IP Library › Granted Patent US 12,475,225
Granted Patent B2
US 12,475,225 · App. 18/160,467 · Granted Nov 18, 2025

Aggressive embedding dropout in embedding-based malware detection

Inventors: Diana Bolocan (Galati, RO); Mihaela-Petruta Gaman (Bucharest, RO); Marian Radu (Bucharest, RO)
Assignee: CrowdStrike, Inc.
G06F21/566G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,475,225
App. No.
18/160,467
Granted
Nov 18, 2025
Kind
B2
Abstract

Malware is detected using an embedding-based machine learning model. The model generates embeddings using byte n-grams. A feature importance operation reveals that only a subset of the embeddings is required to detect malware. In some cases, even a single embedding is adequate and retains 99% detection capabilities. An aggressive embedding dropout operation is implemented that ignores lesser-important embeddings. Because perhaps only one, or a few, embeddings need be determined, malware detection is greatly simplified. Malware detection is greatly simplified and need not calculate full-sized embeddings. A malware detection service runs quicker, and just as capably, while consuming less resources.

Claims (24)

1 . A method executed by a computer that detects a malware, comprising:

receiving, by the computer, n-gram embeddings generated by a byte n-gram embedding model using byte n-grams;

determining, by the computer, a descriptive n-gram embedding of the n-gram embeddings by ranking the n-gram embeddings according to a feature importance operation; and

detecting, by the computer, the malware using a malware classifier trained using an aggressive embedding dropout operation that drops the n-gram embeddings according to a rank determined by the feature importance operation.

2 . The method of claim 1 , further comprising identifying the descriptive n-gram embedding by ranking positional indices associated with the n-gram embedding.

3 . The method of claim 1 , further comprising identifying the descriptive n-gram embedding by ranking values associated with the n-gram embeddings.

4 . The method of claim 1 , further comprising selecting an n-gram embedder according to the descriptive n-gram embedding.

5 . The method of claim 1 , further comprising selecting an n-gram feature extractor according to the descriptive n-gram embedding.

6 . The method of claim 1 , further comprising classifying a byte buffer.

7 . The method of claim 1 , further comprising detecting the malware associated with bits in a byte buffer.

8 . The method of claim 1 , wherein the determining of the descriptive n-gram embedding further comprises applying a principal components analysis to the n-gram embeddings.

9 . At least one computer system that detects a malware, comprising:

at least one central processing unit; and

at least one memory device storing instructions that, when executed by the at least one central processing unit, perform operations, the operations comprising:

receiving n-gram embeddings associated with an embedding vector generated by a byte n-gram embedding model using byte n-grams;

determining a hyperparameter by ranking positional indices associated with the embedding vector according to a feature importance operation; and

detecting the malware using a malware classifier trained using an aggressive embedding dropout operation that drops the n-gram embeddings according to the hyperparameter determined by the feature importance operation.

10 . The at least one computer system of claim 9 , wherein the operations further comprise identifying the descriptive n-gram embedding by the ranking of the positional indices.

11 . The at least one computer system of claim 9 , wherein the operations further comprise identifying the descriptive n-gram embedding by ignoring at least one of the positional indices.

12 . The at least one computer system of claim 9 , wherein the operations further comprise selecting an n-gram embedder according to the descriptive n-gram embedding.

13 . The at least one computer system of claim 9 , wherein the operations further comprise selecting an n-gram feature extractor according to the descriptive n-gram embedding.

14 . The at least one computer system of claim 9 , wherein the operations further comprise classifying a byte buffer.

15 . The at least one computer system of claim 9 , wherein the operations further comprise detecting the malware associated with bits in a byte buffer.

16 . The at least one computer system of claim 9 , wherein the operations further comprise applying a principal components analysis to the n-gram embeddings.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2023
From: BOLOCAN, DIANA; GAMAN, MIHAELA-PETRUTA; RADU, MARIAN
To: CROWDSTRIKE, INC.
Reel/Frame 062509/0554 →
Continuity (1)
Related Publication 20240256666A1 · Aug 1, 2024
References Cited (12)
US 9843596B1 · Averbuch et al. · 2017 [cited by applicant]
US 20190007434A1 · McLane et al. · 2019 [cited by applicant]
US 20190272375A1 · Chen · 2019 [cited by examiner]
US 20200005082A1 · Cazan et al. · 2020 [cited by applicant]
US 20220366040A1 · Marbouti · 2022 [cited by examiner]
CN 110362995A · 2019 [cited by examiner]
CN 111382439A · 2020 [cited by examiner]
Kolter, J. Zico & Maloof, Marcus A., “Learning to Detect and Classify Malicious Executables in the Wild,” Journal of Machine Learning Research, Dec. 2006, 24 pages. [cited by applicant]
Malhi, Arnaz, “PCA-Based Feature Selection Scheme for Machine Defect Classification,” IEEE Transactions on Instrumentation and Measurement, vol. 53, No. 6, Dec. 2004, 9 pages. [cited by applicant]
Zhang, Xiang, Drouin, Alexandre, & Li, Raymond, “byteSteady: Fast Classification Using Byte-Level n-Gram Embeddings,” arXiv:2106.13302 [cs.CL], Jun. 24, 2021, 7 pages. [cited by applicant]
Zhu et al., “Self-representation and PCS embedding for unsupervised feature selection,” Topical Collection: Special Issue on Deep Mining Big Social Data, Jul. 27, 2017, 14 pages. [cited by applicant]
Raff et al., “An Investigation of Byte N-Gram Features for Malware Classification,” Journal of Computer Virology and Hacking Techniques, Mar. 30, 2016, 20 pages. [cited by applicant]