{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T16:10:08Z","timestamp":1778256608409,"version":"3.51.4"},"reference-count":50,"publisher":"Association for Computing Machinery (ACM)","issue":"4","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2025,11,30]]},"abstract":"<jats:p>Embedded PowerShell commands or scripts are among the most popular malware payloads. For malware that prioritizes stealthiness, such as fileless malware, PowerShell\u2019s access to Windows API functions without additional libraries makes it useful for evading detection. Detecting malicious PowerShell scripts and commands is an open challenge for proactive endpoint protection due to three major issues: (1) The malicious commands are usually hidden in a long script beyond the processing limit of typical machine learning models. (2) They are usually mixed with bulky benign scripts. (3) Script obfuscation can easily conceal their potential matching signatures.<\/jats:p>\n                  <jats:p>\n                    In this article, we introduce a novel model addressing these challenges. It incorporates similarity learning, sentence transformer, sliding window method, and stochastic gradient descent (SGD) classifier. Our key insight is that malicious PowerShell code, particularly when obfuscated, exhibits semantic and statistical deviations from benign administrative usage, and these deviations can be captured by contrastive sentence embeddings without the need for de-obfuscation or handcrafted features. We operate this insight through a Siamese similarity learning framework that improves robustness against\n                    <jats:italic toggle=\"yes\">Out-of-Vocabulary<\/jats:italic>\n                    tokens due to unseen code obfuscation methods. The sliding window method enables the model to handle long scripts, and the SGD classifier evaluates segment-level maliciousness. Our model achieves accuracies of 99.01%, 97.59%, 98.70%, and 99.73% across multiple obfuscated and mixed script benchmarks, outperforming existing baselines by over 30% in all cases. This work demonstrates a scalable and effective strategy for robust PowerShell malware detection in real-world scenarios.\n                  <\/jats:p>","DOI":"10.1145\/3771542","type":"journal-article","created":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T11:12:41Z","timestamp":1760008361000},"page":"1-23","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Toward a Robust Detection of PowerShell Malware against Code Mixing and Obfuscation by Using Sentence Transformer and Similarity Learning"],"prefix":"10.1145","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2763-6186","authenticated-orcid":false,"given":"Zhiwei","family":"Fu","sequence":"first","affiliation":[{"name":"School of Information Studies, McGill University","place":["Montreal, Canada"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1195-0007","authenticated-orcid":false,"given":"Leo","family":"Song","sequence":"additional","affiliation":[{"name":"Queen's University","place":["Kingston, Canada"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4513-200X","authenticated-orcid":false,"given":"Steven","family":"Ding","sequence":"additional","affiliation":[{"name":"School of Information Studies, McGill University","place":["Montreal, Canada"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5709-7611","authenticated-orcid":false,"given":"Furkan","family":"Alaca","sequence":"additional","affiliation":[{"name":"School of Computing Science, Queen's University","place":["Kingston, Canada"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8716-8214","authenticated-orcid":false,"given":"Sudipta","family":"Acharya","sequence":"additional","affiliation":[{"name":"Queen's University","place":["Kingston, Canada"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,19]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"(n.d.). Retrieved from https:\/\/beautifytools.com\/javascript-obfuscator.php. [Accessed 05-09-2024]."},{"key":"e_1_3_2_3_2","unstructured":"Wireshark \u00c2\u00b7 Download \u2014 wireshark.org. Retrieved September 05 2024 from https:\/\/www.wireshark.org\/download.html. (n.d.). [Accessed 05-09-2024]."},{"key":"e_1_3_2_4_2","unstructured":"2022. FILELESS MALWARE EXPLAINED. Crowdstrike (2022)."