{"id":"W4379374387","doi":"10.21428/594757db.88040587","title":"Detecting Malicious .NET Files Using CLR Header Features and Machine Learning","year":2023,"lang":"en","type":"article","venue":"","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":2,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Ottawa","funders":"Natural Sciences and Engineering Research Council of Canada","keywords":"Computer science; Malware; Header; Net (polyhedron); .NET Framework; Machine learning; Artificial intelligence; Operating system; Computer network","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"codex-gemma-dda1882f352a","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0002279173,0.0001331984,0.0001287714,0.0002267895,0.0003066098,0.0001427535,0.0002268441,0.00006656546,0.00001386068],"category_scores_gemma":[0.0001192161,0.0001225013,0.0000311166,0.0005364915,0.00003193165,0.0003688468,0.0003676863,0.000264873,0.00001208788],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0000288639,"about_ca_system_score_gemma":0.00001112118,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0002073742,"about_ca_topic_score_gemma":0.0000573179,"domain_scores_codex":[0.9990088,0.0000570568,0.0001426565,0.0003541059,0.0001541143,0.0002832683],"domain_scores_gemma":[0.9994757,0.000139058,0.00006404357,0.0002234639,0.00003590645,0.00006185854],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.00002555141,0.00003452879,0.005754715,0.0001368771,0.00005812711,0.0002214751,0.002986701,0.01536413,0.1794266,0.008910106,0.002264682,0.7848165],"study_design_scores_gemma":[0.0003517207,0.0002368779,0.00448594,0.00006848328,0.00000881329,0.000755103,0.0003562613,0.6765304,0.2999484,0.008132502,0.008446484,0.0006790303],"study_design_candidate":"design_other","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.07090598,0.0001954866,0.9240643,0.0003076873,0.0001324075,0.0001264616,0.000001133235,0.003765484,0.0005010235],"genre_scores_gemma":[0.79799,0.00004123426,0.2004632,0.0002342238,0.00005359627,0.00001063741,0.000001588311,0.00002094222,0.00118456],"genre_candidate":"methods","genre_consensus":null,"teacher_disagreement_score":0.7841375,"threshold_uncertainty_score":0.4995457,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03020082254085604,"score_gpt":0.2876651292808551,"score_spread":0.257464306739999,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}