{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T12:00:14Z","timestamp":1784894414743,"version":"3.55.0"},"reference-count":59,"publisher":"MDPI AG","issue":"11","license":[{"start":{"date-parts":[[2022,6,6]],"date-time":"2022-06-06T00:00:00Z","timestamp":1654473600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Prince Sultan University"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>The Internet of Things (IoT) is prone to malware assaults due to its simple installation and autonomous operating qualities. IoT devices have become the most tempting targets of malware due to well-known vulnerabilities such as weak, guessable, or hard-coded passwords, a lack of secure update procedures, and unsecured network connections. Traditional static IoT malware detection and analysis methods have been shown to be unsatisfactory solutions to understanding IoT malware behavior for mitigation and prevention. Deep learning models have made huge strides in the realm of cybersecurity in recent years, thanks to their tremendous data mining, learning, and expression capabilities, thus easing the burden on malware analysts. In this context, a novel detection and multi-classification vision-based approach for IoT-malware is proposed. This approach makes use of the benefits of deep transfer learning methodology and incorporates the fine-tuning method and various ensembling strategies to increase detection and classification performance without having to develop the training models from scratch. It adopts the fusion of 3 CNNs, ResNet18, MobileNetV2, and DenseNet161, by using the random forest voting strategy. Experiments are carried out using a publicly available dataset, MaleVis, to assess and validate the suggested approach. MaleVis contains 14,226 RGB converted images representing 25 malware classes and one benign class. The obtained findings show that our suggested approach outperforms the existing state-of-the-art solutions in terms of detection and classification performance; it achieves a precision of 98.74%, recall of 98.67%, a specificity of 98.79%, F1-score of 98.70%, MCC of 98.65%, an accuracy of 98.68%, and an average processing time per malware classification of 672 ms.<\/jats:p>","DOI":"10.3390\/s22114302","type":"journal-article","created":{"date-parts":[[2022,6,7]],"date-time":"2022-06-07T00:10:33Z","timestamp":1654560633000},"page":"4302","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":63,"title":["A Novel Detection and Multi-Classification Approach for IoT-Malware Using Random Forest Voting of Fine-Tuning Convolutional Neural Networks"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0796-3507","authenticated-orcid":false,"given":"Safa","family":"Ben Atitallah","sequence":"first","affiliation":[{"name":"RIADI Laboratory, University of Manouba, Manouba 2010, Tunisia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8236-8746","authenticated-orcid":false,"given":"Maha","family":"Driss","sequence":"additional","affiliation":[{"name":"RIADI Laboratory, University of Manouba, Manouba 2010, Tunisia"},{"name":"Security Engineering Lab, CCIS, Prince Sultan University, Riyadh 12435, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4639-516X","authenticated-orcid":false,"given":"Iman","family":"Almomani","sequence":"additional","affiliation":[{"name":"Security Engineering Lab, CCIS, Prince Sultan University, Riyadh 12435, Saudi Arabia"},{"name":"Computer Science Department, King Abdullah II School for Information Technology, The University of Jordan, Amman 11942, Jordan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,6,6]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"100303","DOI":"10.1016\/j.cosrev.2020.100303","article-title":"Leveraging Deep Learning and IoT big data analytics to support the smart cities development: Review and future directions","volume":"38","author":"Driss","year":"2020","journal-title":"Comput. Sci. Rev."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Latif, S., Driss, M., Boulila, W., Huma, Z.E., Jamal, S.S., Idrees, Z., and Ahmad, J. (2021). Deep Learning for the Industrial Internet of Things (IIoT): A Comprehensive Survey of Techniques, Implementation Frameworks, Potential Applications, and Future Directions. Sensors, 21.","DOI":"10.3390\/s21227518"},{"key":"ref_3","unstructured":"(2021, April 15). IoT Cyberattacks Escalate in 2021, According to Kaspersky. Available online: https:\/\/www.iotworldtoday.com\/2021\/09\/17\/iot-cyberattacks-escalate-in-2021-according-to-kaspersky\/."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"280","DOI":"10.1016\/j.icte.2020.04.005","article-title":"A survey of IoT malware and detection methods based on static features","volume":"6","author":"Ngo","year":"2020","journal-title":"ICT Express"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"102143","DOI":"10.1016\/j.sysarc.2021.102143","article-title":"The evolution of IoT Malwares, from 2008 to 2019: Survey, taxonomy, process simulator and perspectives","volume":"116","author":"Vignau","year":"2021","journal-title":"J. Syst. Archit."