},{"key":"e_1_3_2_5_2","article-title":"Invoke-obfuscation: Hiding payloads to avoid detection","author":"Ali Ammad","year":"2020","unstructured":"Ammad Ali. 2020. Invoke-obfuscation: Hiding payloads to avoid detection. Medium (2020).","journal-title":"Medium"},{"key":"e_1_3_2_6_2","article-title":"Transformer machine learning language model for auto-alignment of long-term and short-term plans in construction","volume":"132","author":"Amer Fouad","year":"2021","unstructured":"Fouad Amer, Yoonhwa Jung, and Mani Golparvar-Fard. 2021. Transformer machine learning language model for auto-alignment of long-term and short-term plans in construction. Automation in Construction 132, C (2021).","journal-title":"Automation in Construction"},{"key":"e_1_3_2_7_2","first-page":"23","volume-title":"Proceedings of the International Symposium on Memory Systems. Washington, DC, USA, September, 2020","author":"Botacin Marcus","year":"2020","unstructured":"Marcus Botacin, Andr\u00e9 Gr\u00e9gio, and Marco Antonio Zanata Alves. 2020. Near-memory and in-memory detection of fileless malware. In Proceedings of the International Symposium on Memory Systems. Washington, DC, USA, September, 2020. ACM, 23\u201338."},{"key":"e_1_3_2_8_2","first-page":"177","volume-title":"Proceeding of the 19th International Conference on Computational Statistics. COMPSTAT","author":"Bottou L\u00e9on","year":"2010","unstructured":"L\u00e9on Bottou. 2010. Large-scale machine learning with stochastic gradient descent. In Proceeding of the 19th International Conference on Computational Statistics. COMPSTAT, Yves Lechevallier and Gilbert Saporta (Eds.), Physica-Verlag, 177\u2013186."},{"key":"e_1_3_2_9_2","doi-asserted-by":"crossref","first-page":"2006","DOI":"10.1007\/978-1-4939-2864-4_797","volume-title":"Proceedings of the Encyclopedia of Algorithms","author":"Braverman Vladimir","year":"2016","unstructured":"Vladimir Braverman. 2016. Sliding window algorithms. In Proceedings of the Encyclopedia of Algorithms. 2006\u20132011."},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103731"},{"key":"e_1_3_2_11_2","first-page":"295","volume-title":"Proceedings of the 52nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, Baltimore, MD, USA, June 27-30, 2022","author":"Chai Huajun","year":"2022","unstructured":"Huajun Chai, Lingyun Ying, Haixin Duan, and Daren Zha. 2022. Invoke-deobfuscation: AST-based and semantics-preserving deobfuscation for powershell scripts. In Proceedings of the 52nd Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, Baltimore, MD, USA, June 27-30, 2022. IEEE, 295\u2013306."},{"key":"e_1_3_2_12_2","series-title":"Methods in Molecular Biology","doi-asserted-by":"crossref","first-page":"73","DOI":"10.1007\/978-1-0716-0826-5_3","volume-title":"Proceedings of the Artificial Neural Networks - 3rd Edition.","volume":"2190","author":"Chicco Davide","year":"2021","unstructured":"Davide Chicco. 2021. Siamese neural networks: An overview. In Proceedings of the Artificial Neural Networks - 3rd Edition.Hugh M. Cartwright (Ed.), Methods in Molecular Biology, Vol. 2190. Springer, 73\u201394."},{"key":"e_1_3_2_13_2","unstructured":"Sam Cook. 2022. Malware Statistics and Facts for 2022: Frequency Impact Cost and More. (Jul2022)."},{"key":"e_1_3_2_14_2","unstructured":"Diogo Cortiz. 2021. Exploring transformers in emotion recognition: A comparison of BERT DistillBERT RoBERTa XLNet and ELECTRA. arXiv:2104.02041. Retrieved from https:\/\/arxiv.org\/abs\/2104.02041"},{"key":"e_1_3_2_15_2","article-title":"Classification: ROC curve and AUC","author":"Developer Google","year":"2020","unstructured":"Google Developer. 2020. Classification: ROC curve and AUC. Google (2020).","journal-title":"Google"},{"key":"e_1_3_2_16_2","doi-asserted-by":"crossref","unstructured":"Jacob Devlin Ming-Wei Chang Kenton Lee and Kristina Toutanova. 2018. BERT: Pre-training of deep bidirectional transformers for language understanding. 4171\u20134186. arXiv:1810.04805. Retrieved from https:\/\/arxiv.org\/abs\/1810.04805","DOI":"10.18653\/v1\/N19-1423"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1162\/tacl_a_00410"},{"key":"e_1_3_2_18_2","unstructured":"Hugging Face. 2021. Summary of the Tokenizers. (Jun2021)."