首页|期刊导航|网络安全与数据治理|融合多尺度CNN与Transformer的恶意软件行为检测方法

融合多尺度CNN与Transformer的恶意软件行为检测方法OA

A malware behavior detection method based on the fusion of multi-scale CNN and Transformer

中文摘要英文摘要

针对恶意软件行为轨迹隐蔽且长序列依赖难以建模的严重威胁,提出一种融合多尺度卷积神经网络与Transformer 架构的恶意软件检测方法,此方法首先借助 Speakeasy 仿真日志去噪及复合事件标记化技术,将冗余日志转化为标准化语义序列,接着运用多层次卷积神经网络结构来提取局部攻击行为特征,在此基础上,将提取的局部攻击行为特征输入 Transformer 编码器,利用多头自注意力机制建模全局时序依赖关系.实验结果表明,该混合模型在 Speakeasy 数据集上的准确率和 F1-Score 分别达到92.29%和92.48%.该方法显著降低了序列检测中的误报率,为复杂网络环境下的恶意软件检测提供了新的技术途径.

To address the severe threats posed by stealthy malware behavioral trajectories and the difficulty in modeling long-sequence depend-encies,this paper proposes a detection method that fuses multi-scale Convolutional Neural Networks(CNN)with the Transformer architecture.First,the approach utilizes Speakeasy simulation logs denoising and composite event tokenization techniques to convert redundant logs into standardized semantic sequences.Next,it employs a multi-layer CNN structure to extract local attack behavior features.Subsequently,these extracted features are fed into a Transformer encoder to model global temporal dependencies via a multi-head self-attention mechanism.The ex-perimental results show that the hybrid model has achieved an accuracy of 92.29%and an F1-Score of 92.48%on the Speakeasy dataset.This approach significantly reduces the false positive rate in sequence detection,providing a new technical pathway for malware detection in complex network environments.

刘帅;王小英;戚盼盼;崔方方;谷瑞泽

应急管理大学 计算机科学与工程学院,河北 廊坊 065201||廊坊市网络应急保障与网络安全重点实验室,河北 廊坊 065201应急管理大学 计算机科学与工程学院,河北 廊坊 065201||廊坊市网络应急保障与网络安全重点实验室,河北 廊坊 065201应急管理大学 计算机科学与工程学院,河北 廊坊 065201||廊坊市网络应急保障与网络安全重点实验室,河北 廊坊 065201应急管理大学 计算机科学与工程学院,河北 廊坊 065201||廊坊市网络应急保障与网络安全重点实验室,河北 廊坊 065201应急管理大学 计算机科学与工程学院,河北 廊坊 065201||廊坊市网络应急保障与网络安全重点实验室,河北 廊坊 065201

信息技术与安全科学

恶意软件检测卷积神经网络Transformer多尺度特征提取动态行为分析

malware detectionConvolutional Neural Network(CNN)Transformermulti-scale feature extractiondynamic behavior analysis

《网络安全与数据治理》 2026 (4)

45-50,6

中央高校基本科研业务费研究生科技创新基金(ZY20260317)立德树人视域下AI赋能网络安全"赛-教-创-研-服"育人路径探索与实践(2026GJJG487)

10.19358/j.issn.2097-1788.2026.04.006

评论