Please use this identifier to cite or link to this item:
http://hdl.handle.net/2080/5946Full metadata record
| DC Field | Value | Language |
|---|---|---|
| dc.contributor.author | Mahanta, Manoj Kumar | - |
| dc.contributor.author | Mohapatra, Durga Prasad | - |
| dc.date.accessioned | 2026-09-22T10:06:32Z | - |
| dc.date.available | 2026-09-22T10:06:32Z | - |
| dc.date.issued | 2026-09 | - |
| dc.identifier.citation | Intelligent Computing and Sustainable Innovation in Technology (IC-SIT), Silicon University, Odisha, 8-10 September 2026 | en_US |
| dc.identifier.uri | http://hdl.handle.net/2080/5946 | - |
| dc.description | Copyright belongs to proceeding publisher | en_US |
| dc.description.abstract | Windows Portable Executable (PE) malware detec-tion based on static feature extraction remains vulnerable to adversarial evasion attacks that manipulate file structure without altering functionality. Prior work demonstrated that a single deep neural network (DNN) trained with Fast Gradient Sign Method (FGSM) adversarial examples achieves improved robustness, but evaluated only one architecture and one attack type. In this paper, we present a systematic study extending that foundation across five deep learning architectures (DNN, 1D-CNN, BiLSTM, CNN-LSTM, and Transformer), each trained under a multi-attack adversarial training regime combining FGSM, Projected Gradient Descent (PGD), and DeepFool attacks on the BODMAS dataset. Models are evaluated on five test conditions: a clean real-world test set and four adversarial variants. We further build a soft-voting ensemble of all adversarially-trained models and provide dual explainability using SHAP and LIME. Our results show that CNN-LSTM and Transformer architectures benefit most from multi-attack adversarial training, achieving overall accuracy of 87.58% and 88.31% respectively on the clean test set. We also quantify the accuracy-robustness tradeoff: the DNN experiences a regression of 7.79 percentage points under multi-attack training, while the Transformer gains 4.87 points, confirming that architectural inductive biases critically determine adversarial training outcomes. | en_US |
| dc.subject | malware detection | en_US |
| dc.subject | adversarial training | en_US |
| dc.subject | deep learning | en_US |
| dc.subject | Windows PE | en_US |
| dc.subject | FGSM | en_US |
| dc.subject | PGD | en_US |
| dc.subject | DeepFool | en_US |
| dc.subject | explainability | en_US |
| dc.subject | SHAP | en_US |
| dc.subject | LIME | en_US |
| dc.title | Multi-Architecture Deep Learning with Multi-Attack Adversarial Training for Windows PE Malware Detection | en_US |
| dc.type | Article | en_US |
| Appears in Collections: | Conference Papers | |
Files in This Item:
| File | Description | Size | Format | |
|---|---|---|---|---|
| 2026_IC_SIT_MKMohanta_Multi-Architecture.pdf | 3.25 MB | Adobe PDF | View/Open Request a copy |
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.
