Guarding Organizations Against Malware Risk: A Novel Graph-Based Malware Detection Method
Yinan Gao, Jiarong Xu, Xiaohang Zhao, Xiao Fang
cs.CR, cs.AI
Submitted: 2026-07-29
Code: https://github.com/ShoumikSaha/DRSM
License: http://creativecommons.org/licenses/by-nc-nd/4.0/
The gist: Organizational digitalization expands cybersecurity risks, making cybersecurity an increasingly important research area in Information Systems (IS).
Terminology
Abstract
Organizational digitalization expands cybersecurity risks, making cybersecurity an increasingly important research area in Information Systems (IS). Among these risks, malware has become a pervasive and destructive threat. Byte-based machine learning (ML) methods are widely used for malware detection but remain vulnerable to evasive behaviors that manipulate raw bytes to evade detection. Graph-based methods are less affected by such manipulations because they represent software as program graphs that capture execution behavior. However, they do not explicitly identify cohesive groups of basic blocks that jointly realize meaningful program behaviors, nor do they learn sufficiently expressive program graph representations for accurate detection. To this end, we propose MalGuard, a graph-based malware detection method for organizational malware risk management. MalGuard introduces two methodological innovations: an operational role identification approach and a program graph representation learning method. The former identifies these cohesive groups of basic blocks as operational roles, enabling the detector to capture program behaviors that may not be visible from isolated basic blocks. The latter learns expressive program graph representations by modeling interactions among operational roles, preserving sparse malicious signals, and capturing hierarchical graph structure. Extensive experiments show that MalGuard improves detection performance and reduces the expected cost of undetected malware.
Sources
- EMBER: An Open Dataset for Training Static PE Malware Machine Learning Models
- Deceiving End-to-End Deep Learning Malware Detectors using Adversarial Examples
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs