A Multi-Modal Deep Learning Framework for Robust Detection of Obfuscated API Calls in Malware Analysis

Nayankumar M. Mali Narendrasinh C. Chauhan

Журнал: International Journal of Computer Network and Information Security @ijcnis

Статья в выпуске: 5 vol.18, 2026 года.

Бесплатный доступ

Malware developers employ advanced API obfuscation techniques, such as name randomization, dynamic resolution, call stack manipulation, parameter spoofing, and API chaining, to bypass detection. Existing unimodal analysis systems frequently fail to identify these threats due to their limited scope. To address this, we introduce a novel multi-modal deep learning framework that combines temporal, structural, and parametric analysis for malware detection. This multi‑modal method uses a temporal encoder with self‑attention to detect name obfuscation and API chaining, Graph attention networks analyze call graphs for call stack tampering and dynamic API resolution, while a contrastive learning module identifies anomalous parameter usage. A key novel approach is the dynamic fusion mechanism, which uses attention-based weighting to combine features, enhancing accuracy and interpretability. Additionally, adversarial training ensures robustness against evasion attempts, with theoretical guarantees on performance under variations. Evaluated on 29,505 real‑world malware samples, the proposed multi‑modal framework achieves a 94.2% F1‑score (an 18% improvement over unimodal baselines) and a 98.1% AUC‑ROC. The framework notably maintains 82% robustness against adversarial variations, significantly outperforming conventional LSTM‑based approaches (45%). Beyond detection, the proposed method provides explainable attention maps for forensic analysis and low latency (<1ms/sample), making it suitable for real-time security deployment. These results suggest that multi-modal fusion is critical for next-generation endpoint protection.

Malware Detection \ API Obfuscation \ Multi-Modal Deep Learning \ Graph Attention Networks (GATs) \ Behavioural Malware Analysis \ API Call Graph Analysis \ Contrastive Learning

Короткий адрес: https://sciup.org/15020704

IDS: 15020704   |   DOI: 10.5815/ijcnis.2026.05.08