{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T14:47:36Z","timestamp":1785336456921,"version":"3.55.0"},"reference-count":76,"publisher":"Association for Computing Machinery (ACM)","issue":"2","funder":[{"DOI":"10.13039\/501100020950","name":"National Science and Technology Council","doi-asserted-by":"publisher","award":["109-2221-E-001-010-MY3, 110-2218-E-001-001-MBK"],"award-info":[{"award-number":["109-2221-E-001-010-MY3, 110-2218-E-001-001-MBK"]}],"id":[{"id":"10.13039\/501100020950","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2026,5,31]]},"abstract":"<jats:p>\n                    In this article, we focus on the robustness of behavior-based malware analysis models, justified by the need to address the high mutation rates of malware executables that debilitate conventional signature-based approaches and even behavior-based AI solutions. In response to these challenges, we propose MAMBA\n                    <jats:sup>+<\/jats:sup>\n                    , an obfuscation-resistant dynamic analysis approach tailored for uncovering malware behavior. We have assembled a comprehensive collection of behavioral obfuscation attacks designed to undermine behavior-based models. The central concept behind MAMBA\n                    <jats:sup>+<\/jats:sup>\n                    involves treating obfuscated calls as perturbed data and introducing a novel loss function to effectively balance ground-truth predictions and the handling of these perturbations. To facilitate this approach, MAMBA\n                    <jats:sup>+<\/jats:sup>\n                    designs adapted embedding mechanisms to transform traces of API calls into high-dimensional vectors for attention calculations. Through a comprehensive empirical study with seven obfuscations and three unseen attacks, we reveal important qualitative properties of MAMBA\n                    <jats:sup>+<\/jats:sup>\n                    , and quantitatively demonstrate its superiority in performance and robustness to all compared methods.\n                  <\/jats:p>","DOI":"10.1145\/3799692","type":"journal-article","created":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T11:40:49Z","timestamp":1772106049000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Resilient Dynamic Analysis for Windows Malware Technique Discovery against Behavior Obfuscation"],"prefix":"10.1145","volume":"29","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6315-8927","authenticated-orcid":false,"given":"Yi-Ting","family":"Huang","sequence":"first","affiliation":[{"name":"National Taiwan University of Science and Technology","place":["Taipei, Taiwan"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8784-9976","authenticated-orcid":false,"given":"Lisa","family":"Liu","sequence":"additional","affiliation":[{"name":"University of New South Wales","place":["Sydney, Australia"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7508-0397","authenticated-orcid":false,"given":"Ying-Ren","family":"Guo","sequence":"additional","affiliation":[{"name":"Academia Sinica","place":["Taipei, Taiwan"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1748-7818","authenticated-orcid":false,"given":"Guo-Wei","family":"Wong","sequence":"additional","affiliation":[{"name":"National Taiwan University","place":["Taipei, Taiwan"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7934-5658","authenticated-orcid":false,"given":"Timothy","family":"Lynar","sequence":"additional","affiliation":[{"name":"University of New South Wales","place":["Sydney, Australia"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6815-2436","authenticated-orcid":false,"given":"Meng Chang","family":"Chen","sequence":"additional","affiliation":[{"name":"Academia Sinica","place":["Taipei, Taiwan"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,3,24]]},"reference":[{"key":"e_1_3_3_2_2","unstructured":"[n.d.]