no-1

An effective malware classification method based on byte-to-image transformation and integration of the vision transformer model

Authors:
Thuy Nguyen Thi Thu, Linh Do Thi Hong, Ha Hoang Thi Hong, Cuc Pham Thi, Binh Pham Anh
Pages:
0
View:
16
Position:
3/3
Download:
5
Malware classification is a critical problem in cybersecurity, characterized by numerous challenges due to the complexity and diversity of malware variants. In this study, we propose a novel approach that transforms bytecode into image representations and employs the Vision Transformer (ViT) architecture for malware family classification. The proposed data preprocessing method preserves essential structural information of the malware while simplifying feature extraction. ViT leverages the self-attention mechanism to model complex and long-range dependencies, offering advantages over traditional CNN-based models. Experiments conducted on the Microsoft Malware Classification Challenge dataset demonstrate that the proposed model achieves high accuracy and F1-scores, particularly for malware families such as Kelihos_ver3 and Lollipop. Confusion matrix analysis reveals a strong discriminative capability across malware families, while also highlighting challenges in distinguishing families...
Malware classification is a critical problem in cybersecurity, characterized by numerous challenges due to the complexity and diversity of malware variants. In this study, we propose a novel approach that transforms bytecode into image representations and employs the Vision Transformer (ViT) architecture for malware family classification. The proposed data preprocessing method preserves essential structural information of the malware while simplifying feature extraction. ViT leverages the self-attention mechanism to model complex and long-range dependencies, offering advantages over traditional CNN-based models. Experiments conducted on the Microsoft Malware Classification Challenge dataset demonstrate that the proposed model achieves high accuracy and F1-scores, particularly for malware families such as Kelihos_ver3 and Lollipop. Confusion matrix analysis reveals a strong discriminative capability across malware families, while also highlighting challenges in distinguishing families with structurally similar or heavily obfuscated patterns. The study also discusses current limitations, including computational cost and the lack of integration of dynamic behavioral data, and outlines future research directions to improve performance and real-world applicability. Overall, the results highlight the potential of Vision Transformer architectures in malware classification, suggesting a promising avenue for further research in cybersecurity.
Relate
Motor unit decomposition performance at reduced channels: a progressive FastICA-CKC hybrid approach
Dung Tran Ngoc, Son Pham Nam, Binh Do Khoa, Hieu Nguyen Le Cong, Hieu Nguyen Vu, Nam Le Hai
Volume 55, Issue 1A, 01/2026

Vinh University journal of science

Tạp chí khoa học Trường Đại học Vinh

ISSN: 1859 - 2228

Governing body: Vinh University

  • Address: 182 Le Duan - Vinh City - Nghe An province
  • Phone: (+84) 238.3855.452 - Fax: (+84) 238.3855.269
  • Email: vinhuni@vinhuni.edu.vn
  • Website: https://vinhuni.edu.vn

 

License: 163/GP-BTTTT issued by the Minister of Information and Communications on May 10, 2023

Open Access License: Creative Commons CC BY NC 4.0

 

CONTACT

Editor-in-Chief: Assoc. Prof., Dr. Tran Ba Tien
Email: tientb@vinhuni.edu.vn

Deputy editor-in-chief: Assoc. Prof., Dr. Phan Van Tien
Email: vantienkxd@vinhuni.edu.vn

Sub-Editor: Dr. Do Mai Trang
Email: domaitrang@vinhuni.edu.vn

Editorial assistant: Msc. Le Tuan Dung, Msc. Phan The Hoa, Msc. Pham Thi Quynh Nga, Msc. Tran Thi Thai

  • Address: 4th Floor, Executive Building, No. 182, Le Duan street, Vinh city, Nghe An province.
  • Phone: (+84) 238-385-6700 | Hotline: (+84) 97-385-6700
  • Email: editors@vujs.vn
  • Website: https://vujs.vn

img