Malicious Code Detection Based on AST Multidimensional Feature Fusion and Dynamic Graph Optimization
This paper addresses key issues in current malicious code detection technologies, such as insufficient feature modeling, lack of high-order correlation, and poor adaptability. We propose a novel method for detecting malicious code based on abstract syntax tree (AST) multi-dimensional feature fusion and dynamic graph optimization. This approach innovatively constructs an association-aware graph-enhanced convolution mechanism. First, we use an AST parser to build a code syntax tree, integrating syntactic node type features with word vector semantic features to generate rich contextual multi-dimensional fused embeddings. Next, we introduce a dynamic edge weight adjustment algorithm that adaptively optimizes the graph adjacency matrix based on node attribute similarity, effectively enhancing the representation capability of high-order attack patterns such as cross-process and cross-module attacks. Finally, we design a dynamic loss function with regularization terms to optimize the graph convolution network parameters, improving model generalization performance. Experimental results on the standard Ember dataset show that our method achieves an F1 score of 97.87%, outperforming traditional GCN and GAT baseline models by 3.25%-4.16%. This method effectively overcomes the reliance of traditional detection techniques on static feature libraries, demonstrating significant advantages in complex scenarios such as APT attack chain detection and concurrent behavior analysis in multi-core environments. It provides an efficient and scalable solution for real-time malicious code defense in cloud computing and IoT environments.
Authors
- Ying Ling
- Shaofeng Ming (ORCID: https://orcid.org/0009-0000-6020-779X)
- Songming Han (ORCID: https://orcid.org/0009-0006-8829-6724)
- Xizheng Pan (ORCID: https://orcid.org/0009-0004-3176-9354)
- Xin Li (ORCID: https://orcid.org/0009-0003-6144-5839)
- Zhengwang Miao (ORCID: https://orcid.org/0009-0002-1708-2666)
Institutions
- Northeast Electric Power University (CN)
- Guizhou Electric Power Design and Research Institute (CN)
Publication Details
- Journal
- JUCS - Journal of Universal Computer Science
- Published
- 2026-09-14
- DOI
- https://doi.org/10.3897/jucs.207783
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00
Funders
- Electric Power Research Institute