PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
January 23, 2026Applied Sciences0 citationsOpen Access

APT Malware Detection Model Based on Heterogeneous Multimodal Semantic Fusion

View Full Paper
CPChaosen PuLWLiang Wan

Key Points

  • The research aims to develop an advanced model for detecting APT malware through multimodal feature fusion.
  • Proposed a model called HMSF-ADM based on heterogeneous multimodal semantic fusion.
  • Utilized a Transformer encoder with DPCFTE and a CAS-ViT encoder for encoding features.
  • Implemented two cross-attention mechanisms for interactive feature fusion.
  • Employed a TextCNN classifier for the final malware classification.
  • HMSF-ADM model outperformed mainstream multimodal comparison models in accuracy, precision, and F1-score.
  • Achieved an F1-score exceeding 0.95 for most APT malware families.
  • Maintained accuracy and F1-score above 0.986 in distinguishing APT malware from regular malware.

Abstract

In recent years, Advanced Persistent Threat (APT) malware, with its high stealth, has made it difficult for unimodal detection methods to accurately identify its disguised malicious behaviors. To address this challenge, this paper proposes an APT Malware Detection Model based on Heterogeneous Multimodal Semantic Fusion (HMSF-ADM). By integrating the API call sequence features of APT malware in the operating system and the RGB image features of PE files, the model constructs multimodal representations with stronger discriminability, thus achieving efficient and accurate identification of APT malicious behaviors. First, the model employs two encoders, namely a Transformer encoder equipped with the DPCFTE module and a CAS-ViT encoder, to encode sequence features and image features, respectively, completing local–global collaborative context modeling. Then, the sequence encoding results and image encoding results are interactively fused via two cross-attention mechanisms to generate fused representations. Finally, a TextCNN-based classifier is utilized to perform classification prediction on the fused representations. Experimental results on two APT malware datasets demonstrate that the proposed HMSF-ADM model outperforms various mainstream multimodal comparison models in core metrics such as accuracy, precision, and F1-score. Notably, the F1-score of the model exceeds 0.95 for the vast majority of APT malware families, and its accuracy and F1-score both remain above 0.986 in the task of distinguishing between ordinary malware and APT malware.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Pu et al. (2026) studied this question.

synapsesocial.com/papers/69730f9fc8125b09b0d1f70ahttps://doi.org/10.3390/app16021083
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Attribution classification method of APT malware based on multi-feature fusion2024 · 8 citations
  2. 2The rise of machine learning for detection and classification of malware: Research developments, trends and challenges2020 · 625 citations
  3. 3Deep Residual Learning for Image Recognition2016 · 228,429 citations
  4. 4BiTCN-TAEfficientNet malware classification approach based on sequence and RGB fusion2024 · 15 citations
  5. 5Uncovering APT malware traffic using deep learning combined with time sequence and association analysis2022 · 39 citations