. Cuckoo dataset - Google Drive. Retrieved from https:\/\/drive.google.com\/drive\/folders\/1juNrSMY8lQHzfwI7YVlW1yiJId8j1H-9. Accessed: 2022-1-20."},{"key":"e_1_3_3_3_2","unstructured":"[n.d.]. MalShare. Retrieved from https:\/\/malshare.com\/"},{"key":"e_1_3_3_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3365001"},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2018.8461583"},{"key":"e_1_3_3_6_2","first-page":"1","volume-title":"IEEE Military Communications Conference","author":"Agrawal Rakshit","year":"2018","unstructured":"Rakshit Agrawal, Jack W. Stokes, Mady Marinescu, and Karthik Selvaraj. 2018. Robust neural malware detection models for emulation sequence learning. In IEEE Military Communications Conference. IEEE, 1\u20138."},{"key":"e_1_3_3_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/CNS48642.2020.9162207"},{"key":"e_1_3_3_8_2","first-page":"688","volume-title":"ICISSP","author":"Ali Muhammad","year":"2022","unstructured":"Muhammad Ali, Monem Hamid, Jacob Jasser, Joachim Lerman, Samod Shetty, and Fabio Di Troia. 2022. Profile hidden markov model malware detection and API call obfuscation. In ICISSP. 688\u2013695."},{"key":"e_1_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101760"},{"key":"e_1_3_3_10_2","volume-title":"30th Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\)  Security 21)","author":"Azizi Ahmadreza","year":"2021","unstructured":"Ahmadreza Azizi, Ibrahim Asadullah Tahmid, Asim Waheed, Neal Mangaokar, Jiameng Pu, Mobin Javed, Chandan K. Reddy, and Bimal Viswanath. 2021. T-Miner: A generative approach to defend against trojan attacks on DNN-based text classification. In 30th Security Symposium ( \\(\\lbrace\\) USENIX \\(\\rbrace\\) Security 21)."},{"key":"e_1_3_3_11_2","unstructured":"Arini Balakrishnan and Chloe Schulze. 2005. Code obfuscation literature survey. CS701 Construction of Compilers 19 31 (2005) 10."},{"key":"e_1_3_3_12_2","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1109\/MALWARE.2015.7413683","volume-title":"2015 10th International Conference on Malicious and Unwanted Software (MALWARE)","author":"Banescu Sebastian","year":"2015","unstructured":"Sebastian Banescu, Tobias Wuchner, Aleieldin Salem, Marius Guggenmos, Mart\u0131n Ochoa, and Alexander Pretschner. 2015. A framework for empirical evaluation of malware detection resilience against behavior obfuscation. In 2015 10th International Conference on Malicious and Unwanted Software (MALWARE). 40\u201347."},{"key":"e_1_3_3_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833659"},{"key":"e_1_3_3_14_2","doi-asserted-by":"crossref","first-page":"249","DOI":"10.1007\/978-3-030-11289-9_11","volume-title":"Blockchain and Clinical Trial: Securing Patient Data","author":"Beavers Jake","year":"2019","unstructured":"Jake Beavers and Sina Pournouri. 2019. Recent cyber attacks and vulnerabilities in medical devices and healthcare institutions. In Blockchain and Clinical Trial: Securing Patient Data. Hamid Jahankhani, Stefan Kendzierskyj, Arshad Jamal, Gregory Epiphaniou, and Haider Al-Khateeb (Eds.). Springer International Publishing, Cham, 249\u2013267."},{"key":"e_1_3_3_15_2","doi-asserted-by":"publisher","DOI":"10.1145\/3371924"},{"key":"e_1_3_3_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2879302"},{"key":"e_1_3_3_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2018.00009"},{"key":"e_1_3_3_18_2","first-page":"2343","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Chen Yizheng","year":"2020","unstructured":"Yizheng Chen, Shiqi Wang, Dongdong She, and Suman Jana. 2020. On training robust PDF malware classifiers. In 29th USENIX Security Symposium (USENIX Security 20). 2343\u20132360."