"Dhilung Kirat Jiyong Jang and Marc Stoecklin. 2018. DeepLocker Concealing Targeted Attacks with AI Locksmithing. Retrieved from https:\/\/i.blackhat.com\/us-18\/Thu-August-9\/us-18-Kirat-DeepLocker-Concealing-Targeted-Attacks-with-AI-Locksmithing.pdf"},{"key":"e_1_3_2_56_2","unstructured":"Takashi Koide Naoki Fukushi Hiroki Nakano and Daiki Chiba. 2023. Detecting Phishing Sites Using ChatGPT. (2023). arxiv:cs.CR\/2306.05816"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102514"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2021.3100177"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2022.118073"},{"key":"e_1_3_2_60_2","unstructured":"Lorenzo Maffia Dario Nisi Platon Kotzias Giovanni Lagorio Simone Aonzo and Davide Balzarotti. 2021. Longitudinal Study of the Prevalence of Malware Evasive Techniques. Retrieved from https:\/\/arxiv.org\/abs\/2112.11289"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDIS.2018.00019"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102202"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.07.002"},{"key":"e_1_3_2_64_2","unstructured":"Microsoft. 2021. NtQuerySystemInformation Function (winternl.h). Retrieved from https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/winternl\/nf-winternl-ntquerysysteminformation"},{"key":"e_1_3_2_65_2","unstructured":"Microsoft. 2022. OpenProcess Function (processthreadsapi.h). Retrieved from https:\/\/docs.microsoft.com\/en-us\/windows\/win32\/api\/processthreadsapi\/nf-processthreadsapi-openprocess"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2017.06.007"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3112056"},{"key":"e_1_3_2_68_2","unstructured":"Aaron Mulgrew. 2023. I Built a Zero Day Virus with Undetectable Exfiltration using Only ChatGPT Prompts. Retrieved from https:\/\/www.forcepoint.com\/blog\/x-labs\/zero-day-exfiltration-using-chatgpt-prompts"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.02.006"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2022.103202"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3089586"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1145\/3329786"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.107095"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-022-12615-7"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.4316\/AECE.2019.02003"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3019658"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.23919\/SpliTech55088.2022.9854268"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_4"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2801858"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/3579375.3579377"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.05.010"},{"key":"e_1_3_2_82_2","doi-asserted-by":"crossref","unstructured":"Sherif Saad William Briguglio and Haytham Elmiligi. 2019. The curious case of machine learning in malware detection. (2019). arxiv:cs.CR\/1905.07573","DOI":"10.5220\/0007470705280535"},{"key":"e_1_3_2_83_2","unstructured":"Daniele Sgandurra Luis Mu\u00f1oz-Gonz\u00e1lez Rabih Mohsen and Emil C. Lupu. 2016. Automated Dynamic Analysis of Ransomware: Benefits Limitations and Use for Detection. (2016). arxiv:cs.CR\/1609.03020"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102627"},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2970466"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3041951"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2020.106273"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-62582-5"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.13164\/mendel.2019.2.027"},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567985"},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.11.001"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/AICAPS57044.2023.10074588"},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2020.107138"},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363267"},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101895"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2906934"},{"key":"e_1_3_2_97_2","unstructured":"VirusShare. 2023. Because Sharing Is Caring. Retrieved from https:\/\/virusshare.com\/"},{"key":"e_1_3_2_98_2","unstructured":"VIRUSTOTAL. 2023. Analyse Suspicious Files Domains IPs and URLs to Detect Malware and Other Breaches Automatically Share Them with the Security Community. Retrieved from https:\/\/www.virustotal.com\/gui\/home\/upload"},{"key":"e_1_3_2_99_2","unstructured":"Wireshark. 2023. Wireshark. Retrieved from https:\/\/www.wireshark.org\/"},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2020.03.012"},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00020"},{"key":"e_1_3_2_102_2","unstructured":"Limin Yang Arridhana Ciptadi Ihar Laziuk Ali Ahmadzadeh and Gang Wang. 2022. BODMAS Malware Dataset. Retrieved from https:\/\/whyisyoung.github.io\/BODMAS\/"},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.1145\/3073559"},{"key":"e_1_3_2_104_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2020.08.082"},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.1145\/3374135.3385270"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-022-19443-7"},{"issue":"3","key":"e_1_3_2_107_2","first-page":"327","article-title":"Introduction to artificial neural network (ANN) methods: What they are and how to use them","volume":"41","author":"Zupan J.","year":"1994","unstructured":"J. Zupan. 1994. Introduction to artificial neural network (ANN) methods: What they are and how to use them. Acta Chim. Sloven. 41, 3 (1994), 327.","journal-title":"Acta Chim. Sloven."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3638552","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3638552","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:06:13Z","timestamp":1750291573000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3638552"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1,22]]},"references-count":106,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2024,6,30]]}},"alternative-id":["10.1145\/3638552"],"URL":"https:\/\/doi.org\/10.1145\/3638552","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1,22]]},"assertion":[{"value":"2022-12-16","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-12-21","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-01-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}