{"id":"W4385336663","doi":"10.1016/j.cose.2023.103409","title":"XMal: A lightweight memory-based explainable obfuscated-malware detector","year":2023,"lang":"en","type":"article","venue":"Computers & Security","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":40,"is_retracted":false,"has_abstract":false,"ca_institutions":"Seneca Polytechnic; Toronto Metropolitan University","funders":"Natural Sciences and Engineering Research Council of Canada","keywords":"Obfuscation; Malware; Computer science; Feature (linguistics); Code (set theory); Popularity; Detector; Process (computing); Computer security; Static analysis; Field (mathematics); Artificial intelligence; Machine learning; Data mining; Pattern recognition (psychology); Operating system; Programming language","routes":{"ca_aff":true,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.0007602481,0.00139528,0.000752674,0.00145222,0.0005797523,0.001173427,0.002555279,0.001454676,0.007059171],"category_scores_gemma":[0.00323608,0.0005923293,0.0008698286,0.0004894307,0.0008906543,0.003338189,0.003802877,0.001482846,0.002198152],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0006084695,"about_ca_system_score_gemma":0.001023543,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.0008263623,"about_ca_topic_score_gemma":0.001588127,"domain_scores_codex":[0.9988528,0.0001877283,0.00004506253,0.000199018,0.0005631429,0.0001522679],"domain_scores_gemma":[0.997965,0.0008757727,0.000204135,0.0006577431,0.0002309619,0.00006647511],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"bench_or_experimental","study_design_scores_codex":[0.002541559,0.0005030409,0.01102788,0.001018323,0.0003453708,0.001127713,0.0005243439,0.02509445,0.1061176,0.04378473,0.04094051,0.7669745],"study_design_scores_gemma":[0.0002000415,0.0006914114,0.002722043,0.0001512414,0.0002279927,0.0009444293,0.0001180584,0.7248909,0.1913427,0.04469777,0.03387591,0.0001374321],"study_design_candidate":"bench_or_experimental","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.0835498,0.001573887,0.7912049,0.0007078992,0.0002794363,0.0003099048,0.00114266,0.1144895,0.006741991],"genre_scores_gemma":[0.6434079,0.0004920114,0.3360195,0.0008167057,0.0001630403,0.0002716477,0.001987555,0.002715116,0.01412642],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.007059171,"threshold_uncertainty_score":0.02361524,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.0111523516249054,"score_gpt":0.2436627829738028,"score_spread":0.2325104313488973,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}