},{"key":"e_1_3_3_19_2","doi-asserted-by":"publisher","DOI":"10.1093\/comjnl\/bxz033"},{"key":"e_1_3_3_20_2","volume-title":"12th Security Symposium (USENIX Security 03)","author":"Christodorescu Mihai","year":"2003","unstructured":"Mihai Christodorescu and Somesh Jha. 2003. Static analysis of executables to detect malicious patterns. In 12th Security Symposium (USENIX Security 03)."},{"key":"e_1_3_3_21_2","unstructured":"Cuckoo Sandbox. [n.d.]. Retrieved from https:\/\/cuckoosandbox.org\/"},{"key":"e_1_3_3_22_2","unstructured":"Jacob Devlin Ming-Wei Chang Kenton Lee and Kristina Toutanova. 2018. Bert: Pre-training of deep bidirectional transformers for language understanding. arXiv:1810.04805. Retrieved from https:\/\/arxiv.org\/abs\/1810.04805"},{"key":"e_1_3_3_23_2","first-page":"85","volume-title":"SECURIT","author":"Faruki Parvez","year":"2012","unstructured":"Parvez Faruki, Vijay Laxmi, Manoj Singh Gaur, and P Vinod. 2012. Behavioural detection with API call-grams to identify malicious PE files. In SECURIT. 85\u201391."},{"issue":"6","key":"e_1_3_3_24_2","first-page":"1276","article-title":"Malware analysis by combining multiple detectors and observation windows","volume":"71","author":"Ficco Massimo","year":"2021","unstructured":"Massimo Ficco. 2021. Malware analysis by combining multiple detectors and observation windows. IEEE Trans. Comput. 71, 6 (2021), 1276\u20131290.","journal-title":"IEEE Trans. Comput."},{"key":"e_1_3_3_25_2","first-page":"272","volume-title":"2019 IEEE\/ACM 41st International Conference on Software Engineering: Companion Proceedings (ICSE-Companion)","author":"Fu Xiaoqin","year":"2019","unstructured":"Xiaoqin Fu and Haipeng Cai. 2019. On the deterioration of learning-based malware detectors for android. In 2019 IEEE\/ACM 41st International Conference on Software Engineering: Companion Proceedings (ICSE-Companion). IEEE, 272\u2013273."},{"key":"e_1_3_3_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3638552"},{"key":"e_1_3_3_27_2","unstructured":"Ian J. Goodfellow Jonathon Shlens and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv:1412.6572. Retrieved from https:\/\/arxiv.org\/abs\/1412.6572"},{"key":"e_1_3_3_28_2","unstructured":"Kathrin Grosse Nicolas Papernot Praveen Manoharan Michael Backes and Patrick McDaniel. 2016. Adversarial perturbations against deep neural networks for malware classification. arXiv:1606.04435. Retrieved from https:\/\/arxiv.org\/abs\/1606.04435"},{"key":"e_1_3_3_29_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2018.02.008"},{"key":"e_1_3_3_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2969514"},{"key":"e_1_3_3_31_2","unstructured":"Yi-Ting Huang Chi Yu Lin Ying-Ren Guo Kai-Chieh Lo Yeali S. Sun and Meng Chang Chen. 2021. Open source intelligence for malicious behavior discovery and interpretation. IEEE Transactions on Dependable and Secure Computing 19 2 (2021) 776\u2013789."},{"key":"e_1_3_3_32_2","series-title":"IWSPA\u201918","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1145\/3180445.3180449","volume-title":"Proceedings of the Fourth ACM International Workshop on Security and Privacy Analytics","author":"Romeo \u00cd\u00f1igo \u00cdncer","year":"2018","unstructured":"\u00cd\u00f1igo \u00cdncer Romeo, Michael Theodorides, Sadia Afroz, and David Wagner. 2018. Adversarially robust malware detection using monotonic classification. In Proceedings of the Fourth ACM International Workshop on Security and Privacy Analytics (Tempe, AZ, USA) (IWSPA\u201918). Association for Computing Machinery, New York, NY, USA, 54\u201363."},{"key":"e_1_3_3_33_2","volume-title":"10th USENIX Workshop on Offensive Technologies (WOOT\u201916)","author":"Ispoglou Kyriakos K.","year":"2016","unstructured":"Kyriakos K. Ispoglou and Mathias Payer. 2016. malWASH: Washing malware to evade dynamic analysis. In 10th USENIX Workshop on Offensive Technologies (WOOT\u201916)."