Image-Based Techniques and Ensemble Soft Voting for Malware Classification
cs.CR
Submitted: 2026-08-14
Updated: 2026-08-14
Comments: To appear as a chapter in the book "Artificial Intelligence for Cyber Defense in Emerging Threats", to be published by Springer by early 2027
License: http://creativecommons.org/licenses/by/4.0/
The gist: In this chapter, we investigate image-based malware family classification using an ensemble learning framework and a soft voting strategy.
Terminology
Abstract
In this chapter, we investigate image-based malware family classification using an ensemble learning framework and a soft voting strategy. We consider malware binaries that have been converted into images using eight distinct conversion strategies. Three complementary feature extraction tracks are applied to these images: handcrafted descriptors combining Histogram of Oriented Gradients (HOG) and Haralick texture features along with 38 statistical features; dense embeddings obtained from three pretrained neural networks (VGG16, ResNet50, and ViT-B/16), where each pretrained model is used as a frozen feature extractor with its classification head removed; and 512-dimensional embeddings derived from a custom Convolutional Neural Network (CNN) trained directly on the malware images. Each of the three feature extraction techniques is evaluated with machine learning classifiers across all eight image conversion types. The best individual results are 77.8% accuracy for the handcrafted features, 73.8% for the pretrained neural network track, and 74.8% for the custom CNN track. Then we consider various soft voting ensemble strategies, and we find that the best-performing soft voting pool--consisting of fifteen voters selected on a dedicated validation split--achieves 80.2% accuracy across the 17 malware families under consideration, a statistically significant improvement of 2.4 percentage points over the best individual model. A quantitative diversity analysis confirms that the different feature representations are complementary, with the handcrafted descriptors being the strongest contributors.
Sources
- RawMal-TF: Raw Malware Dataset Labeled by Type and Family
- Use HiResCAM instead of Grad-CAM for faithful explanations of convolutional neural networks
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs