Netinfo Security ›› 2026, Vol. 26 ›› Issue (7): 1028-1043.doi: 10.3969/j.issn.1671-1122.2026.07.003

Previous Articles     Next Articles

Enhancing malware detection via multi-view sensitivity mining and Sens-FiLM modulation

Kou Liang(), Tu Guoxuan, Pan Xiaochen, Zhang Jilin   

  1. College of Cyberspace, Hangzhou Dianzi University, Hangzhou 310018, China
  • Received:2026-05-14 Online:2026-07-10 Published:2026-09-03
  • Contact: Kou Liang E-mail:kouliang@hdu.edu.cn

Abstract:

Leveraging contextual semantics in API sequences is effective for malware detection, yet the security semantics of run-time parameters remain underexplored. Although recent studies attempt to incorporate run-time parameters via static labeling, they often fail to capture the dynamic semantic ambiguity where risk varies by API context and often fail to detect individual anomalies that evade cluster-based patterns. This paper proposed MvSe-Mal, a multi-view sensitivity mining framework for malware detection. The framework first employed statistical risk analysis to quantify the intrinsic security level of API operations. Then, it established a three-dimensional sensitivity quantification mechanism by integrating complementary mining strategies: cluster analysis to capture grouped malicious behaviors, individual anomaly detection to pinpoint statistical irregularities, and API affinity to measure the associative strength between parameters and malicious API. Finally, it proposed a sensitivity-aware feature-wise linear modulation (Sens-FiLM) mechanism. Instead of simple static concatenation, Sens-FiLM treated sensitivity levels as dynamic conditions to recalibrate the intermediate feature representations of deep neural networks. This enabled the model to adaptively highlight high-risk behavioral patterns while suppressing noise based on real-time sensitivity contexts. The framework were evaluated on two DNN models. Extensive experiments demonstrate that MvSe-Mal significantly outperformed not only baselines relying solely on API sequences but also existing approaches that incorporate parameters, validating the effectiveness of the proposed strategy.

Key words: malware detection, API sequence, run-time parameter, FiLM, deep learning

CLC Number: