{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,28]],"date-time":"2026-08-28T17:02:46Z","timestamp":1787936566592,"version":"build-2784847793"},"reference-count":64,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,4,29]],"date-time":"2025-04-29T00:00:00Z","timestamp":1745884800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,4,29]],"date-time":"2025-04-29T00:00:00Z","timestamp":1745884800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100008793","name":"Universidad del Rosario","doi-asserted-by":"publisher","award":["EDI 2022-1"],"award-info":[{"award-number":["EDI 2022-1"]}],"id":[{"id":"10.13039\/501100008793","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100019622","name":"Ministerio de Comercio, Industria y Turismo","doi-asserted-by":"publisher","award":["TED 2021- 129300B-I00"],"award-info":[{"award-number":["TED 2021- 129300B-I00"]}],"id":[{"id":"10.13039\/100019622","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100019622","name":"Ministerio de Comercio, Industria y Turismo","doi-asserted-by":"publisher","award":["PID2021 - 122466OB - I00"],"award-info":[{"award-number":["PID2021 - 122466OB - I00"]}],"id":[{"id":"10.13039\/100019622","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100023561","name":"Ministerio de Universidades","doi-asserted-by":"publisher","award":["172\/MSJD\/22"],"award-info":[{"award-number":["172\/MSJD\/22"]}],"id":[{"id":"10.13039\/501100023561","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007065","name":"Nvidia","doi-asserted-by":"publisher","award":["Nvidia Academic Grant Program"],"award-info":[{"award-number":["Nvidia Academic Grant Program"]}],"id":[{"id":"10.13039\/100007065","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>The existence of malicious software (malware) represents a potential threat to users who connect to a large set of services provided by multiple providers. Such malware is capable of stealing, spying on, encrypting data from users, and spreading, provoking impacts that are beyond a single citizen\u2019s device and reaching critical information systems. To detect malware families, Machine Learning and Deep Learning techniques have been employed recently, demonstrating promising results. However, these techniques lack in detecting more advanced malware that employs obfuscation techniques. In this paper, we present DEFENDIFY, a novel framework, empowered by Computer Vision, Deep Learning, and Transfer Learning techniques, that is able to detect completely obfuscated malware with high performance in terms of accuracy and computational consumption. DEFENDIFY comprises three modules: Dataset Creation, Binary Obfuscation, and Model Generation. These modules work together to detect both obfuscated and non-obfuscated malware. The core module, i.e., the Model Generation, employs an entropy tester that determines whether a sample is obfuscated or not. Then, a Deep Learning model powered by Transfer Learning is employed to determine if it is malware or goodware. We validated our framework using real data gathered from malware repositories and legitimate software. The proposed framework was configured to test four Convolutional Neural Network architectures: ResNet18, ResNet34, EfficientNetB3, and EfficientNetV2S. Among them, the ResNet18 architecture obtained the best performance in detecting both non-obfuscated and obfuscated samples with an F1-score of 99.34% and 97.5%, respectively.