{"id":"W4414982131","doi":"10.1145/3771542","title":"Toward a Robust Detection of PowerShell Malware against Code Mixing and Obfuscation by Using Sentence Transformer and Similarity Learning","year":2025,"lang":"en","type":"article","venue":"ACM Transactions on Privacy and Security","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":2,"is_retracted":false,"has_abstract":true,"ca_institutions":"Queen's University; McGill University","funders":"","keywords":"Malware; Obfuscation; Scripting language; Robustness (evolution); Scalability; Sentence; Classifier (UML); Header; Sliding window protocol","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001349401,0.001317105,0.001117756,0.001131421,0.0004876284,0.00120603,0.001404413,0.001459435,0.001474429],"category_scores_gemma":[0.00457602,0.0003975802,0.001167173,0.0004154961,0.0008215675,0.002571509,0.001339989,0.002117851,0.002472159],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0008106731,"about_ca_system_score_gemma":0.001275978,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003701182,"about_ca_topic_score_gemma":0.003320316,"domain_scores_codex":[0.9989229,0.0002441243,0.00006063801,0.0004087069,0.0002569943,0.0001066498],"domain_scores_gemma":[0.9981968,0.0006653758,0.0002342473,0.0002705277,0.0005055557,0.0001273744],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0007084563,0.0009235154,0.01848938,0.0002769313,0.0001988962,0.0006884371,0.0004137465,0.1793196,0.07372592,0.007190179,0.01912454,0.6989405],"study_design_scores_gemma":[0.000006935259,0.00008501525,0.0006107413,0.00000714903,0.00001355652,0.0001051103,0.00002357047,0.9869894,0.009667526,0.001885345,0.0005940296,0.00001150948],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.2580868,0.001022762,0.7191253,0.001194965,0.0003041454,0.0003199762,0.0006002671,0.0153439,0.004001867],"genre_scores_gemma":[0.8429723,0.0002814617,0.1469629,0.000787136,0.0001315866,0.0001474694,0.002113817,0.0004281876,0.006175247],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003701182,"threshold_uncertainty_score":0.007359266,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.02180981101327473,"score_gpt":0.2641078728312054,"score_spread":0.2422980618179307,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}