IP Library › Granted Patent US 12,518,012
Granted Patent B2
US 12,518,012 · App. 18/490,141 · Granted Jan 6, 2026

Structure-aware neural networks for malware detection

Inventors: David Benjamin Krisiloff (Arlington, VA); Scott Eric Coull (Cary, NC)
Assignee: GOOGLE LLC
G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,518,012
App. No.
18/490,141
Granted
Jan 6, 2026
Kind
B2
Abstract

Provided is a malware detection system that provides structure-aware neural networks for performing malware detection. In particular, rather than treat the entire computer file as one large input to a deep neural network, the malware detection system can break the file up based on the internal file structure. Each portion of the computer file can then be processed using individual neural networks and the outputs of these networks can be combined and similarly processed. In this way the overall system can evaluate the file with knowledge of the structure of the file, enabling the malware detection to have a higher-order understanding of the interoperation of different portions of the computer file.

Claims (58)

1 . A computer-implemented method to perform malware detection via hierarchically-organized machine learning models, the method comprising:

obtaining, by a computing system comprising one or more computing devices, a computer file to be analyzed for malware detection, wherein the computer file has a structure;

parsing, by the computing system, the computer file into a plurality of file portions based on the structure of the computer file;

respectively processing, by the computing system, the plurality of file portions with a plurality of machine-learned feature extractor models to respectively generate a plurality of feature embeddings respectively for the plurality of file portions, such that each file portion is processed by one of the machine-learned feature extractor models to generate one of the feature embeddings, and wherein each feature embedding comprises a numerical vector expressed within a latent space;

combining, by the computing system, the plurality of feature embeddings within the latent space; and

processing, by the computing system, the combination of the plurality of feature embeddings with a machine-learned prediction model to generate, as an output of the machine-learned prediction model, a model prediction for the computer file, wherein the model prediction is indicative of a malware classification for the computer file.

2 . The computer-implemented method of claim 1 , wherein:

parsing, by the computing system, the computer file into the plurality of file portions based on the structure of the computer file comprises assigning, by the computing system, a respective portion class to each of the plurality of file portions; and

the respective machine-learned feature extractor model used to process each file portion comprises a class-specific model trained specifically for the portion class assigned to the file portion.

3 . The computer-implemented method of claim 1 , wherein parsing, by the computing system, the computer file into the plurality of file portions based on the structure of the computer file comprises applying, by the computing system, a rule-based parsing engine that applies a plurality of user-defined parsing rules.

4 . The computer-implemented method of claim 1 , wherein each of the plurality of machine-learned feature extractor models comprises a convolutional neural network, and wherein the machine-learned prediction model comprises a transformer neural network.

5 . The computer-implemented method of claim 1 , wherein, for at least a first file portion of the plurality of file portions:

the method further comprises parsing, by the computing system, the first file portion into a plurality of file sub-portions; and

processing, by the computing system, the first file portion with the respective machine-learned feature extractor model comprises:

respectively processing, by the computing system, the plurality of file sub-portions with a plurality of machine-learned feature extractor sub-models to respectively generate a plurality of intermediate feature embeddings respectively for the plurality of file sub-portions; and

processing, by the computing system, the plurality of intermediate feature embeddings with a feature aggregation model to generate the feature embedding for the first file portion.

6 . The computer-implemented method of claim 1 , wherein the model prediction comprises a binary or logistic malware classification for the computer file.

7 . The computer-implemented method of claim 1 , wherein the model prediction comprises a multiclass malware family classification for the computer file.

8 . The computer-implemented method of claim 1 , wherein the model prediction comprises a functionality classification or an attribution classification for the computer file.

9 . The computer-implemented method of claim 1 , further comprising:

determining, by the computing system, that the computer file comprises malware based on the model prediction; and

in response to determining that the computer file comprises malware: generating, by the computing system, a malware alert or performing, by the computing system, a malware response action.

10 . One or more non-transitory computer-readable media that collectively store instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations, the operations comprising:

obtaining, by the computing system, a computer file, wherein the computer file has a structure;

parsing, by the computing system, the computer file into a plurality of file portions based on the structure of the computer file;

respectively processing, by the computing system, the plurality of file portions with a plurality of machine-learned feature extractor models to respectively generate a plurality of feature embeddings respectively for the plurality of file portions, such that each file portion is processed by one of the machine-learned feature extractor models to generate one of the feature embeddings, and wherein each feature embedding comprises a numerical vector expressed within a latent space;

combining, by the computing system, the plurality of feature embeddings within the latent space; and

processing, by the computing system, the combination of the plurality of feature embeddings with a machine-learned prediction model to generate, as an output of the machine-learned prediction model, an output representation for the computer file.