},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.03.117"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patrec.2005.10.010"},{"key":"e_1_3_2_21_2","doi-asserted-by":"crossref","unstructured":"Zhangyin Feng Daya Guo Duyu Tang Nan Duan Xiaocheng Feng Ming Gong Linjun Shou Bing Qin Ting Liu Daxin Jiang and Ming Zhou. 2020. CodeBERT: A Pre-Trained Model for Programming and Natural Languages. (2020). arXiv:2002.08155. Retrieved from https:\/\/arxiv.org\/abs\/2002.08155","DOI":"10.18653\/v1\/2020.findings-emnlp.139"},{"key":"e_1_3_2_22_2","unstructured":"Vala Flynn. 2021. The Advantages and Disadvantages of Code Obfuscation. (Aug2021)."},{"key":"e_1_3_2_23_2","article-title":"AMSI-based detection of malicious powershell code using contextual embeddings","author":"Hendler Danny","year":"2020","unstructured":"Danny Hendler, Shay Kels, and Amir Rubin. 2020. AMSI-based detection of malicious powershell code using contextual embeddings. Proceedings of the 15th ACM Asia Conference on Computer and Communications Security 15 (2020).","journal-title":"Proceedings of the 15th ACM Asia Conference on Computer and Communications Security"},{"key":"e_1_3_2_24_2","unstructured":"Geoffrey E. Hinton Oriol Vinyals and Jeffrey Dean. 2015. Distilling the knowledge in a neural network. arXiv:1503.02531. Retrieved from https:\/\/arxiv.org\/abs\/1503.02531"},{"key":"e_1_3_2_25_2","first-page":"687","volume-title":"Proceedings of the 2019 16th International Bhurban Conference on Applied Sciences and Technology","author":"Ijaz Muhammad","year":"2019","unstructured":"Muhammad Ijaz, Muhammad Hanif Durad, and Maliha Ismail. 2019. Static and dynamic malware analysis using machine learning. In Proceedings of the 2019 16th International Bhurban Conference on Applied Sciences and Technology. IEEE, 687\u2013691."},{"key":"e_1_3_2_26_2","unstructured":"Juniper Johnson and Sarah Connell. 2021. Experiments in Tokenization for Word Embedding Models. (Aug2021)."},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2022.119133"},{"key":"e_1_3_2_28_2","unstructured":"Mikhail Kasimov. 2017. MPSD Dataset. (Nov2017)."},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/2348283.2348453"},{"key":"e_1_3_2_30_2","unstructured":"Taku Kudo. 2021. Unsupervised Text Tokenizer for Neural Network-Based Text Generation. (2021)."},{"key":"e_1_3_2_31_2","volume-title":"Proceedings of the 38th Conference on Neural Information Processing Systems, Datasets and Benchmarks Track","author":"Kuratov Yuri","year":"2024","unstructured":"Yuri Kuratov, Aydar Bulatov, Petr Anokhin, Ivan Rodkin, Dmitry Sorokin, Artyom Sorokin, and Mikhail Burtsev. 2024. BABILong: Testing the limits of LLMs with long context reasoning-in-a-haystack. In Proceedings of the 38th Conference on Neural Information Processing Systems, Datasets and Benchmarks Track."},{"key":"e_1_3_2_32_2","first-page":"3035","volume-title":"Proceedings of the Encyclopedia of Database Systems","author":"Liu Ling","year":"2009","unstructured":"Ling Liu and M. Tamer \u00d6zsu. 2009. Term frequency by inverse document frequency. In Proceedings of the Encyclopedia of Database Systems. Springer US, 3035."},{"key":"e_1_3_2_33_2","unstructured":"McAfee. 2017. Fileless malware execution with PowerShell is easier than you may realize. (Feb2017)."},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2021.100404"},{"key":"e_1_3_2_35_2","unstructured":"Eduardo Mu\u00c3\u00b1oz. 2021. Create a Tokenizer and Train a Hugging Face Roberta Model from Scratch. (Aug2021)."},{"key":"e_1_3_2_36_2","unstructured":"NewsCatcher Engineering Team. 2022. Ultimate guide to text similarity with python. arXiv:2104.02041. Retrieved from https:\/\/arxiv.org\/abs\/2104.02041"},{"key":"e_1_3_2_37_2","article-title":"Evaluation of multilabel multi-class classification","author":"Nomula Sridhar","year":"2019","unstructured":"Sridhar Nomula. 2019. Evaluation of multilabel multi-class classification. Share and Discover Knowledge on SlideShare (2019).","journal-title":"Share and Discover Knowledge on SlideShare"},{"key":"e_1_3_2_38_2","article-title":"What you need to know about powershell attacks","author":"O\u2019Connor Fred","year":"2017","unstructured":"Fred O\u2019Connor. 2017. What you need to know about powershell attacks. Cybereason (2017).","journal-title":"Cybereason"},{"key":"e_1_3_2_39_2","unstructured":"OECD. 2009. Computer viruses and other malicious software: A threat to the internet economy. (2009)."},{"key":"e_1_3_2_40_2","unstructured":"Espejel Omar. 2021. Sentence-Transformers: all-distilroberta-v1. (Aug2021)."