},{"key":"ref_6","unstructured":"Baig, M., Zavarsky, P., Ruhl, R., and Lindskog, D. (2012, January 10\u201312). The study of evasion of packed pe from static detection. Proceedings of the World Congress on Internet Security (WorldCIS-2012), Guelph, ON, Canada."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"551","DOI":"10.3390\/iot1020030","article-title":"A study on the evolution of ransomware detection using machine learning and deep learning techniques","volume":"1","author":"Fernando","year":"2020","journal-title":"IoT"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"8699","DOI":"10.1007\/s12652-020-02630-7","article-title":"Detecting ransomware attacks using intelligent algorithms: Recent development and next direction from deep learning and big data perspectives","volume":"12","author":"Bello","year":"2021","journal-title":"J. Ambient. Intell. Humaniz. Comput."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Zakaria, W.Z.A., Abdollah, M.F., Mohd, O., and Ariffin, A.F.M. (2017, January 28\u201330). The rise of ransomware. Proceedings of the 2017 International Conference on Software and e-Business, Hong Kong, China.","DOI":"10.1145\/3178212.3178224"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"108288","DOI":"10.1016\/j.measurement.2020.108288","article-title":"A hybrid deep transfer learning model with machine learning methods for face mask detection in the era of the COVID-19 pandemic","volume":"167","author":"Loey","year":"2021","journal-title":"Measurement"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1002\/ima.22654","article-title":"Randomly initialized convolutional neural network for the recognition of COVID-19 using X-ray images","volume":"32","author":"Driss","year":"2022","journal-title":"Int. J. Imaging Syst. Technol."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"658","DOI":"10.1002\/ima.22653","article-title":"Fusion of convolutional neural networks based on Dempster\u2013Shafer theory for automatic pneumonia detection from chest X-ray images","volume":"32","author":"Driss","year":"2022","journal-title":"Int. J. Imaging Syst. Technol."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Tan, C., Sun, F., Kong, T., Zhang, W., Yang, C., and Liu, C. (2018, January 4\u20137). A survey on deep transfer learning. Proceedings of the International Conference on Artificial Neural Networks, Rhodes, Greece.","DOI":"10.1007\/978-3-030-01424-7_27"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"196197","DOI":"10.1109\/ACCESS.2020.3034343","article-title":"Transfer learning with adaptive fine-tuning","volume":"8","author":"Podgorelec","year":"2020","journal-title":"IEEE Access"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"132","DOI":"10.1016\/j.inffus.2017.02.004","article-title":"Ensemble learning for data stream analysis: A survey","volume":"37","author":"Krawczyk","year":"2017","journal-title":"Inf. Fusion"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"e1249","DOI":"10.1002\/widm.1249","article-title":"Ensemble learning: A survey","volume":"8","author":"Sagi","year":"2018","journal-title":"Wiley Interdiscip. Rev. Data Min. Knowl. Discov."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Nisa, M., Shah, J.H., Kanwal, S., Raza, M., Khan, M.A., Dama\u0161evi\u010dius, R., and Bla\u017eauskas, T. (2020). Hybrid malware classification method using segmentation-based fractal texture analysis and deep convolution neural network features. Appl. Sci., 10.","DOI":"10.3390\/app10144966"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Hemalatha, J., Roseline, S.A., Geetha, S., Kadry, S., and Dama\u0161evi\u010dius, R. (2021). An efficient densenet-based deep learning model for malware detection. Entropy, 23.","DOI":"10.3390\/e23030344"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"891","DOI":"10.1007\/s11219-017-9368-4","article-title":"A survey on dynamic mobile malware detection","volume":"26","author":"Yan","year":"2018","journal-title":"Softw. Qual. J."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"3","DOI":"10.1186\/s13673-018-0125-x","article-title":"A state-of-the-art survey of malware detection approaches using data mining techniques","volume":"8","author":"Souri","year":"2018","journal-title":"Hum. Centric Comput. Inf. Sci."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Sharma, S., Khanna, K., and Ahlawat, P. (2022). Survey for Detection and Analysis of Android Malware (s) Through Artificial Intelligence Techniques. Cyber Security and Digital Forensics, Springer.","DOI":"10.1007\/978-981-16-3961-6_28"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Lo, W.W., Yang, X., and Wang, Y. (2019, January 24\u201326). An xception convolutional neural network for malware classification with transfer learning. Proceedings of the 2019 10th IFIP International Conference on New Technologies, Mobility and Security (NTMS), Guayaquil, Ecuador.","DOI":"10.1109\/NTMS.2019.8763852"},{"key":"ref_23","unstructured":"Davuluru, V.S.P., Narayanan, B.N., and Balster, E.J. (2019, January 15\u201319). Convolutional neural networks as classification tools and feature extractors for distinguishing malware programs. Proceedings of the 2019 IEEE National Aerospace and Electronics Conference (NAECON), Dayton, OH, USA."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"166630","DOI":"10.1109\/ACCESS.2020.3022722","article-title":"A malware detection method of code texture visualization based on an improved faster RCNN combining transfer learning","volume":"8","author":"Zhao","year":"2020","journal-title":"IEEE Access"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Narayanan, B.N., and Davuluru, V.S.P. (2020). Ensemble malware classification system using deep neural networks. Electronics, 9.","DOI":"10.3390\/electronics9050721"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"101748","DOI":"10.1016\/j.cose.2020.101748","article-title":"Image-Based malware classification using ensemble of CNN architectures (IMCEC)","volume":"92","author":"Vasan","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Olowoyo, O., and Owolawi, P. (2020, January 25\u201327). Malware classification using deep learning technique. Proceedings of the 2020 2nd International Multidisciplinary Information Technology and Engineering Conference (IMITEC), Kimberley, South Africa.","DOI":"10.1109\/IMITEC50163.2020.9334071"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Awan, M.J., Masood, O.A., Mohammed, M.A., Yasin, A., Zain, A.M., Dama\u0161evi\u010dius, R., and Abdulkareem, K.H. (2021). Image-Based Malware Classification Using VGG19 Network and Spatial Convolutional Attention. Electronics, 10.","DOI":"10.3390\/electronics10192444"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"334","DOI":"10.1016\/j.future.2021.06.029","article-title":"MCFT-CNN: Malware classification with fine-tune convolution neural networks using traditional and transfer learning in internet of things","volume":"125","author":"Sudhakar","year":"2021","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_30","unstructured":"Carletti, V., Greco, A., Saggese, A., and Vento, M. (2021, January 7\u20139). Robustness evaluation of convolutional neural networks for malware classification. Proceedings of the Italian Conference on Cybersecurity (ITASEC), Online."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Bouchaib, P., and Bouhorma, M. (2021, January 1\u20132). Transfer Learning and Smote Algorithm For Image-Based Malware Classification. Proceedings of the 4th International Conference on Networking, Information Systems & Security, Kenitra, Morocco.","DOI":"10.1145\/3454127.3457631"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Khetarpal, A., and Mallik, A. (2021, January 15\u201317). Visual Malware Classification Using Transfer Learning. Proceedings of the 2021 Fourth International Conference on Electrical, Computer and Communication Technologies (ICECCT), Coimbatore, India.","DOI":"10.1109\/ICECCT52121.2021.9616822"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"El-Shafai, W., Almomani, I., and AlKhayer, A. (2021). Visualized malware multi-classification framework using fine-tuned CNN-based transfer learning models. Appl. Sci., 11.","DOI":"10.3390\/app11146446"},{"key":"ref_34","first-page":"103063","article-title":"DTMIC: Deep transfer learning for malware image classification","volume":"64","author":"Kumar","year":"2022","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"159262","DOI":"10.1109\/ACCESS.2021.3131713","article-title":"Vision-Based Malware Detection: A Transfer Learning Approach Using Optimal ECOC-SVM Configuration","volume":"9","author":"Wong","year":"2021","journal-title":"IEEE Access"},{"key":"ref_36","unstructured":"(2022, April 23). Bin To PNG Conversion. Available online: https:\/\/web.cs.hacettepe.edu.tr\/~selman\/malevis\/bin2png.py."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Sandler, M., Howard, A., Zhu, M., Zhmoginov, A., and Chen, L.C. (2018, January 18\u201322). Mobilenetv2: Inverted residuals and linear bottlenecks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Salt Lake City, GA, USA.","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Van Der Maaten, L., and Weinberger, K.Q. (2017, January 21\u201326). Densely connected convolutional networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Du, K.L., and Swamy, M. (2019). Combining Multiple Learners: Data Fusion and Ensemble Learning. Neural Networks and Statistical Learning, Springer.","DOI":"10.1007\/978-1-4471-7452-3_25"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"122272","DOI":"10.1016\/j.physa.2019.122272","article-title":"An improved Stacking framework for stock index prediction by leveraging tree-based ensemble models and deep learning algorithms","volume":"541","author":"Jiang","year":"2020","journal-title":"Phys. Stat. Mech. Its Appl."