Redes Neurais sem Pesos Aplicadas à Detecção Zero-day de Programas Maliciosos por Imagem
Resumo
Este trabalho apresenta um estudo exploratório sobre a aplicação das arquiteturas WiSARD e ClusWiSARD à detecção de malware baseada em visualização de binários como imagens, utilizando o conjunto de dados MaleVis. O desempenho é avaliado em dois cenários: o convencional, com todas as famílias disponíveis para treinamento, e o de emulação de zero-day, em que famílias são omitidas do treinamento. No primeiro, os modelos atingiram acurácia balanceada média em torno de 91%. No segundo, o detector binário manteve desempenho semelhante sobre as famílias conhecidas, enquanto a revocação da família omitida variou amplamente dependendo das características visuais de cada classe, superando 60% em cerca de 40% das classes avaliadas.Referências
Aleksander, I., Gregorio, M. D., França, F., Lima, P., and Morton, H. (2009). A brief introduction to weightless neural systems. In 17th European Symposium on Artificial Neural Networks (ESANN), pages 299–305.
Aleksander, I., Thomas, W., and Bowden, P. (1984). WISARD: A radical step forward in image recognition. Sensor Review, 4(3):120–124.
Bacellar, A. T. L., Susskind, Z., Breternitz Jr., M., John, E., John, L. K., Lima, P. M. V., and França, F. M. G. (2024). Differentiable weightless neural networks. In Proceedings of the 41st International Conference on Machine Learning (ICML), volume 235 of PMLR.
Bavishi, S. and Modi, S. (2024). Accelerating malware classification: A vision transformer solution. Disponível em: [link]. Acesso em: 08 maio 2026.
Bledsoe, W. W. and Browning, I. (1959). Pattern recognition and reading by machine. In IRE-AIEE-ACM Computer Conference, IRE-AIEE-ACM ’59 (Eastern), pages 225–232. Association for Computing Machinery.
Bozkir, A. S., Cankaya, A. O., and Aydos, M. (2019). Utilization and comparison of convolutional neural networks in malware recognition. In 2019 27th Signal Processing and Communications Applications Conference (SIU), pages 1–4.
Brezinski, K. and Ferens, K. (2023). Metamorphic malware and obfuscation: A survey of techniques, variants, and generation kits. Security and Communication Networks, 2023:8227751.
Cardoso, D. O., Carvalho, D., Alves, D. S. F., de Souza, D. F. P., Carneiro, H. C. C., Pedreira, C. E., Lima, P. M. V., and França, F. M. G. (2016). Financial credit analysis via a clustering weightless neural classifier. Neurocomputing, 183:70–78.
Carvalho, D., Carneiro, H., França, F., and Lima, P. (2013). B-bleaching: Agile overtraining avoidance in the WiSARD weightless neural classifier. In 21st European Symposium on Artificial Neural Networks (ESANN).
Comar, P. M., Liu, L., Saha, S., Tan, P.-N., and Nucci, A. (2013). Combining supervised and unsupervised learning for zero-day malware detection. In Proceedings of IEEE INFOCOM, pages 2022–2030.
Egele, M., Scholte, T., Kirda, E., and Kruegel, C. (2012). A survey on automated dynamic malware-analysis techniques and tools. ACM Computing Surveys, 44(2).
Filho, A. S. L., Guarisa, G. P., Filho, L. L., Oliveira, L. F. R., França, F. M. G., and Lima, P. M. V. (2020). wisardpkg — a library for WiSARD-based models. Disponível em: [link]. Acesso em: 08 maio 2026.
Gopinath, M. and Sethuraman, S. C. (2023). A comprehensive survey on deep learning based malware detection techniques. Computer Science Review, 47:100529.
Guo, Y. (2023). A review of machine learning-based zero-day attack detection: Challenges and future directions. Computer Communications, 198:175–185.
HUMIR Lab (2019). MaleVis: A dataset for vision based malware recognition. Disponível em: [link]. Acesso em: 08 maio 2026.
Kappaun, A., Camargo, K., Rangel, F., Firmino, F., Lima, P. M. V., and Oliveira, J. (2016). Evaluating binary encoding techniques for WiSARD. In 2016 5th Brazilian Conference on Intelligent Systems (BRACIS), pages 103–108.
