TY - JOUR
T1 - DynMD
T2 - Energy-Based Dynamic Graph Representation Learning for Malware Detection
AU - Liu, Chen
AU - Li, Bo
AU - Wu, Yidong
AU - Liu, Xudong
AU - Li, Jianxin
AU - Li, Chunpei
N1 - Publisher Copyright:
© 2004-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - Graph Neural Networks (GNNs) have found widespread application in malware detection tasks in recent years, aiming to uncover the malicious nature of target processes by aggregating neighborhood information via different relations. However, current GNN-based malware detection models are primarily designed for static graphs or fixed-window dynamic graphs; they often overlook the correlation between distinct continuous behaviors and specific attacks (e.g., code injection), leading to a disruption in the attack’s continuity and incurring substantial computing overhead. This paper introduces a novel model dubbed DynMD, designed to enhance the efficiency of malware detection on streaming behavioral data via energy-based dynamic graph representation learning. Concretely, DynMD investigates an energy function to adaptively partition windows, facilitating the construction of a lossless malware dynamic heterogeneous graph. More importantly, DynMD proposes a unique time-aware dynamic graph learning method to capture energy-concordant dynamic neighborhoods. This approach involves both intra-graph and inter-graph message propagation, promoting dynamic graph learning while avoiding time-consuming and repetitive computations. Experimental results on three real-world malware datasets show that DynMD improves detection accuracy by up to 3.99% and achieves detection 3.81× to 5.33× faster than the MG-DVD framework, identifying malware within an average of 40 seconds of execution.
AB - Graph Neural Networks (GNNs) have found widespread application in malware detection tasks in recent years, aiming to uncover the malicious nature of target processes by aggregating neighborhood information via different relations. However, current GNN-based malware detection models are primarily designed for static graphs or fixed-window dynamic graphs; they often overlook the correlation between distinct continuous behaviors and specific attacks (e.g., code injection), leading to a disruption in the attack’s continuity and incurring substantial computing overhead. This paper introduces a novel model dubbed DynMD, designed to enhance the efficiency of malware detection on streaming behavioral data via energy-based dynamic graph representation learning. Concretely, DynMD investigates an energy function to adaptively partition windows, facilitating the construction of a lossless malware dynamic heterogeneous graph. More importantly, DynMD proposes a unique time-aware dynamic graph learning method to capture energy-concordant dynamic neighborhoods. This approach involves both intra-graph and inter-graph message propagation, promoting dynamic graph learning while avoiding time-consuming and repetitive computations. Experimental results on three real-world malware datasets show that DynMD improves detection accuracy by up to 3.99% and achieves detection 3.81× to 5.33× faster than the MG-DVD framework, identifying malware within an average of 40 seconds of execution.
KW - Graph neural networks
KW - dynamic graph representation learning
KW - energy-based model
KW - malware detection
UR - https://www.scopus.com/pages/publications/105018722633
U2 - 10.1109/TDSC.2025.3619926
DO - 10.1109/TDSC.2025.3619926
M3 - 文章
AN - SCOPUS:105018722633
SN - 1545-5971
VL - 23
SP - 1592
EP - 1607
JO - IEEE Transactions on Dependable and Secure Computing
JF - IEEE Transactions on Dependable and Secure Computing
IS - 1
ER -