Shaji, Rony (2025) Robust Deep Learning Models for Multi-Source Malware Detection Through Stacking-Based Model Integration. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (924kB) | Preview |
Preview |
PDF (Configuration Manual)
Download (809kB) | Preview |
Abstract
As malicious software grows increasingly sophisticated, the use of obfuscation, polymorphism, and memory residency makes it harder for classical detection based on either static or one-source-based analysis. This study addresses the need for improved and generalized approaches to detection by introducing the Integrated Learning Framework for Deep Learning that integrates all types of memory-forensics feature sets. In the CIC-MalMem-2022 competition, the research proposes the use of two customized learning models, CNN-MLP for the structural behavioral characteristics and FT-Transformer for the contextual dependencies based on the Win-DLL and combines their predictions using logistic regression-based model stacking. The experimentally validated findings show the superior performance capability of the individual base learner and the modest but significant improvement potential of the proposed Integrated learning. Interesting SHAPTAIL explainer analyses confirm the well-balanced contributions of both learners for promoting model understandability and applicability. These experimental insights suggest that Integrated learning, based on multiple sources, can enhance the performance capability of malicious software detection, especially for dynamic and memory-centric scenarios. Future research can take into consideration robustness evaluation against malicious attempts and the use of varied forensic corpora, since enhanced external validity is warranted.
| Item Type: | Thesis (Masters) |
|---|---|
| Supervisors: | Name Email Mahajan, Kamil UNSPECIFIED |
| Uncontrolled Keywords: | Malware Detection; Deep Learning; Integrated Learning; Memory Forensics; Explainable AI |
| Subjects: | Q Science > QH Natural history > QH301 Biology > Methods of research. Technique. Experimental biology > Data processing. Bioinformatics > Artificial intelligence Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Artificial intelligence Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Machine learning |
| Divisions: | School of Computing > Master of Science in Cyber Security |
| Depositing User: | Ciara O'Brien |
| Date Deposited: | 04 Sep 2026 10:23 |
| Last Modified: | 04 Sep 2026 10:23 |
| URI: | https://norma.ncirl.ie/id/eprint/9829 |
Actions (login required)
![]() |
View Item |
Tools
Tools