Malicious Code Detection Based on AST Multidimensional Feature Fusion and Dynamic Graph Optimization

This paper addresses key issues in current malicious code detection technologies, such as insufficient feature modeling, lack of high-order correlation, and poor adaptability. We propose a novel method for detecting malicious code based on abstract syntax tree (AST) multi-dimensional feature fusion and dynamic graph optimization. This approach innovatively constructs an association-aware graph-enhanced convolution mechanism. First, we use an AST parser to build a code syntax tree, integrating syntactic node type features with word vector semantic features to generate rich contextual multi-dimensional fused embeddings. Next, we introduce a dynamic edge weight adjustment algorithm that adaptively optimizes the graph adjacency matrix based on node attribute similarity, effectively enhancing the representation capability of high-order attack patterns such as cross-process and cross-module attacks. Finally, we design a dynamic loss function with regularization terms to optimize the graph convolution network parameters, improving model generalization performance. Experimental results on the standard Ember dataset show that our method achieves an F1 score of 97.87%, outperforming traditional GCN and GAT baseline models by 3.25%-4.16%. This method effectively overcomes the reliance of traditional detection techniques on static feature libraries, demonstrating significant advantages in complex scenarios such as APT attack chain detection and concurrent behavior analysis in multi-core environments. It provides an efficient and scalable solution for real-time malicious code defense in cloud computing and IoT environments.

Authors

Institutions

Publication Details

Journal
JUCS - Journal of Universal Computer Science
Published
2026-09-14
DOI
https://doi.org/10.3897/jucs.207783
Primary Topic
Advanced Malware Detection Techniques
Type
article
Field-Weighted Citation Impact
0.00

Funders

Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Malicious Code Detection Based on AST Multidimensional Feature Fusion and Dynamic Graph Optimization

Ying Ling, Shaofeng Ming, Songming Han, Xizheng Pan et al.
JUCS - Journal of Universal Computer Science
Advanced Malware Detection Techniques
article

Malicious Code Detection Based on AST Multidimensional Feature Fusion and Dynamic Graph Optimization

Ying Ling, Shaofeng Ming, Songming Han, Xizheng Pan, Xin Li, Zhengwang Miao
article en

Abstract

This paper addresses key issues in current malicious code detection technologies, such as insufficient feature modeling, lack of high-order correlation, and poor adaptability. We propose a novel method for detecting malicious code based on abstract syntax tree (AST) multi-dimensional feature fusion and dynamic graph optimization. This approach innovatively constructs an association-aware graph-enhanced convolution mechanism. First, we use an AST parser to build a code syntax tree, integrating syntactic node type features with word vector semantic features to generate rich contextual multi-dimensional fused embeddings. Next, we introduce a dynamic edge weight adjustment algorithm that adaptively optimizes the graph adjacency matrix based on node attribute similarity, effectively enhancing the representation capability of high-order attack patterns such as cross-process and cross-module attacks. Finally, we design a dynamic loss function with regularization terms to optimize the graph convolution network parameters, improving model generalization performance. Experimental results on the standard Ember dataset show that our method achieves an F1 score of 97.87%, outperforming traditional GCN and GAT baseline models by 3.25%-4.16%. This method effectively overcomes the reliance of traditional detection techniques on static feature libraries, demonstrating significant advantages in complex scenarios such as APT attack chain detection and concurrent behavior analysis in multi-core environments. It provides an efficient and scalable solution for real-time malicious code defense in cloud computing and IoT environments.

JUCS - Journal of Universal Computer ScienceVol. 32(9)
Northeast Electric Power University (CN), Guizhou Electric Power Design and Research Institute (CN)
Electric Power Research Institute
Openalex Percentile: Top 10%
Advanced Malware Detection Techniques
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.