11 . The one or more non-transitory computer-readable media of claim 10 , wherein:

parsing, by the computing system, the computer file into the plurality of file portions based on the structure of the computer file comprises assigning, by the computing system, a respective portion class to each of the plurality of file portions; and

the respective machine-learned feature extractor model used to process each file portion comprises a class-specific model trained specifically for the portion class assigned to the file portion.

12 . The one or more non-transitory computer-readable media of claim 10 , wherein parsing, by the computing system, the computer file into the plurality of file portions based on the structure of the computer file comprises applying, by the computing system, a rule-based parsing engine that applies a plurality of user-defined parsing rules.

13 . The one or more non-transitory computer-readable media of claim 10 , wherein each of the plurality of machine-learned feature extractor models comprises a convolutional neural network and the machine-learned prediction model comprises a transformer neural network.

14 . The one or more non-transitory computer-readable media of claim 10 , wherein, for at least a first file portion of the plurality of file portions:

the operations further comprise parsing, by the computing system, the first file portion into a plurality of file sub-portions; and

processing, by the computing system, the first file portion with the respective machine-learned feature extractor model comprises:

respectively processing, by the computing system, the plurality of file sub-portions with a plurality of machine-learned feature extractor sub-models to respectively generate a plurality of intermediate feature embeddings respectively for the plurality of file sub-portions; and

processing, by the computing system, the plurality of intermediate feature embeddings with a feature aggregation model to generate the feature embedding for the first file portion.

15 . The one or more non-transitory computer-readable media of claim 10 , further comprising:

using, by the computing system, the output representation for the computer file to perform a downstream task for the computer file, wherein the downstream task comprises a similarity search task or an anomaly detection task.

16 . A computing system to train a set of hierarchically-organized machine learning models for malware detection, the computer system comprising one or more processors and one or more non-transitory computer-readable media that collectively store instructions that, when executed by the one or more processors, cause the computing system to perform operations, the operations comprising:

obtaining, by the computing system, a computer file, wherein the computer file has a structure, and wherein a ground truth label is associated with the computer file;

parsing, by the computing system, the computer file into a plurality of file portions based on the structure of the computer file;

respectively processing, by the computing system, the plurality of file portions with a plurality of machine-learned feature extractor models to respectively generate a plurality of feature embeddings respectively for the plurality of file portions, such that each file portion is processed by one of the machine-learned feature extractor models to generate one of the feature embeddings, and wherein each feature embedding comprises a numerical vector expressed within a latent space;

combining, by the computing system, the plurality of feature embeddings within the latent space; and

processing, by the computing system, the combination of the plurality of feature embeddings with a machine-learned prediction model to generate, as an output of the machine-learned prediction model, a model prediction for the computer file, wherein the model prediction is indicative of a malware classification for the computer file;

evaluating, by the computing system, a loss function that generates a loss value based on a comparison of the model prediction for the computer file with the ground truth label for computer file; and

modifying, by the computing system, one or more parameter values of the machine-learned prediction model and the plurality of machine-learned feature extractor models based on the loss function.

17 . The computing system of claim 16 , wherein:

parsing, by the computing system, the computer file into the plurality of file portions based on the structure of the computer file comprises assigning, by the computing system, a respective portion class to each of the plurality of file portions; and

the respective machine-learned feature extractor model used to process each file portion comprises a class-specific model trained specifically for the portion class assigned to the file portion.

18 . The computing system of claim 16 , wherein parsing, by the computing system, the computer file into the plurality of file portions based on the structure of the computer file comprises applying, by the computing system, a rule-based parsing engine that applies a plurality of user-defined parsing rules.

19 . The computing system of claim 16 , wherein each of the plurality of machine-learned feature extractor models comprises a convolutional neural network and the machine-learned prediction model comprises a transformer neural network.