},{"key":"e_1_3_3_34_2","first-page":"277","article-title":"Cybersecurity for financial institutions: The integral role of information sharing in cyber attack mitigation","volume":"20","author":"Johnson Ariana L.","year":"2016","unstructured":"Ariana L. Johnson. 2016. Cybersecurity for financial institutions: The integral role of information sharing in cyber attack mitigation. NC Banking Inst. 20, 1 (2016), 277.","journal-title":"NC Banking Inst."},{"key":"e_1_3_3_35_2","doi-asserted-by":"publisher","DOI":"10.1198\/tech.2003.s783"},{"issue":"1","key":"e_1_3_3_36_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3372823","article-title":"The AI-based cyber threat landscape: A survey","volume":"53","author":"Kaloudi Nektaria","year":"2020","unstructured":"Nektaria Kaloudi and Jingyue Li. 2020. The AI-based cyber threat landscape: A survey. Comput. Surveys 53, 1 (2020), 1\u201334.","journal-title":"Comput. Surveys"},{"key":"e_1_3_3_37_2","doi-asserted-by":"crossref","unstructured":"Shinichi Kamiya Jun-Koo Kang Jungmin Kim Andreas Milidonis and Ren\u00e9 M. Stulz. 2018. What is the Impact of Successful Cyberattacks on Target Firms? National Bureau of Economic Research.","DOI":"10.3386\/w24409"},{"key":"e_1_3_3_38_2","doi-asserted-by":"publisher","DOI":"10.1155\/2015\/659101"},{"key":"e_1_3_3_39_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-50127-7_11"},{"key":"e_1_3_3_40_2","first-page":"137","volume-title":"AI 2016: Advances in Artificial Intelligence: 29th Australasian Joint Conference, Hobart, TAS, Australia, December 5-8, 2016, Proceedings 29","author":"Kolosnjaji Bojan","year":"2016","unstructured":"Bojan Kolosnjaji, Apostolis Zarras, George Webster, and Claudia Eckert. 2016. Deep learning for classification of malware system call sequences. In AI 2016: Advances in Artificial Intelligence: 29th Australasian Joint Conference, Hobart, TAS, Australia, December 5-8, 2016, Proceedings 29. Springer, 137\u2013149."},{"key":"e_1_3_3_41_2","first-page":"15","article-title":"Metamorphic virus: Analysis and detection","volume":"15","author":"Konstantinou Evgenios","year":"2008","unstructured":"Evgenios Konstantinou and Stefen Wolthusen. 2008. Metamorphic virus: Analysis and detection. Royal Holloway University of London 15 (2008), 15.","journal-title":"Royal Holloway University of London"},{"key":"e_1_3_3_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379443"},{"key":"e_1_3_3_43_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-011-0157-5"},{"key":"e_1_3_3_44_2","doi-asserted-by":"publisher","DOI":"10.3390\/computers12100195"},{"key":"e_1_3_3_45_2","doi-asserted-by":"crossref","unstructured":"Henry B. Mann and Donald R. Whitney. 1947. On a test of whether one of two random variables is stochastically larger than the other. The Annals of Mathematical Statistics. 50\u201360.","DOI":"10.1214\/aoms\/1177730491"},{"key":"e_1_3_3_46_2","unstructured":"Marco Melis Michele Scalas Ambra Demontis Davide Maiorca Battista Biggio Giorgio Giacinto and Fabio Roli. 2020. Do gradient-based explanations tell anything about adversarial robustness to android malware? arXiv:2005.01452. Retrieved from https:\/\/arxiv.org\/abs\/2005.01452"},{"issue":"4","key":"e_1_3_3_47_2","article-title":"Getting ahead of the arms race: Hothousing the coevolution of VirusTotal with a packer","volume":"23","author":"Men\u00e9ndez H\u00e9ctor D.","year":"2021","unstructured":"H\u00e9ctor D. Men\u00e9ndez, David Clark, and Earl T. Barr. 2021. Getting ahead of the arms race: Hothousing the coevolution of VirusTotal with a packer. Entropy 23, 4 (March2021), 395\u2013413.","journal-title":"Entropy"},{"key":"e_1_3_3_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3600160.3605037"},{"key":"e_1_3_3_49_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-016-0281-3"},{"key":"e_1_3_3_50_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-016-0281-3"},{"key":"e_1_3_3_51_2","doi-asserted-by":"crossref","first-page":"378","DOI":"10.1007\/978-3-642-40576-1_37","volume-title":"Security in Computing and Communications","author":"Natani Pratiksha","year":"2013","unstructured":"Pratiksha Natani and Deepti Vidyarthi. 2013. Malware detection using API function frequency with ensemble based classifier. In Security in Computing and Communications. Springer Berlin, 378\u2013388."},{"issue":"6","key":"e_1_3_3_52_2","doi-asserted-by":"crossref","first-page":"895","DOI":"10.1111\/puar.13028","article-title":"Cyberattacks at the grass roots: American local governments and the need for high levels of cybersecurity","volume":"79","author":"Norris Donald F","year":"2019","unstructured":"Donald F Norris, Laura Mateczun, Anupam Joshi, and Tim Finin. 2019. Cyberattacks at the grass roots: American local governments and the need for high levels of cybersecurity. Public Adm. Rev. 79, 6 (Nov.2019), 895\u2013904.","journal-title":"Public Adm. Rev."},{"key":"e_1_3_3_53_2","first-page":"406","volume-title":"International Conference on Security and Privacy in Communication Systems","author":"Oosthoek Kris","year":"2019","unstructured":"Kris Oosthoek and Christian Doerr. 2019. SoK: ATT&CK techniques and trends in windows malware. In International Conference on Security and Privacy in Communication Systems. Springer, 406\u2013425."},{"key":"e_1_3_3_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3329786"},{"key":"e_1_3_3_55_2","doi-asserted-by":"crossref","first-page":"1916","DOI":"10.1109\/ICASSP.2015.7178304","volume-title":"2015 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","author":"Pascanu Razvan","year":"2015","unstructured":"Razvan Pascanu, Jack W. Stokes, Hermineh Sanossian, Mady Marinescu, and Anil Thomas. 2015. Malware classification with recurrent networks. In 2015 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). IEEE, 1916\u20131920."},{"key":"e_1_3_3_56_2","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1007\/978-3-319-06089-7_20","volume-title":"Theory and Applications of Models of Computation: 11th Annual Conference, TAMC 2014, Chennai, India, April 11-13, 2014. Proceedings 11","author":"P\u00e9choux Romain","year":"2014","unstructured":"Romain P\u00e9choux and Thanh Dinh Ta. 2014. A categorical treatment of malicious behavioral obfuscation. In Theory and Applications of Models of Computation: 11th Annual Conference, TAMC 2014, Chennai, India, April 11-13, 2014. Proceedings 11. Springer, 280\u2013299."},{"key":"e_1_3_3_57_2","doi-asserted-by":"publisher","DOI":"10.5555\/1953048.2078195"},{"key":"e_1_3_3_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/1190215.1190270"},{"key":"e_1_3_3_59_2","series-title":"ACSAC\u201920","doi-asserted-by":"crossref","first-page":"54","DOI":"10.1145\/3427228.3427242","volume-title":"Annual Computer Security Applications Conference","author":"Rabadi Dima","year":"2020","unstructured":"Dima Rabadi and Sin G. Teo. 2020. Advanced windows methods on malware detection and classification. In Annual Computer Security Applications Conference (Austin, USA) (ACSAC\u201920). Association for Computing Machinery, New York, NY, USA, 54\u201368."},{"key":"e_1_3_3_60_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.fsidi.2021.301183"},{"key":"e_1_3_3_61_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-70542-0_6"},{"key":"e_1_3_3_62_2","doi-asserted-by":"crossref","first-page":"490","DOI":"10.1007\/978-3-030-00470-5_23","volume-title":"Research in Attacks, Intrusions, and Defenses: 21st International Symposium","author":"Rosenberg Ishai","year":"2018","unstructured":"Ishai Rosenberg, Asaf Shabtai, Lior Rokach, and Yuval Elovici. 2018. Generic black-box end-to-end attack against state of the art API call based malware classifiers. In Research in Attacks, Intrusions, and Defenses: 21st International Symposium. Springer, 490\u2013510."