Feature Fusion in Vector Spaces for Static Cryptojacking Detection in WebAssembly

  • Bento P. Ch. Baptista UFAM
  • Euler Vieira UFAM / IFAM
  • Andrés D. Peralta UFAM
  • Eduardo L. Feitosa UFAM

Abstract


The proliferation of WebAssembly (Wasm) has fostered cryptojacking campaigns whose opaque binaries evade conventional detection. This paper proposes a static-analysis method based on feature fusion in vector spaces: the binary’s Abstract Syntax Tree is segmented into functional chunks, and semantic embeddings are fused with deterministic structural metrics associated with Proof-of-Work routines. Three independent strategies operate over the resulting vector base: topological similarity, supervised learning, and zero-shot inference via LLM. Evaluation on 74 binaries totaling 53,888 chunks showed that aggregated classification via Linear SVM achieves an F1-Score of 0.95, while topological triage attains an MRR of 0.92 with sub-second latency invariant to binary size, enabling both large-scale synchronous triage and asynchronous forensic auditing without dynamic instrumentation.

References

Cabrera-Arteaga, J., Monperrus, M., Toady, T., and Baudry, B. (2023). Webassembly diversification for malware evasion. Computers & Security, 131:103296.

Cao, S., He, N., Guo, Y., and Wang, H. (2024). Wasmixer: Binary obfuscation for webassembly. In Computer Security – ESORICS 2024. Springer.

Chawla, N. V., Bowyer, K. W., Hall, L. O., and Kegelmeyer, W. P. (2002). Smote: synthetic minority over-sampling technique. Journal of artificial intelligence research, 16:321–357.

Cortes, C. and Vapnik, V. (1995). Support-vector networks. Machine learning, 20(3):273–297.

Cside (2025). Cryptojacking is dead: long live cryptojacking. acessado em 15-10-2025.

Géron, A. (2022). Hands-on machine learning with Scikit-Learn, Keras, and TensorFlow. ”O’Reilly Media, Inc.”.

Haas, A., Rossberg, A., Schuff, D. L., Titzer, B. L., Holman, M., Gohman, D., Wagner, L., Zakai, A., and Bastien, J. (2017). Bringing the web up to speed with webassembly. SIGPLAN Not., 52(6):185–200.

Harnes, H. and Morrison, D. (2024a). Cryptic bytes: Webassembly obfuscation for evading cryptojacking detection. arXiv preprint arXiv:2403.15197.

Harnes, H. and Morrison, D. (2024b). Sok: Analysis techniques for webassembly. Future Internet, 16(3):84.

Hoffman, K. (2019). Programming WebAssembly with Rust: unified development for web, mobile, and embedded applications. The Pragmatic Bookshelf.

Hong, G., Yang, Z., Yang, S., Zhang, L., Nan, Y., Zhang, Z., Yang, M., Zhang, Y., Qian, Z., and Duan, H. (2018). How you get shot in the back: A systematical study about cryptojacking in the real world. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS ’18, page 1701–1713, New York, NY, USA. Association for Computing Machinery.

Kharraz, A., Ma, Z., Murley, P., Lever, C., Mason, J., Miller, A., Borisov, N., Antonakakis, M., and Bailey, M. (2019). Outguard: Detecting in-browser covert cryptocurrency mining in the wild. In The World Wide Web Conference, WWW ’19, page 840–852, New York, NY, USA. Association for Computing Machinery.

Konoth, R. K., Vineti, E., Moonsamy, V., Lindorfer, M., Kruegel, C., Bos, H., and Vigna, G. (2018). Minesweeper: An in-depth look into drive-by cryptocurrency mining and its defense. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS ’18, page 1714–1730, New York, NY, USA. Association for Computing Machinery.

Loose, N., Mächtle, F., Pott, C., Bezsmertnyi, V., and Eisenbarth, T. (2023). Madvex: instrumentation-based adversarial attacks on machine learning malware detection. In International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, pages 69–88. Springer.

Ma, W., Liu, S., Lin, Z., Wang, W., Hu, Q., Liu, Y., Zhang, C., Nie, L., Li, L., and Liu, Y. (2023). Lms: Understanding code syntax and semantics for code analysis. arXiv preprint arXiv:2305.12138.

Malkov, Y. A. and Yashunin, D. A. (2018). Efficient and robust approximate nearest neighbor search using hierarchical navigable small world graphs. IEEE transactions on pattern analysis and machine intelligence, 42(4):824–836.

Musch, M., Wressnegger, C., Johns, M., and Rieck, K. (2019). Thieves in the browser: Web-based cryptojacking in the wild. In Proceedings of the 14th International Conference on Availability, Reliability and Security, ARES ’19, New York, NY, USA. Association for Computing Machinery.

Naseem, F. N., Aris, A., Babun, L., Tekiner, E., and Uluagac, A. S. (2021). Minos: A lightweight real-time cryptojacking detection system. In NDSS.

Pan, J. J., Wang, J., and Li, G. (2023). Survey of vector database management systems. arXiv preprint arXiv:2310.14021.

Pedregosa, F., Varoquaux, G., Gramfort, A., Michel, V., Thirion, B., Grisel, O., Blondel, M., Prettenhofer, P., Weiss, R., Dubourg, V., et al. (2011). Scikit-learn: Machine learning in python. Journal of Machine Learning Research, 12:2825–2830.

Peng, J. and outros (2025). Wasmguard: Enhancing web security through robust raw-binary detection of webassembly malware. In Proceedings of the ACM Web Conference 2025 (WWW ’25). ACM.

Perrone, G. and Romano, S. P. (2025). Webassembly and security: a review. Computer Science Review, 56:100728.

QDRANT (2026). Qdrant: High-performance vector search engine. Qdrant Technologies. Versão 1.18.

Romano, A., Zheng, Y., and Wang, W. (2020). Minerray: Semantics-aware analysis for ever-evolving cryptojacking detection. In Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering, pages 1129–1140.

Sonic Wall (2024). Sonicwall cyber threat report. [link]. acessado em 17-Dez-2024.

Taipalus, T., Grahn, H., Turtiainen, H., and Costin, A. (2024). Utilizing vector database management systems in cyber security. In Proceedings of the 23th European Conference on Cyber Warfare and Security. Academic Conferences International Ltd.

Xia, Y., He, P., Zhang, X., Liu, P., Ji, S., and Wang, W. (2023). Static semantics reconstruction for enhancing javascript-webassembly multilingual malware detection. In European Symposium on Research in Computer Security, pages 255–276. Springer.
Published
2026-09-01
BAPTISTA, Bento P. Ch.; VIEIRA, Euler; PERALTA, Andrés D.; FEITOSA, Eduardo L.. Feature Fusion in Vector Spaces for Static Cryptojacking Detection in WebAssembly. In: BRAZILIAN SYMPOSIUM ON CYBERSECURITY (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 660-675. DOI: https://doi.org/10.5753/sbseg.2026.24181.

Most read articles by the same author(s)

<< < 1 2