Analyzing Malware Behavior Using Generative Neural Networks

Authors

  • Wurood A. Jbara Department of Computer Science, College of Science, Mustansiriyah University, IRAQ,
  • Noor Al-Huda K. Hussein Technical College, Imam Ja’afar Al-Sadiq University, Baghdad, IRAQ,

DOI:

https://doi.org/10.71229/pc796a74

Keywords:

cypher security , deep learning, threats , GNN , GAN , VAE , CNN

Abstract

Traditional detection techniques are struggling with ever-evolving malware threats like zero-day attacks, polymorphic malware, and adversarial samples. Current detection systems (signature-based, heuristic-based, conventional machine learning) fail to generalize to unseen/obfuscated malware variants. In an attempt to overcome these constraints, this paper investigates the possibilities of employing Generative Neural Networks (GNNs), in the form of Generative Adversarial Networks (GANs) and Variational Autoencoders (VAEs) for the purpose of malware be haviour analysis and detection. We aim to create a novel framework for detecting malware samples that provides some of the best performance in terms of accuracy, precision, and recall while remaining robust to new or unseen malware. This work aims to firstly implement a generative learning-based approach and to measure its adversarial robustness in comparison with the four existing detection techniques. Experimental results show the accuracy, precision, recall of the proposed model is found to be 96.5%, 95.9%, 94.6% with the false positive rate of the model which can be negligible and it is 3.2% which outperforms the traditional machine learning and deep learning models. Our results demonstrate that GNN-based malware detection not only addresses the limitations of conventional approaches in terms of scalability but also provides a more robust and adaptable framework that could be integrated into future real-time threat intelligence and automated defense systems.

Author Biography

  • Wurood A. Jbara , Department of Computer Science, College of Science, Mustansiriyah University, IRAQ,

    Department of Computer Science, College of Science

References

[1] J. Kim, S. Bu, S. C.-I. Sciences, and undefined 2018‏, “Zero-day malware detection using transferred generative adversarial networks based on deep autoencoders‏,” Elsevier‏, Accessed: Feb. 02, 2025. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0020025518303475

[2] L. Campanile, M. Iacono, F. Martinelli, … F. M.-… I. and N., and undefined 2020‏, “Towards the use of generative adversarial neural networks to attack online resources‏,” Springer‏, Accessed: Feb. 03, 2025. [Online]. Available: https://link.springer.com/chapter/10.1007/978-3-030-44038-1_81 DOI: https://doi.org/10.1007/978-3-030-44038-1_81

[3] Y. Liu, J. Li, B. Liu, X. Gao, and X. Liu, “Malware detection method based on image analysis and generative adversarial networks,” Concurr Comput, vol. 34, no. 22, Oct. 2022, doi: 10.1002/CPE.7170. DOI: https://doi.org/10.1002/cpe.7170

[4] U. Urooj, B. Ali, S. Al-Rimy, A. Binti Zainal, A. Abdelmaboud, and W. Nagmeldin, “Addressing Behavioral Drift in Ransomware Early Detection Through Weighted Generative Adversarial Networks‏,” 2023‏, doi: 10.1109/ACCESS.2023.3348451. DOI: https://doi.org/10.1109/ACCESS.2023.3348451

[5] M. Amin, B. Shah, A. Sharif, T. Ali, K. Il Kim, and S. Anwar, “Android malware detection through generative adversarial networks,” Transactions on Emerging Telecommunications Technologies, vol. 33, no. 2, Feb. 2022, doi: 10.1002/ETT.3675. DOI: https://doi.org/10.1002/ett.3675

[6] W. A. Jbara, N. Al-Huda, K. Hussein, and J. H. Soud, “Deepfake Detection in Video and Audio Clips: A Comprehensive Survey and Analysis‏,” mesopotamian.press‏WA Jbara, NAHK Hussein, JH Soud‏Mesopotamian Journal of CyberSecurity, 2024‏•mesopotamian.press‏, doi: 10.58496/MJCS/2024/025. DOI: https://doi.org/10.58496/MJCS/2024/025

[7] I. Rosenberg, G. Sicard, E. D.- Entropy, and undefined 2018‏, “End-to-end deep neural networks and transfer learning for automatic analysis of nation-state malware‏,” mdpi.com‏, Accessed: Feb. 03, 2025. [Online]. Available: https://www.mdpi.com/1099-4300/20/5/390 DOI: https://doi.org/10.3390/e20050390

[8] W. Meng, C. D. Jensen, M. Gazzan, and F. T. Sheldon, “An enhanced minimax loss function technique in generative adversarial network for ransomware behavior prediction‏,” mdpi.com‏, 2023, doi: 10.3390/fi15100318. DOI: https://doi.org/10.3390/fi15100318