<\/jats:p>","DOI":"10.1186\/s42400-025-00396-z","type":"journal-article","created":{"date-parts":[[2025,4,29]],"date-time":"2025-04-29T02:02:56Z","timestamp":1745892176000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["DEFENDIFY: defense amplified with transfer learning for obfuscated malware framework"],"prefix":"10.1186","volume":"8","author":[{"given":"Rodrigo","family":"Castillo Camargo","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Juan","family":"Murcia Nieto","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nicol\u00e1s","family":"Rojas","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7244-2631","authenticated-orcid":false,"given":"Daniel","family":"D\u00edaz-L\u00f3pez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Santiago","family":"Alf\u00e9rez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Angel Luis","family":"Perales G\u00f3mez","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pantaleone","family":"Nespoli","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"F\u00e9lix","family":"G\u00f3mez M\u00e1rmol","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Umit","family":"Karabiyik","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,29]]},"reference":[{"key":"396_CR1","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/978-3-319-15618-7_5","volume-title":"Engineering secure software and systems","author":"K Allix","year":"2015","unstructured":"Allix K, Bissyand\u00e9 TF, Klein J et al (2015) Are your training datasets yet relevant? In: Piessens F, Caballero J, Bielova N (eds) Engineering secure software and systems. Springer, Cham, pp 51\u201367"},{"key":"396_CR2","doi-asserted-by":"crossref","unstructured":"Balram N, Hsieh G, McFall C (2019) Static malware analysis using machine learning algorithms on APT1 dataset with string and PE header features. In: 2019 International conference on computational science and computational intelligence (CSCI). IEEE, pp 90\u201395","DOI":"10.1109\/CSCI49370.2019.00022"},{"issue":"3","key":"396_CR3","doi-asserted-by":"publisher","first-page":"227","DOI":"10.1007\/s10207-016-0330-4","volume":"16","author":"M Bat-Erdene","year":"2017","unstructured":"Bat-Erdene M, Park H, Li H et al (2017) Entropy analysis to classify unknown packing algorithms for malware detection. Int J Inf Secur 16(3):227\u2013248. https:\/\/doi.org\/10.1007\/s10207-016-0330-4","journal-title":"Int J Inf Secur"},{"issue":"3","key":"396_CR4","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1109\/TPAMI.1980.4767015","volume":"2","author":"M Ben-Bassat","year":"1980","unstructured":"Ben-Bassat M, Klove KL, Weil MH (1980) Sensitivity analysis in Bayesian classification models: multiplicative deviations. IEEE Trans Pattern Anal Mach Intell PAMI 2(3):261\u2013266. https:\/\/doi.org\/10.1109\/TPAMI.1980.4767015","journal-title":"IEEE Trans Pattern Anal Mach Intell PAMI"},{"issue":"6","key":"396_CR5","first-page":"1022","volume":"22","author":"A Bensaoud","year":"2020","unstructured":"Bensaoud A, Abudawaood N, Kalita J (2020) Classifying malware images with convolutional neural network models. Int J Netw Secur 22(6):1022\u20131031","journal-title":"Int J Netw Secur"},{"key":"396_CR6","unstructured":"Bergstra J, Bardenet R, Bengio Y, et\u00a0al (2011) Algorithms for hyper-parameter optimization. In: Proceedings of the 24th international conference on neural information processing systems. Curran Associates Inc., Granada, Spain, NIPS\u201911, pp 2546\u20132554"},{"key":"396_CR7","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1023\/A:1010950718922","volume":"45","author":"L Breiman","year":"2001","unstructured":"Breiman L (2001) Random forests. Mach Learn 45:5\u201332. https:\/\/doi.org\/10.1023\/A:1010950718922","journal-title":"Mach Learn"},{"key":"396_CR8","doi-asserted-by":"publisher","unstructured":"Burita L, Le DT (2021) Cyber security and apt groups. In: 2021 Communication and information technologies (KIT), pp 1\u20137. https:\/\/doi.org\/10.1109\/KIT52904.2021.9583744","DOI":"10.1109\/KIT52904.2021.9583744"},{"key":"396_CR9","doi-asserted-by":"publisher","unstructured":"Ceschin