},{"key":"e_1_3_2_41_2","unstructured":"Selva Prabhakaran. 2022. Cosine Similarity: Understanding the Math and How It Works. (Apr2022)."},{"key":"e_1_3_2_42_2","first-page":"3226","volume-title":"Proceedings of the 2021 IEEE International Conference on Systems, Man, and Cybernetics, SMC 2021, Melbourne, Australia, October 17-20, 2021","author":"Rahali Abir","year":"2021","unstructured":"Abir Rahali and Moulay A. Akhloufi. 2021. MalBERT: Malware detection using bidirectional encoder representations from transformers. In Proceedings of the 2021 IEEE International Conference on Systems, Man, and Cybernetics, SMC 2021, Melbourne, Australia, October 17-20, 2021. IEEE, 3226\u20133231."},{"key":"e_1_3_2_43_2","first-page":"7","volume-title":"Proceedings of the International Conference on Software Security and Assurance, Seoul, Korea (South), July 26-27, 2018","author":"Rauti Sampsa","year":"2018","unstructured":"Sampsa Rauti and Ville Lepp\u00e4nen. 2018. A comparison of online javascript obfuscators. In Proceedings of the International Conference on Software Security and Assurance, Seoul, Korea (South), July 26-27, 2018. IEEE, 7\u201312."},{"key":"e_1_3_2_44_2","unstructured":"Victor Sanh Lysandre Debut Julien Chaumond and Thomas Wolf. 2019. DistilBERT: A distilled version of BERT: Smaller faster cheaper and lighter. arXiv:1910.01108. Retrieved from https:\/\/arxiv.org\/abs\/1910.01108"},{"key":"e_1_3_2_45_2","doi-asserted-by":"crossref","DOI":"10.1109\/BigData.2017.8257919","article-title":"Exponential random graph models with big networks: Maximum pseudolikelihood estimation and the parametric bootstrap","author":"Schmid Christian S.","year":"2017","unstructured":"Christian S. Schmid and Bruce A. Desmarais. 2017. Exponential random graph models with big networks: Maximum pseudolikelihood estimation and the parametric bootstrap. 2017 IEEE International Conference on Big Data (Big Data) 2018 (2017), 116\u2013121.","journal-title":"2017 IEEE International Conference on Big Data (Big Data)"},{"key":"e_1_3_2_46_2","doi-asserted-by":"crossref","first-page":"260","DOI":"10.1007\/978-1-4899-7687-1_50","volume-title":"Proceedings of the Encyclopedia of Machine Learning and Data Mining","author":"Ting Kai Ming","year":"2017","unstructured":"Kai Ming Ting. 2017. Confusion matrix. In Proceedings of the Encyclopedia of Machine Learning and Data Mining. Claude Sammut and Geoffrey I. Webb (Eds.), Springer, 260."},{"key":"e_1_3_2_47_2","doi-asserted-by":"crossref","unstructured":"Denis Ugarte Davide Maiorca Fabrizio Cara and Giorgio Giacinto. 2019. PowerDrive: Accurate de-obfuscation and analysis of powershell malware. arXiv:1904.10270. Retrieved from https:\/\/arxiv.org\/abs\/1904.10270","DOI":"10.1007\/978-3-030-22038-9_12"},{"key":"e_1_3_2_48_2","first-page":"240","volume-title":"Proceedings of the 16th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","author":"Ugarte Denis","year":"2019","unstructured":"Denis Ugarte, Davide Maiorca, Fabrizio Cara, and Giorgio Giacinto. 2019. PowerDrive: Accurate de-obfuscation and analysis of powershell malware. In Proceedings of the 16th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment. 240\u2013259."},{"key":"e_1_3_2_49_2","doi-asserted-by":"crossref","unstructured":"Said Varlioglu Nelly Elsayed Zag ElSayed and Murat Ozer. 2022. The Dangerous Combo: Fileless Malware and Cryptojacking. (Mar2022).","DOI":"10.1109\/SoutheastCon48659.2022.9764043"},{"key":"e_1_3_2_50_2","unstructured":"Dan Virgillito. 2021. What is Malware Obfuscation. (Apr2021)."},{"key":"e_1_3_2_51_2","unstructured":"WatchGuard Technologies. 2022. Internet security report - quarter 4 2022. (2022)."}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3771542","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,19]],"date-time":"2025-11-19T16:40:13Z","timestamp":1763570413000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3771542"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":50,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2025,11,30]]}},"alternative-id":["10.1145\/3771542"],"URL":"https:\/\/doi.org\/10.1145\/3771542","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2024-01-19","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-07-26","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-11-19","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}