[9] A. Almaleh, R. Almushabb, R. O.-A. Sciences, and undefined 2023‏, “Malware API calls detection using hybrid logistic regression and RNN model‏,” mdpi.com‏, Accessed: Feb. 03, 2025. [Online]. Available: https://www.mdpi.com/2076-3417/13/9/5439 DOI: https://doi.org/10.3390/app13095439

[10] J. Y. Kim, S. J. Bu, and S. B. Cho, “Malware detection using deep transferred generative adversarial networks,” Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), vol. 10634 LNCS, pp. 556–564, 2017, doi: 10.1007/978-3-319-70087-8_58. DOI: https://doi.org/10.1007/978-3-319-70087-8_58

[11] Y. Jian, H. Kuang, C. Ren, Z. Ma, H. W.-C. & Security, and undefined 2021‏, “A novel framework for image-based malware detection with a deep neural network‏,” Elsevier‏, Accessed: Feb. 03, 2025. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0167404821002248

[12] J. Kim, S. Bu, S. C.-N. I. P. 24th International, and undefined 2017‏, “Malware detection using deep transferred generative adversarial networks‏,” Springer‏, Accessed: Feb. 02, 2025. [Online]. Available: https://link.springer.com/chapter/10.1007/978-3-319-70087-8_58

[13] R. Zaki, I. N.-M. J. of CyberSecurity, and undefined 2024‏, “Hybrid Classifier for Detecting Zero-Day Attacks on IoT Networks‏,” mesopotamian.press‏RM Zaki, IS Naser‏Mesopotamian Journal of CyberSecurity, 2024‏•mesopotamian.press‏, doi: 10.58496/MJCS/2024/016. DOI: https://doi.org/10.58496/MJCS/2024/016

[14] S. Gupta and B. Crispo, “Towards autonomous device protection using behavioural profiling and generative artificial intelligence,” IET Cyber-Physical Systems: Theory and Applications, 2024, doi: 10.1049/CPS2.12102. DOI: https://doi.org/10.1049/cps2.12102

[15] N. Owoh, J. Adejoh, S. Hosseinzadeh, M. A.-F. Internet, and undefined 2024‏, “Malware Detection Based on API Call Sequence Analysis: A Gated Recurrent Unit–Generative Adversarial Network Model Approach‏,” mdpi.com‏, Accessed: Feb. 02, 2025. [Online]. Available: https://www.mdpi.com/1999-5903/16/10/369 DOI: https://doi.org/10.3390/fi16100369

[16] Z. Moti et al., “Generative adversarial network to detect unseen Internet of Things malware‏,” Elsevier‏, doi: 10.1016/j.adhoc.2021.102591. DOI: https://doi.org/10.1016/j.adhoc.2021.102591

[17] A. Wiles, F. Colombo, R. M.- Authorea, and undefined 2024‏, “Ransomware detection using network traffic analysis and generative adversarial networks‏,” authorea.com‏, 2024, doi: 10.22541/au.172659907.77469627/v1. DOI: https://doi.org/10.22541/au.172659907.77469627/v1

[18] Y. Zhang, H. Li, Y. Zheng, S. Yao, J. J.-J. of C. V. and, and undefined 2021‏, “Enhanced DNNs for malware classification with GAN-based adversarial training‏,” Springer‏, Accessed: Feb. 02, 2025. [Online]. Available: https://link.springer.com/article/10.1007/s11416-021-00378-y

[19] J. Kim, S. C.-C. & Security, and undefined 2022‏, “Obfuscated malware detection using deep generative model based on global/local features‏,” Elsevier‏, Accessed: Feb. 02, 2025. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S0167404821003254

[20] J. Kim, S. C.-I. D. E. and A. Learning, and undefined 2018‏, “Detecting intrusive malware with a hybrid generative deep learning model‏,” Springer‏, Accessed: Feb. 02, 2025. [Online]. Available: https://link.springer.com/chapter/10.1007/978-3-030-03493-1_52

[21] C. Molloy, F. Alaca, S. D.-C. on A. N. Networks, and undefined 2024‏, “Ch4os: Discretized Generative Adversarial Network for Functionality-Preserving Evasive Modification on Malware‏,” Springer‏, Accessed: Feb. 02, 2025. [Online]. Available: https://link.springer.com/chapter/10.1007/978-3-031-72356-8_30 DOI: https://doi.org/10.1007/978-3-031-72356-8_30

fig 2

Downloads

Published

2026-08-02

Issue

Section

Original Articles

How to Cite

Analyzing Malware Behavior Using Generative Neural Networks. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(2), 510-518. https://doi.org/10.71229/pc796a74

Similar Articles

1-10 of 28

You may also start an advanced similarity search for this article.