F, Botacin M, L\u00fcders G, et\u00a0al (2021) No need to teach new tricks to old malware: winning an evasion challenge with xor-based adversarial samples. In: Reversing and offensive-oriented trends symposium. Association for Computing Machinery, Vienna, ROOTS\u201920, pp 13\u201322. https:\/\/doi.org\/10.1145\/3433667.3433669","DOI":"10.1145\/3433667.3433669"},{"key":"396_CR10","volume":"70","author":"M Conti","year":"2022","unstructured":"Conti M, Vinod P, Vitella A (2022) Obfuscation detection in android applications using deep learning. J Inf Secur Appl 70:103311","journal-title":"J Inf Secur Appl"},{"issue":"1","key":"396_CR11","doi-asserted-by":"publisher","first-page":"21","DOI":"10.1109\/TIT.1967.1053964","volume":"13","author":"T Cover","year":"1967","unstructured":"Cover T, Hart P (1967) Nearest neighbor pattern classification. IEEE Trans Inf Theory 13(1):21\u201327. https:\/\/doi.org\/10.1109\/TIT.1967.1053964","journal-title":"IEEE Trans Inf Theory"},{"key":"396_CR12","series-title":"Monographs on statistics and applied probability","volume-title":"Analysis of binary data","author":"D Cox","year":"1989","unstructured":"Cox D (1989) Analysis of binary data, 2nd edn. Monographs on statistics and applied probability. Chapman and Hall, London","edition":"2"},{"key":"396_CR13","unstructured":"Cyberfish (2025) Zero phishing protection for MSPs and SMB | cofense protect. https:\/\/cofense.com\/. Accessed 15 Mar 2025"},{"key":"396_CR14","doi-asserted-by":"publisher","DOI":"10.3390\/sym10120669","author":"D D\u00edaz-L\u00f3pez","year":"2018","unstructured":"D\u00edaz-L\u00f3pez D, Blanco Uribe M, Santiago Cely C et al (2018) Developing secure IoT services: a security-oriented review of IoT platforms. Symmetry. https:\/\/doi.org\/10.3390\/sym10120669","journal-title":"Symmetry"},{"issue":"1","key":"396_CR15","first-page":"366","volume":"10","author":"H El Merabet","year":"2019","unstructured":"El Merabet H, Hajraoui A (2019) A survey of malware detection techniques based on machine learning. Int J Adv Comput Sci Appl 10(1):366\u2013373","journal-title":"Int J Adv Comput Sci Appl"},{"key":"396_CR16","first-page":"502","volume-title":"Inf Secur","author":"R Farley","year":"2014","unstructured":"Farley R, Wang X (2014) Codext: automatic extraction of obfuscated attack code from memory dump. In: Chow SSM, Camenisch J, Hui LCK et al (eds) Inf Secur. Springer, Cham, pp 502\u2013514"},{"issue":"2","key":"396_CR17","doi-asserted-by":"publisher","first-page":"179","DOI":"10.1111\/j.1469-1809.1936.tb02137.x","volume":"7","author":"RA Fisher","year":"1936","unstructured":"Fisher RA (1936) The use of multiple measurements in taxonomic problems. Ann Eugen 7(2):179\u2013188. https:\/\/doi.org\/10.1111\/j.1469-1809.1936.tb02137.x","journal-title":"Ann Eugen"},{"key":"396_CR18","volume-title":"Hands-on machine learning with scikit-learn, keras, and tensorflow","author":"A G\u00e9ron","year":"2019","unstructured":"G\u00e9ron A (2019) Hands-on machine learning with scikit-learn, keras, and tensorflow. O\u2019Reilly Media Inc, Newton"},{"key":"396_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2019.107037","volume":"168","author":"D Glaroudis","year":"2020","unstructured":"Glaroudis D, Iossifides A, Chatzimisios P (2020) Survey, comparison and research challenges of IoT application protocols for smart farming. Comput Netw 168:107037","journal-title":"Comput Netw"},{"key":"396_CR20","volume-title":"Ethical hacking: a hands-on introduction to breaking in","author":"D Graham","year":"2021","unstructured":"Graham D (2021) Ethical hacking: a hands-on introduction to breaking in. No Starch Press, San Francisco"},{"key":"396_CR21","doi-asserted-by":"crossref","unstructured":"Guo Y, Fan W (2019) Feature collection and selection in malware classification. In: Proceedings of the 2019 international conference on artificial intelligence and advanced manufacturing, pp 1\u20135","DOI":"10.1145\/3358331.3358342"},{"key":"396_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101762","volume":"92","author":"P Hakon","year":"2020","unstructured":"Hakon P, Fareed Y, Sindre G (2020) The ransomware-as-a-service economy within the darknet. Comput Secur 92:101762. https:\/\/doi.org\/10.1016\/j.cose.2020.101762","journal-title":"Comput Secur"},{"issue":"17","key":"396_CR23","doi-asserted-by":"publisher","first-page":"3393","DOI":"10.3390\/electronics13173393","volume":"13","author":"S Han","year":"2024","unstructured":"Han S, Yun H, Park Y (2024) Deep learning for cybersecurity classification: utilizing depth-wise CNN and attention mechanism on VM-obfuscated data. Electronics 13(17):3393","journal-title":"Electronics"},{"key":"396_CR24","doi-asserted-by":"crossref","unstructured":"Hussain A, Asif M, Ahmad MB, et\u00a0al (2022) Malware detection using machine learning algorithms for windows platform. In: Proceedings of international conference on information technology and applications: ICITA 2021. Springer, pp 619\u2013632","DOI":"10.1007\/978-981-16-7618-5_53"},{"issue":"2","key":"396_CR25","first-page":"333","volume":"8","author":"J Iaksch","year":"2021","unstructured":"Iaksch J, Fernandes E, Borsato M (2021) Digitalization and big data in smart farming\u2014a review. J Manag Anal 8(2):333\u2013349","journal-title":"J Manag Anal"},{"key":"396_CR26","doi-asserted-by":"publisher","first-page":"242","DOI":"10.1007\/978-3-030-63095-9_14","volume-title":"Security and privacy in communication networks","author":"Y Jiang","year":"2020","unstructured":"Jiang Y, Li R, Tang J et al (2020) Aomdroid: detecting obfuscation variants of android malware using transfer learning. In: Park N, Sun K, Foresti S et al (eds) Security and privacy in communication networks. Springer, Cham, pp 242\u2013253"},{"key":"396_CR27","doi-asserted-by":"crossref","unstructured":"Joshi S, Upadhyay H, Lagos L, et\u00a0al (2018) Machine learning approach for malware detection using random forest classifier on process list data structure. In: Proceedings of the 2nd international conference on information system and data mining, pp 98\u2013102","DOI":"10.1145\/3206098.3206113"},{"key":"396_CR28","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2022.107703","volume":"98","author":"AG Kakisim","year":"2022","unstructured":"Kakisim AG, Gulmez S, Sogukpinar I (2022) Sequential opcode embedding-based malware detection method. Comput Electr Eng 98:107703","journal-title":"Comput Electr Eng"},{"key":"396_CR29","unstructured":"Ke G, Meng Q, Finley T, et\u00a0al (2017) Lightgbm: a highly efficient gradient boosting decision tree. In: Advances in neural information processing systems, vol\u00a030. Curran Associates, Inc., Long Beach"},{"key":"396_CR30","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1016\/j.ins.2018.04.092","volume":"460\u2013461","author":"JY Kim","year":"2018","unstructured":"Kim JY, Bu SJ, Cho SB (2018) Zero-day malware detection using transferred generative adversarial networks based on deep autoencoders. Inf Sci 460\u2013461:83\u2013102. https:\/\/doi.org\/10.1016\/j.ins.2018.04.092","journal-title":"Inf Sci"},{"key":"396_CR31","doi-asserted-by":"publisher","first-page":"18855","DOI":"10.1109\/ACCESS.2023.3247344","volume":"11","author":"H Lee","year":"2023","unstructured":"Lee H, Kim S, Baek D et al (2023) Robust IoT malware detection and classification using opcode category features on machine learning. IEEE Access 11:18855\u201318867","journal-title":"IEEE Access"},{"key":"396_CR32","doi-asserted-by":"publisher","first-page":"39","DOI":"10.1186\/s13638-022-02103-9","volume":"1","author":"M