20 . The computing system of claim 16 , wherein, for at least a first file portion of the plurality of file portions:

the operations further comprise parsing, by the computing system, the first file portion into a plurality of file sub-portions; and

processing, by the computing system, the first file portion with the respective machine-learned feature extractor model comprises:

respectively processing, by the computing system, the plurality of file sub-portions with a plurality of machine-learned feature extractor sub-models to respectively generate a plurality of intermediate feature embeddings respectively for the plurality of file sub-portions; and

processing, by the computing system, the plurality of intermediate feature embeddings with a feature aggregation model to generate the feature embedding for the first file portion.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2023
From: KRISILOFF, DAVID BENJAMIN; COULL, SCOTT ERIC
To: GOOGLE LLC
Reel/Frame 065297/0107 →
Continuity (1)
Related Publication 20250131092A1 · Apr 24, 2025
References Cited (32)
US 8424091B1 · Su · 2013 [cited by examiner]
US 9705904B1 · Davis · 2017 [cited by examiner]
US 11108809B2 · Johns et al. · 2021 [cited by applicant]
US 11637859B1 · Johns et al. · 2023 [cited by applicant]
US 11689567B2 · Gadhe · 2023 [cited by examiner]
US 11720686B1 · Cross · 2023 [cited by examiner]
US 12118087B2 · Vukmirovic · 2024 [cited by examiner]
US 20170262633A1 · Miserendino · 2017 [cited by examiner]
US 20180063169A1 · Zhao · 2018 [cited by examiner]
US 20180278647A1 · Gabaev · 2018 [cited by examiner]
US 20200218807A1 · Davis · 2020 [cited by examiner]
US 20220318386A1 · Bhosale · 2022 [cited by examiner]
US 20230205883A1 · Ulasen · 2023 [cited by examiner]
US 20230353595A1 · Hu · 2023 [cited by examiner]
US 20240004993A1 · Rozenberg · 2024 [cited by examiner]
US 20240232349A1 · Briliauskas · 2024 [cited by examiner]
US 20240256666A1 · Bolocan · 2024 [cited by examiner]
US 20250045393A1 · Rokka Chhetri · 2025 [cited by examiner]
Coull et al., “Activation Analysis of a Byte-Based Deep Neural Network for Malware Classification”, arXiv:1903.04717v2, Mar. 20, 2019, 7 pages. [cited by applicant]
Fleshman et al., “Non-Negative Networks Against Adversarial Attack”, arXiv:1806.06108v2, Jan. 3, 2019, 12 pages. [cited by applicant]
Ghouti et al., “Malware Classification Using Compact Image Features and Multiclass Support Vector Machines”, IET Information Security, vol. 14, Issue 4, May 15, 2020, 11 pages. [cited by applicant]
Krcal et al., “Deep Convolutional Malware Classifiers Can Learn from Raw Executables and Labels Only”, Workshops at the International Conference on Learning Representations, Vancouver, Canada, Apr. 30-May 3, 2018, 4 pag… [cited by applicant]
Kumar et al., “DTMIC: Deep Transfer Learning for Malware Image Classification”, Journal of Information Security and Applications, vol. 64, Feb. 1, 2022, 12 pages. [cited by applicant]
Makandar et al., “Malware Class Recognition Using Image Processing Techniques”, 2017 International Conference on Data Management, Analytics and Innovation, Pune, India, Feb. 24-26, 2017, 5 pages. [cited by applicant]
Park, “A Vision Transformer Enhanced with Patch Encoding for Malware Classification”, Intelligent Data Engineering and Automated Learning—IDEAL 2022, 2022, p. 289-299. [cited by applicant]
Raff et al., “Classifying Sequences of Extreme Length with Constant Memory Applied to Malware Detection”, arXiv:2012.09390v1, Dec. 17, 2020, 14 pages. [cited by applicant]
Raff et al., “Malware Detection by Eating a Whole Exe”, arXiv:1710.09435v1, Oct. 25, 2017, 13 pages. [cited by applicant]
Su et al., “Lightweight Classification of IoT Malware Based on Image Recognition”, arXiv:1802.03714v1, Feb. 11, 2018, 7 pages. [cited by applicant]
Venkatraman et al., “A Hybrid Deep Learning Image-Based Analysis for Effective Malware Detection”, Journal of Information Security and Applications, vol. 47, Jan. 31, 2020, 23 pages. [cited by applicant]
Vu et al., “HIT4Mal: Hybrid Image Transformation for Malware Classification”, Transactions on Emerging Telecommunications Technologies, vol. 31, Issue 11, Nov. 4, 2020, 16 pages. [cited by applicant]
Bakour et al., “VisDroid: Android Malware Classification Based on Local and Global Image Features, Bag of Visual Words and Machine Learning Techniques”, Neural Computing and Applications, vol. 33, Jul. 11, 2020, 21 page… [cited by applicant]
Son et al., “An Enhancement for Image-based Malware Classification Using Machine Learning with Low Dimension Normalized Input Images” Journal of Information Security and Applications, vol. 69, Sep. 1, 2022, 20 pages. [cited by applicant]