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Cutler, A., Cutler, D.R., and Stevens, J.R. (2012). Random forests. Ensemble Machine Learning, Springer.","DOI":"10.1007\/978-1-4419-9326-7_5"},{"key":"ref_43","unstructured":"(2022, May 19). Jupyter: Free Software, Open Standards, and Web Services for Interactive Computing across all Programming Languages. Available online: https:\/\/jupyter.org\/."},{"key":"ref_44","unstructured":"(2022, May 19). Anaconda. Available online: https:\/\/www.anaconda.com\/."},{"key":"ref_45","unstructured":"(2022, April 23). Python Programming Language. Available online: https:\/\/www.python.org\/."},{"key":"ref_46","unstructured":"(2022, April 23). An Open Source Machine Learning Framework: PyTorch. Available online: https:\/\/pytorch.org\/."},{"key":"ref_47","unstructured":"Kingma, D.P., Mohamed, S., Jimenez Rezende, D., and Welling, M. (2014). Semi-supervised learning with deep generative models. Adv. Neural Inf. Process. Syst., 27."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Rehman, M.U., Shafique, A., Khalid, S., Driss, M., and Rubaiee, S. (2021). Future forecasting of COVID-19: A supervised learning approach. Sensors, 21.","DOI":"10.3390\/s21103322"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"55595","DOI":"10.1109\/ACCESS.2021.3071766","article-title":"A hybrid deep random neural network for cyberattack detection in the industrial internet of things","volume":"9","author":"Huma","year":"2021","journal-title":"IEEE Access"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Driss, M., Almomani, I., and Ahmad, J. (2022). A federated learning framework for cyberattack detection in vehicular sensor networks. Complex Intell. Syst., 1\u201315.","DOI":"10.1007\/s40747-022-00705-w"},{"key":"ref_51","unstructured":"(2022, April 23). MaleVis Dataset. Available online: https:\/\/web.cs.hacettepe.edu.tr\/~selman\/malevis\/."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Bozkir, A.S., Cankaya, A.O., and Aydos, M. (2019, January 24\u201326). Utilization and comparision of convolutional neural networks in malware recognition. Proceedings of the 2019 27th Signal Processing and Communications Applications Conference (SIU), Sivas, Turkey.","DOI":"10.1109\/SIU.2019.8806511"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Shalaginov, A., Dyrkolbotn, G.O., and Alazab, M. (2021). Review of the malware categorization in the era of changing cybethreats landscape: Common approaches, challenges and future needs. Malware Analysis Using Artificial Intelligence and Deep Learning, Springer.","DOI":"10.1007\/978-3-030-62582-5_3"},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"532","DOI":"10.1007\/978-0-387-39940-9_565","article-title":"Cross-validation","volume":"5","author":"Refaeilzadeh","year":"2009","journal-title":"Encycl. Database Syst."},{"key":"ref_55","doi-asserted-by":"crossref","first-page":"206303","DOI":"10.1109\/ACCESS.2020.3036491","article-title":"Intelligent vision-based malware detection and classification using deep random forest paradigm","volume":"8","author":"Roseline","year":"2020","journal-title":"IEEE Access"},{"key":"ref_56","doi-asserted-by":"crossref","first-page":"87936","DOI":"10.1109\/ACCESS.2021.3089586","article-title":"A new malware classification framework based on deep learning algorithms","volume":"9","author":"Aslan","year":"2021","journal-title":"IEEE Access"},{"key":"ref_57","doi-asserted-by":"crossref","first-page":"102545","DOI":"10.1016\/j.adhoc.2021.102545","article-title":"Deep convolutional recurrent model for region recommendation with spatial and temporal contexts","volume":"129","author":"Xu","year":"2022","journal-title":"Hoc Netw."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"1762","DOI":"10.1109\/TIP.2019.2942502","article-title":"Deep spatial and temporal network for robust visual object tracking","volume":"29","author":"Teng","year":"2019","journal-title":"IEEE Trans. Image Process."},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"602","DOI":"10.1080\/21642583.2014.956265","article-title":"Random forests: From early developments to recent advancements","volume":"2","author":"Fawagreh","year":"2014","journal-title":"Syst. Sci. Control Eng. Open Access J."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/11\/4302\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:25:00Z","timestamp":1760138700000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/11\/4302"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,6]]},"references-count":59,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2022,6]]}},"alternative-id":["s22114302"],"URL":"https:\/\/doi.org\/10.3390\/s22114302","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,6]]}}}