Cross-Domain Malware Detection via Probability-Level Fusion of Lightweight Gradient Boosting Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autore principale: Mohamed, Omar Khalid Ali
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909762801631232
author Mohamed, Omar Khalid Ali
author_facet Mohamed, Omar Khalid Ali
contents The escalating sophistication of malware necessitates robust detection mechanisms that generalize across diverse data sources. Traditional single-dataset models struggle with cross-domain generalization and often incur high computational costs. This paper presents a novel, lightweight framework for malware detection that employs probability-level fusion across three distinct datasets: EMBER (static features), API Call Sequences (behavioral features), and CIC Obfuscated Memory (memory patterns). Our method trains individual LightGBM classifiers on each dataset, selects top predictive features to ensure efficiency, and fuses their prediction probabilities using optimized weights determined via grid search. Extensive experiments demonstrate that our fusion approach achieves a macro F1-score of 0.823 on a cross-domain validation set, significantly outperforming individual models and providing superior generalization. The framework maintains low computational overhead, making it suitable for real-time deployment, and all code and data are provided for full reproducibility.
format Preprint
id arxiv_https___arxiv_org_abs_2509_00476
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Cross-Domain Malware Detection via Probability-Level Fusion of Lightweight Gradient Boosting Models
Mohamed, Omar Khalid Ali
Cryptography and Security
Artificial Intelligence
68T10 (Primary) 68T05, 68M25 (Secondary)
I.2.6; I.5.2; K.6.5
The escalating sophistication of malware necessitates robust detection mechanisms that generalize across diverse data sources. Traditional single-dataset models struggle with cross-domain generalization and often incur high computational costs. This paper presents a novel, lightweight framework for malware detection that employs probability-level fusion across three distinct datasets: EMBER (static features), API Call Sequences (behavioral features), and CIC Obfuscated Memory (memory patterns). Our method trains individual LightGBM classifiers on each dataset, selects top predictive features to ensure efficiency, and fuses their prediction probabilities using optimized weights determined via grid search. Extensive experiments demonstrate that our fusion approach achieves a macro F1-score of 0.823 on a cross-domain validation set, significantly outperforming individual models and providing superior generalization. The framework maintains low computational overhead, making it suitable for real-time deployment, and all code and data are provided for full reproducibility.
title Cross-Domain Malware Detection via Probability-Level Fusion of Lightweight Gradient Boosting Models
topic Cryptography and Security
Artificial Intelligence
68T10 (Primary) 68T05, 68M25 (Secondary)
I.2.6; I.5.2; K.6.5
url https://arxiv.org/abs/2509.00476