Image-Based Malware Type Classification on MalNet-Image Tiny: Effects of Multi-Scale Fusion, Transfer Learning, Data Augmentation, and Schedule-Free Optimization

📅 2026-04-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the challenge of scale variation in Android malware image classification caused by differing binary lengths. On the MalNet-Image Tiny benchmark, it presents the first systematic investigation into the synergistic effects of combining Feature Pyramid Networks (FPN), ImageNet pretraining, Mixup and TrivialAugment data augmentation, and the schedule-free AdamW optimizer. Using a ResNet18 backbone, the study comprehensively evaluates how multi-scale feature fusion, transfer learning, and lightweight augmentation strategies influence classification performance across 43 malware families. The optimal configuration achieves superior results—F1_macro = 0.6927, P_macro = 0.7707, AUC_macro = 0.9556, and L_test = 0.8536—in just 10 training epochs, substantially outperforming the original baseline trained for 96 epochs in both accuracy and efficiency.

Technology Category

Machine Learning: Multi-class/Multi-label Learning & Extreme ClassificationComputer Vision: Adversarial Attacks & RobustnessApplication Domains: Mobility, Driving & Flight

Application Category

Web Mining and Content Analysis: Large pretrained models with web dataSystems and Infrastructure for Web, Mobile and WoT: Applied ML and AI for Web-based mobile applicationsSecurity and Privacy: Large-scale security measurements
📝 Abstract
This paper studies 43-class malware type classification on MalNet-Image Tiny, a public benchmark derived from Android APK files. The goal is to assess whether a compact image classifier benefits from four components evaluated in a controlled ablation: a feature pyramid network (FPN) for scale variation induced by resizing binaries of different lengths, ImageNet pretraining, lightweight augmentation through Mixup and TrivialAugment, and schedule-free AdamW optimization. All experiments use a ResNet18 backbone and the provided train/validation/test split. Reproducing the benchmark-style configuration yields macro-F1 (F1_macro) of 0.6510, consistent with the reported baseline of approximately 0.65. Replacing the optimizer with schedule-free AdamW and using unweighted cross-entropy increases F1_macro to 0.6535 in 10 epochs, compared with 96 epochs for the reproduced baseline. The best configuration combines pretraining, Mixup, TrivialAugment, and FPN, reaching F1_macro=0.6927, P_macro=0.7707, AUC_macro=0.9556, and L_test=0.8536. The ablation indicates that the largest gains in F1_macro arise from pretraining and augmentation, whereas FPN mainly improves P_macro, AUC_macro, and L_test in the strongest configuration.
Problem

Research questions and friction points this paper is trying to address.

malware classification
image-based malware detection
multi-scale variation
MalNet-Image Tiny
Android APK
Innovation

Methods, ideas, or system contributions that make the work stand out.

multi-scale fusion
transfer learning
data augmentation
schedule-free optimization
malware classification
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
A
Ahmed A. Abouelkhaire
Department of Electrical and Computer Engineering, University of Victoria, Victoria, BC, Canada
Waleed A. Yousef
Waleed A. Yousef
Associate Professor of Computer Science, Helwan University
Pattern RecognitionMachine LearningData AnalysisData ScienceComputer Aided Detection
I
Issa Traoré
Department of Electrical and Computer Engineering, University of Victoria, Victoria, BC, Canada