arXiv · 2609.38390
Behavior-Centric Malware Classification with Fine-Grained Malicious Logic Localization
Abstract
Effective malware analysis requires understanding not only whether a program is malicious, but also which behaviors it exhibits and where those behaviors originate in the code. Existing machine-learning-based malware detectors largely operate as black boxes, providing limited insight into the malicious logic responsible for their decisions. This paper addresses malicious behavior localization and classification at the basic-block level. We propose a behavior-centric analysis framework that decomposes malware samples into behaviors and systematically links these behaviors to their originating code regions. Using context-sensitive backward slicing from security-relevant system API calls, we reconstruct control- and data-dependency chains and represent each behavior as a structured graph of related basic blocks. A Transformer-based model captures instruction-level semantics, while a Graph Neural Network models structural dependencies within behavior graphs. The resulting representations are fused to enable accurate and interpretable classification, with attention-based attribution identifying code regions responsible for malicious behaviors. We evaluate our approach using standard classification metrics and a behavior coverage metric that measures the detection of manually labeled malicious behaviors. Our results demonstrate that the proposed framework achieves accurate malware classification while providing fine-grained, behavior-aware localization of malicious logic.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Prakriti Baral, Zhuoyun Qian, Hailu Xu, Fangtian Zhong. 2026-09-29. Behavior-Centric Malware Classification with Fine-Grained Malicious Logic Localization. https://arxiv.org/abs/2609.38390
Cite the original work for its findings. Save a collection to share your selection of sources.