inklap

Multimodal Malware Detection under Obfuscated and Adversarial Attack Conditions Using ResNet-50 and MLP Encoders with Contrastive Learning and Adaptive Cross-Modal Fusion

Peter Sackitey, Collinson Colin Mawunyo Agbesi, Timothy Graham · Applied Cybersecurity & Internet Governance · 2026

Traditional Android malware detection methods such as basic heuristic and signature-based methods as well as those trained on unimodal data samples are exposed to challenges from contemporary malware that utilizes advanced evasion techniques like adversarial and obfuscation perturbed variants to avoid detection. This work presents a multimodal malware detection method that uses image-based and tabular representations of Android APKs. A ResNet-50 network is used to extract visual embeddings from byteplot images that capture structural patterns resilient to obfuscated variants, while tabular data was analysed by a masked autoencoder pre-trained MLP to model behavioural correlations. An adaptive fusion technique dynamically weights the contributions of each modality per sample while Cross-modal contrastive learning aligns these embeddings in a shared latent space. The fused representation is fed into a supervised classifier to predict benign and malware categories. Adversarial, obfuscated, and clean scenarios confirmed outstanding results on tests samples from the multimodal CIC-MalDroid2020 dataset. Evaluation metrics include accuracy, recall, precision, F1-score, and macro-averaged

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً