Classifying Sequences of Extreme Length with Constant Memory Applied to Malware Detection
Edward Raff, William Fleshman, Richard Zak, Hyrum S. Anderson, Bobby Filar, Mark McLean
Abstract
Recent works within machine learning have been tackling inputs of ever-increasing size, with cybersecurity presenting sequence classification problems of particularly extreme lengths. In the case of Windows executable malware detection, inputs may exceed 100 MB, which corresponds to a time series with T = 100, 000, 000 steps. To date, the closest approach to handling such a task is MalConv, a convolutional neural network capable of processing up to T = 2, 000, 000 steps. The O(T ) memory of CNNs has prevented further application of CNNs to malware. In this work, we develop a new approach to temporal max pooling that makes the required memory invariant to the sequence length T . This makes MalConv 116× more memory efficient, and up to 25.8× faster to train on its original dataset, while removing the input length restrictions to MalConv. We re-invest these gains into improving the Mal-Conv architecture by developing a new Global Channel Gating design, giving us an attention mechanism capable of learning feature interactions across 100 million time steps in an efficient manner, a capability lacked by the original MalConv CNN. Our implementation can be found at https://github.com/ NeuromorphicComputationResearchProgram/MalConv2
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 76f5ad56-c45c-49eb-81bd-ec368b2f7794Cited by top-tier papers7
- RS-Del: Edit Distance Robustness Certificates for Sequence Classifiers via Randomized DeletionZhuoqun Huang, Neil G. Marchant, Keane Lucas, Lujo Bauer et al.NeurIPS 2023 · 24 citations
- Recasting Self-Attention with Holographic Reduced RepresentationsMohammad Mahmudul Alam, Edward Raff, Stella Biderman, Tim Oates et al.ICML 2023 · 18 citations
- MalCL: Leveraging GAN-Based Generative Replay to Combat Catastrophic Forgetting in Malware ClassificationJimin Park, AHyun Ji, Minji Park, Mohammad Saidur Rahman et al.AAAI 2025 · 12 citations
- Beyond Raw Bytes: Towards Large Malware Language ModelsLuke Kurlandski, Harel Berger, Yin Pan, Matthew WrightNDSS 2026 · 5 citations
- MPass: Bypassing Learning-based Static Malware DetectorsJialai Wang, Wenjie Qu, Yi Rong, Han Qiu et al.DAC 2023 · 4 citations
Builds on3
- Reformer: The Efficient TransformerNikita Kitaev, Lukasz Kaiser, Anselm LevskayaICLR 2020 · 2,878 citations
- A New Burrows Wheeler Transform Markov DistanceEdward Raff, Charles Nicholas, Mark McLeanAAAI 2020 · 13 citations
- An Observational Investigation of Reverse Engineers' ProcessesDaniel Votipka, Seth M. Rabin, Kristopher K. Micinski, Jeffrey S. Foster et al.USENIX Security 2020
Related papers
- Adversarial Training for Raw-Binary Malware ClassifiersKeane Lucas, Samruddhi Pai, Weiran Lin, Lujo Bauer et al.USENIX Security 2023
- Dynamic Malware Analysis with Feature Engineering and Feature LearningZhaoqi Zhang, Panpan Qi, Wei WangAAAI 2020 · 153 citations
- MalDetectFormer: Leveraging Sparse SpatioTemporal Information for Effective Malicious Traffic DetectionShuai Zhang, Yu Fan, Haoyi Zhou, Bo LiAAAI 2025 · 1 citation
- Time-aware Large Kernel ConvolutionsVasileios Lioutas, Yuhong GuoICML 2020 · 30 citations
- Sequence Modeling with Multiresolution Convolutional MemoryJiaxin Shi, Ke Alexander Wang, Emily B. FoxICML 2023 · 24 citations