Li","year":"2022","unstructured":"Li M, Han D, Li D et al (2022) MFVT: an anomaly traffic detection method merging feature fusion network and vision transformer architecture. EURASIP J Wirel Commun Netw 1:39","journal-title":"EURASIP J Wirel Commun Netw"},{"issue":"2","key":"396_CR33","doi-asserted-by":"publisher","first-page":"40","DOI":"10.1109\/MSP.2007.48","volume":"5","author":"R Lyda","year":"2007","unstructured":"Lyda R, Hamrock J (2007) Using entropy analysis to find encrypted and packed malware. IEEE Secur Priv 5(2):40\u201345. https:\/\/doi.org\/10.1109\/MSP.2007.48","journal-title":"IEEE Secur Priv"},{"key":"396_CR34","doi-asserted-by":"publisher","first-page":"7999","DOI":"10.1016\/j.egyr.2021.08.124","volume":"7","author":"C Ma","year":"2021","unstructured":"Ma C (2021) Smart city and cyber-security; technologies used, leading challenges and future recommendations. Energy Rep 7:7999\u20138012","journal-title":"Energy Rep"},{"issue":"4","key":"396_CR35","doi-asserted-by":"publisher","first-page":"279","DOI":"10.1007\/s11416-021-00381-3","volume":"17","author":"N Marastoni","year":"2021","unstructured":"Marastoni N, Giacobazzi R, Dalla Preda M (2021) Data augmentation and transfer learning to classify malware images in a deep learning context. J Comput Virol Hack Techn 17(4):279\u2013297. https:\/\/doi.org\/10.1007\/s11416-021-00381-3","journal-title":"J Comput Virol Hack Techn"},{"key":"396_CR36","doi-asserted-by":"publisher","first-page":"5415724","DOI":"10.1155\/2021\/5415724","volume":"2021","author":"I Mart\u00ednez Mart\u00ednez","year":"2021","unstructured":"Mart\u00ednez Mart\u00ednez I, Flori\u00e1n Quiti\u00e1n A, D\u00edaz-L\u00f3pez D et al (2021) Malseirs: forecasting malware spread based on compartmental models in epidemiology. Complexity 2021:5415724. https:\/\/doi.org\/10.1155\/2021\/5415724","journal-title":"Complexity"},{"key":"396_CR37","doi-asserted-by":"crossref","unstructured":"Mercaldo F, Ciaramella G, Santone A, et\u00a0al (2023) Obfuscated mobile malware detection by means of dynamic analysis and explainable deep learning. In: Proceedings of the 18th international conference on availability, reliability and security, pp 1\u201310","DOI":"10.1145\/3600160.3605037"},{"key":"396_CR38","unstructured":"Mimecast (2025) Cybergraph datasheet\u2013mimecast. https:\/\/www.mimecast.com\/resources\/datasheets\/cybergraph\/. Accessed 15 Mar 2025"},{"key":"396_CR39","unstructured":"Mitre (2025a) Abuse elevation control mechanism: device administrator permissions. https:\/\/attack.mitre.org\/techniques\/T1626\/001\/. Accessed 15 Mar 2025"},{"key":"396_CR40","unstructured":"Mitre (2025b) Dynamic resolution. https:\/\/attack.mitre.org\/techniques\/T1637\/. Accessed 15 Mar 2025"},{"key":"396_CR41","doi-asserted-by":"publisher","DOI":"10.3390\/s19071492","author":"P Nespoli","year":"2019","unstructured":"Nespoli P, Useche Pel\u00e1ez D, D\u00edaz-L\u00f3pez D et al (2019) Cosmos: collaborative, seamless and adaptive sentinel for the internet of things. Sensors. https:\/\/doi.org\/10.3390\/s19071492","journal-title":"Sensors"},{"key":"396_CR42","doi-asserted-by":"publisher","unstructured":"Pelaez DU, D\u00edaz-L\u00f3pez D, Nespoli P, et\u00a0al (2018) Tris: a three-rings IoT sentinel to protect against cyber-threats. In: 2018 Fifth international conference on internet of things: systems, management and security, pp 123\u2013130. https:\/\/doi.org\/10.1109\/IoTSMS.2018.8554432","DOI":"10.1109\/IoTSMS.2018.8554432"},{"issue":"21","key":"396_CR43","doi-asserted-by":"publisher","first-page":"4654","DOI":"10.3390\/s19214654","volume":"19","author":"J Pereira-Kohatsu","year":"2019","unstructured":"Pereira-Kohatsu J, Quijano-S\u00e1nchez L, Liberatore