Organizations: Artificial Intelligence Research (AIR) Center · School of Electrical Engineering and Computer Science, College of Engineering & Mines University of North Dakota, Grand Forks, ND 58201, USA
By 2030, Internet of Things (IoT) devices are projected to reach 40 billion, with fast-paced technological advancements in fields such as industry, healthcare, agriculture, automobiles, and building/home automation systems. This expansion has created a large attack surface for cybercrime, as the majority of these devices open the door for cybercriminals to exploit vulnerabilities, as they lack adequate built-in security. Cybercriminals launch malware attacks to compromise systems or steal sensitive data, and once a system is compromised, a ransom is typically demanded for its release. Current cybersecurity measures in place are being outpaced by the rapid growth of the IoT, which is accompanied by a subsequent growth in malware variants being created per day. Recognizing this pitfall, this research examines and proposes a novel approach to malware detection and classification to safeguard devices from further attacks and make IoT systems more robust and secure. The framework proposed utilizes a Structured State Space Sequence (S4) model, which discretizes sequences of malware samples in a sequence and captures long-range dependencies, essentially identifying the "cause" and "effect" hidden within malware execution flow. This study presents two novel contributions: the first empirical application of the S4 model for malware analysis, and a comprehensive comparison of its performance against other deep learning architectures, laying the stepping stone for future research in this new paradigm.
Figures & tables
Fig. 1 : Overall System Workflow
Fig. 2 : Overview of the proposed state space based malware classification architecture, showing the sequence construction stage, stacked state space blocks with residual connections, and dual feed-forward classification networks. The discrete-time dynamics within a single state space block are shown in the lower-left panel.
Component
Setting
Number of input features ( D )
71
Sequence length ( L )
32
Model dimension ( dmodel )
128
State dimension ( dstate )
64
Number of state space blocks
3
State space layers per block
1
TABLE I : Configuration of the proposed state space based model
Fig. 3 : Training and validation loss, binary detection accuracy, and malware family classification accuracy over 50 training epochs.
Parameter
Values
Model dimension ( dmodel )
{128, 256}
State dimension ( dstate )
{32, 64}
Number of state space blocks
{2, 3}
Learning rate
{1e-4, 5e-4}
Family loss weight
{0.5, 0.7}
Dropout rate
{0.1, 0.2}
TABLE II : Hyperparameter search space used for grid search tuning
Metric
Formula
Accuracy
TP+TN+FP+FNTP+TN
Precision
TP+FPTP
Recall
TP+FNTP
F1-score
Precision+Recall2⋅Precision⋅Recall
Macro-average
C1∑i=1Cmi
Weighted-average
∑i=1Cwimi
TABLE III : Evaluation metrics used for malware classification
Fig. 4 : Binary malware detection performance across evaluated models in terms of accuracy, precision, recall, and F1-score.
Fig. 5 : Per-class F1-scores for the selected ransomware families across different model architectures.
Fig. 6 : Per-class precision for the selected ransomware families across different model architectures.
Fig. 7 : Per-class recall for the selected ransomware families across different model architectures.
Fig. 8 : Summary of macro-averaged and weighted performance metrics for malware family classification across evaluated models.
With the rapid proliferation of IoT devices, security concerns have dramatically escalated and intrusion detection systems have become critical for protecting networked environments. This paper presents an improved CNN-LSTM based intrusion detection model that combines multi-class classification, dataset integration, and temporal feature learning to enhance detection performance in IoT networks. Using network traffic data, the proposed approach is evaluated on intrusion detection tasks and achieves an accuracy of approximately 97%. Experimental results demonstrate that the model effectively detects multiple attack categories while maintaining stable training and validation performance. The integration of convolutional and recurrent neural network components enables the framework to capture both spatial and temporal characteristics of network traffic, improving overall intrusion detection capability in IoT environments.
Mohammad Tariq Ikhlas, Pohanyar Khowaja Khil, Malik Muhammad Mueed Aslam +1
Traditional malware detection methods struggle to generalize to obfuscated or previously unseen threats. This paper introduces ThreatVisionAI, a hybrid malware family classification framework that integrates a raw-image CNN, a wavelet-based CNN, and a Vision Transformer (ViT) to capture complementary spatial, frequency-domain, and global relational features in malware images. The wavelet-based CNN captures multi-scale frequency information that helps distinguish closely related families, while the ViT branch models long-range dependencies across the image. Evaluated on the Malimg dataset, ThreatVisionAI achieves 98.01% accuracy and a weighted F1 score of 0.9742, with wavelet-domain features providing measurable gains on minority and visually similar families. These results confirm that frequency-aware and transformer-based representations improve image-based malware family classification.
Allyson Taylor, Prashanth BusiReddyGari
Department of Mathematics & Computer Science University of North Carolina Pembroke
Malware detection remains largely reactive: machine learning models trained on known samples degrade as threats evolve. Understanding evolutionary relationships among malware families can inform proactive defense, but traditional reverse engineering can take months to years to uncover such lineage relationships. We propose MalTree, a framework that applies bioinformatics inspired phylogenetic techniques (UPGMA and Neighbor-Joining) at scale to model malware evolution automatically using structural, behavioral, and image-based features. We introduce temporal validation using VirusTotal timestamps to assess whether inferred trees reflect actual evolutionary order. MalTree achieves 87% temporal consistency, indicating that inferred evolutionary relationships closely align with real-world emergence timelines. Our analysis shows that some families mutate over 10 times faster than others, suggesting that detection strategies should be tailored to family-specific evolutionary tempos. Case studies, including the Mirai botnet, confirm that inferred relationships from our phylogenetic tree align with documented threat intelligence. Our framework provides a foundation for shifting malware analysis from sample-by-sample classification toward lineage-aware evolutionary modeling.
Akash Amalan, Georgios Smaragdakis, Tom J. Viering
Delft University of Technology, Delft, The Netherlands.