},{"key":"e_1_3_3_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/MALWARE.2015.7413680"},{"key":"e_1_3_3_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2019.2945767"},{"key":"e_1_3_3_65_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484570"},{"key":"e_1_3_3_66_2","unstructured":"Zhanna Malekos Smith Eugenia Lostri and James A. Lewis. 2020. McAfee: The hidden costs of cybercrime. https:\/\/www.mcafee.com\/enterprise\/en-us\/assets\/reports\/rp-hidden-costs-of-cybercrime.pdf. (2020)."},{"key":"e_1_3_3_67_2","unstructured":"Blake E. Strom Andy Applebaum Doug P. Miller Kathryn C. Nickels Adam G. Pennington and Cody B. Thomas. 2018. MITRE ATT&CK: Design and philosophy. Retrieved from https:\/\/www.mitre.org\/sites\/default\/files\/publications\/pr-18-0944-11-mitre-attack-design-and-philosophy.pdf"},{"key":"e_1_3_3_68_2","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2019.00015"},{"key":"e_1_3_3_69_2","doi-asserted-by":"crossref","first-page":"698","DOI":"10.1007\/978-3-642-15497-3_42","volume-title":"Computer Security \u2013 ESORICS 2010","author":"Tokhtabayev Arnur G.","year":"2010","unstructured":"Arnur G. Tokhtabayev, Victor A. Skormin, and Andrey M. Dolgikh. 2010. Expressive, efficient and obfuscation resilient behavior based IDS. In Computer Security \u2013 ESORICS 2010. 698\u2013715."},{"key":"e_1_3_3_70_2","series-title":"CCS\u201902","doi-asserted-by":"crossref","first-page":"255","DOI":"10.1145\/586110.586145","volume-title":"Proceedings of the 9th ACM conference on Computer and Communications Security","author":"Wagner David","year":"2002","unstructured":"David Wagner and Paolo Soto. 2002. Mimicry attacks on host-based intrusion detection systems. In Proceedings of the 9th ACM conference on Computer and Communications Security (Washington, DC, USA) (CCS\u201902). Association for Computing Machinery, New York, NY, USA, 255\u2013264."},{"key":"e_1_3_3_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_3_72_2","first-page":"1","volume-title":"2020 IEEE Wireless Communications and Networking Conference (WCNC)","author":"Wang Ji","year":"2020","unstructured":"Ji Wang, Qi Jing, Jianbo Gao, and Xuanwei Qiu. 2020. SEdroid: A robust android malware detector using selective ensemble learning. In 2020 IEEE Wireless Communications and Networking Conference (WCNC). 1\u20135."},{"key":"e_1_3_3_73_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.6"},{"key":"e_1_3_3_74_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11416-006-0028-7"},{"key":"e_1_3_3_75_2","unstructured":"Yonghui Wu Mike Schuster Zhifeng Chen Quoc V Le Mohammad Norouzi Wolfgang Macherey Maxim Krikun Yuan Cao Qin Gao Klaus Macherey et\u00a0al. 2016. Google\u2019s neural machine translation system: Bridging the gap between human and machine translation. arXiv:1609.08144. Retrieved from https:\/\/arxiv.org\/abs\/1609.08144"},{"key":"e_1_3_3_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2017.2675881"},{"key":"e_1_3_3_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/BWCCA.2010.85"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3799692","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,24]],"date-time":"2026-03-24T10:51:37Z","timestamp":1774349497000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3799692"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,24]]},"references-count":76,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,5,31]]}},"alternative-id":["10.1145\/3799692"],"URL":"https:\/\/doi.org\/10.1145\/3799692","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,24]]},"assertion":[{"value":"2023-09-24","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-02-07","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-03-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}