F et al (2019) Detecting and monitoring hate speech in twitter. Sensors 19(21):4654","journal-title":"Sensors"},{"key":"396_CR44","doi-asserted-by":"publisher","first-page":"61","DOI":"10.7551\/mitpress\/1113.003.0008","volume":"10","author":"J Platt","year":"2000","unstructured":"Platt J (2000) Probabilistic outputs for support vector machines and comparisons to regularized likelihood methods. Adv Large Margin Classif 10:61\u201374","journal-title":"Adv Large Margin Classif"},{"key":"396_CR45","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1016\/j.comcom.2022.08.015","volume":"195","author":"V Ravi","year":"2022","unstructured":"Ravi V, Alazab M, Selvaganapathy S et al (2022) A multi-view attention-based deep learning framework for malware detection in smart healthcare systems. Comput Commun 195:73\u201381","journal-title":"Comput Commun"},{"key":"396_CR46","doi-asserted-by":"publisher","first-page":"8383461","DOI":"10.1155\/2022\/8383461","volume":"2022","author":"A Rehman","year":"2022","unstructured":"Rehman A, Saba T, Khan MZ et al (2022) Internet-of-things-based suspicious activity recognition using multimodalities of computer vision for smart city security. Secur Commun Netw 2022:8383461","journal-title":"Secur Commun Netw"},{"key":"396_CR47","volume":"60","author":"T Rezaei","year":"2021","unstructured":"Rezaei T, Manavi F, Hamzeh A (2021) A PE header-based method for malware detection using clustering and deep embedding techniques. J Inf Secur Appl 60:102876","journal-title":"J Inf Secur Appl"},{"key":"396_CR48","doi-asserted-by":"crossref","unstructured":"Ribani R, Marengoni M (2019) A survey of transfer learning for convolutional neural networks. In: 2019 32nd SIBGRAPI conference on graphics, patterns and images tutorials (SIBGRAPI-T). IEEE, pp 47\u201357","DOI":"10.1109\/SIBGRAPI-T.2019.00010"},{"key":"396_CR49","doi-asserted-by":"publisher","first-page":"836","DOI":"10.1007\/s11036-020-01524-4","volume":"25","author":"J Ristvej","year":"2020","unstructured":"Ristvej J, Lacin\u00e1k M, Ondrejka R (2020) On smart city and safe city concepts. Mob Netw Appl 25:836\u2013845","journal-title":"Mob Netw Appl"},{"key":"396_CR50","doi-asserted-by":"crossref","unstructured":"Sahin M, Bahtiyar S (2020) A survey on malware detection with deep learning. In: 13th international conference on security of information and networks, pp 1\u20136","DOI":"10.1145\/3433174.3433609"},{"issue":"2","key":"396_CR51","doi-asserted-by":"publisher","first-page":"1","DOI":"10.16925\/2357-6014.2019.02.02","volume":"15","author":"C S\u00e1nchez Venegas","year":"2019","unstructured":"S\u00e1nchez Venegas C, Aguado Bedoya C, D\u00edaz-L\u00f3pez D et al (2019) Using reverse engineering to handle malware. Ing Solidar 15(2):1\u201326. https:\/\/doi.org\/10.16925\/2357-6014.2019.02.02","journal-title":"Ing Solidar"},{"key":"396_CR52","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2023.106030","volume":"122","author":"K Shaukat","year":"2023","unstructured":"Shaukat K, Luo S, Varadharajan V (2023) A novel deep learning-based approach for malware detection. Eng Appl Artif Intell 122:106030","journal-title":"Eng Appl Artif Intell"},{"key":"396_CR53","doi-asserted-by":"crossref","unstructured":"Smith LN (2017) Cyclical learning rates for training neural networks. arXiv:1506.01186","DOI":"10.1109\/WACV.2017.58"},{"issue":"20","key":"396_CR54","doi-asserted-by":"publisher","first-page":"20352","DOI":"10.1109\/JIOT.2022.3172270","volume":"9","author":"L Song","year":"2022","unstructured":"Song L, Hu X, Zhang G et al (2022) Networking systems of AI: on the convergence of computing and communications. IEEE Internet Things J 9(20):20352\u201320381. https:\/\/doi.org\/10.1109\/JIOT.2022.3172270","journal-title":"IEEE Internet Things J"},{"key":"396_CR55","doi-asserted-by":"crossref","unstructured":"Talukder S, Talukder Z (2020) A survey on malware detection and analysis tools. Int J Netw Secur Appl 12(2): 21","DOI":"10.5121\/ijnsa.2020.12203"},{"key":"396_CR56","unstructured":"Tan M, Le Q (2019) EfficientNet: rethinking model scaling for convolutional neural networks. In: Chaudhuri K, Salakhutdinov R (eds) Proceedings of the 36th international conference on machine learning, proceedings of machine learning research, vol\u00a097. PMLR, Long Beach, California, USA, pp 6105\u20136114. https:\/\/proceedings.mlr.press\/v97\/tan19a.html"},{"key":"396_CR57","unstructured":"Tan M, Le QV (2020) Efficientnet: rethinking model scaling for convolutional neural networks. arXiv:1905.11946"},{"key":"396_CR58","unstructured":"Tan M, Le QV (2021) Efficientnetv2: smaller models and faster training. arXiv:2104.00298"},{"key":"396_CR59","doi-asserted-by":"publisher","unstructured":"Toffalini F, Ochoa M, Sun J, et\u00a0al (2019) Careful-packing: a practical and scalable anti-tampering software protection enforced by trusted computing. In: Proceedings of the ninth ACM conference on data and application security and privacy. Association for Computing Machinery, Richardson, Texas, USA, CODASPY \u201919, pp 231\u2013242. https:\/\/doi.org\/10.1145\/3292006.3300029","DOI":"10.1145\/3292006.3300029"},{"key":"396_CR60","doi-asserted-by":"publisher","first-page":"107","DOI":"10.15332\/iteckne.v15i2.2072","volume":"15","author":"DE Useche-Pelaez","year":"2018","unstructured":"Useche-Pelaez DE, Sepulveda-Alzate D, D\u00edaz-L\u00f3pez D et al (2018) Building malware classificators usable by state security agencies. Iteckne 15:107\u2013121","journal-title":"Iteckne"},{"key":"396_CR61","unstructured":"Webroot (2020) Webroot threat report. Tech. rep., Webroot. https:\/\/mypage.webroot.com\/rs\/557-FSI-195\/images\/2020%20Webroot%20Threat%20Report_US_FINAL.pdf"},{"issue":"1","key":"396_CR62","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s40537-016-0043-6","volume":"3","author":"K Weiss","year":"2016","unstructured":"Weiss K, Khoshgoftaar TM, Wang D (2016) A survey of transfer learning. J. Big Data 3(1):1\u201340","journal-title":"J. Big Data"},{"issue":"5","key":"396_CR63","doi-asserted-by":"publisher","DOI":"10.1002\/wics.1511","volume":"12","author":"B Xi","year":"2020","unstructured":"Xi B (2020) Adversarial machine learning for cybersecurity and computer vision: current developments and challenges. Wiley Interdiscip Rev: Comput Stat 12(5):e1511","journal-title":"Wiley Interdiscip Rev: Comput Stat"},{"key":"396_CR64","doi-asserted-by":"publisher","first-page":"65889","DOI":"10.1109\/ACCESS.2019.2917668","volume":"7","author":"H Xue","year":"2019","unstructured":"Xue H, Sun S, Venkataramani G et al (2019) Machine learning-based analysis of program binaries: a comprehensive study. IEEE Access 7:65889\u201365912","journal-title":"IEEE Access"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00396-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00396-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00396-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,29]],"date-time":"2025-04-29T02:03:12Z","timestamp":1745892192000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-025-00396-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,29]]},"references-count":64,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["396"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00396-z","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,29]]},"assertion":[{"value":"16 May 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 March 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 April 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"97"}}