Kim, J.-Y., Bu, S.-J., and Cho, S.-B. (2018). Zero-day malware detection using transferred generative adversarial networks based on deep autoencoders. Information Sciences, 460–461:83–102.
Nataraj, L. (2015). A Signal Processing Approach to Malware Analysis. PhD thesis, University of California, Santa Barbara.
Pillow Development Team (2025a). PIL.Image.Image.convert() — Pillow 12.0.0 documentation. Disponível em: [link]. Acesso em: 08 maio 2026.
Pillow Development Team (2025b). PIL.Image.Image.resize() — Pillow 12.0.0 documentation. Disponível em: [link]. Acesso em: 08 maio 2026.
Quertier, T., Marais, B., Barrué, G., Morucci, S., Azé, S., and Salladin, S. (2024). A lean transformer model for dynamic malware analysis and detection. Disponível em: [link]. Acesso em: 08 maio 2026.
Ramos, L., Filho, L. L., França, F., and Lima, P. (2020). Detecção estática e dinâmica de malwares usando redes neurais sem peso. In Anais do XX Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais, pages 369–381, Porto Alegre, RS, Brasil. SBC.
Rey, V., Sánchez, P. M. S., Celdrán, A. H., and Bovet, G. (2022). Federated learning for malware detection in IoT devices. Computer Networks, 204:108693.
Salas, M. P. and de Geus, P. L. (2024). Deep learning applied to imbalanced malware datasets classification. Journal of Internet Services and Applications, 15(1):342–359.
Susskind, Z., Arora, A., Miranda, I. D. S., Bacellar, A. T. L., Villon, L. A. Q., Katopodis, R. F., de Araújo, L. S., Dutra, D. L. C., Lima, P. M. V., França, F. M. G., Breternitz Jr., M., and John, L. K. (2023). ULEEN: A novel architecture for ultra-low-energy edge neural networks. ACM Transactions on Architecture and Code Optimization, 20(4).
Susskind, Z., Arora, A., Miranda, I. D. S., Villon, L. A. Q., Katopodis, R. F., Araújo, L. S. D., Dutra, D. L. C., Lima, P. M. V., França, F. M. G., Breternitz, M., and John, L. K. (2022). Weightless neural networks for efficient edge inference. In Proceedings of the 31st International Conference on Parallel Architectures and Compilation Techniques (PACT’22).
Ucci, D., Aniello, L., and Baldoni, R. (2019). Survey of machine learning techniques for malware analysis. Computers & Security, 81:123–147.
Aleksander, I., Thomas, W., and Bowden, P. (1984). WISARD: A radical step forward in image recognition. Sensor Review, 4(3):120–124.
Bacellar, A. T. L., Susskind, Z., Breternitz Jr., M., John, E., John, L. K., Lima, P. M. V., and França, F. M. G. (2024). Differentiable weightless neural networks. In Proceedings of the 41st International Conference on Machine Learning (ICML), volume 235 of PMLR.
Bavishi, S. and Modi, S. (2024). Accelerating malware classification: A vision transformer solution. Disponível em: [link]. Acesso em: 08 maio 2026.
Bledsoe, W. W. and Browning, I. (1959). Pattern recognition and reading by machine. In IRE-AIEE-ACM Computer Conference, IRE-AIEE-ACM ’59 (Eastern), pages 225–232. Association for Computing Machinery.
Bozkir, A. S., Cankaya, A. O., and Aydos, M. (2019). Utilization and comparison of convolutional neural networks in malware recognition. In 2019 27th Signal Processing and Communications Applications Conference (SIU), pages 1–4.
Brezinski, K. and Ferens, K. (2023). Metamorphic malware and obfuscation: A survey of techniques, variants, and generation kits. Security and Communication Networks, 2023:8227751.
Cardoso, D. O., Carvalho, D., Alves, D. S. F., de Souza, D. F. P., Carneiro, H. C. C., Pedreira, C. E., Lima, P. M. V., and França, F. M. G. (2016). Financial credit analysis via a clustering weightless neural classifier. Neurocomputing, 183:70–78.
Carvalho, D., Carneiro, H., França, F., and Lima, P. (2013). B-bleaching: Agile overtraining avoidance in the WiSARD weightless neural classifier. In 21st European Symposium on Artificial Neural Networks (ESANN).
Comar, P. M., Liu, L., Saha, S., Tan, P.-N., and Nucci, A. (2013). Combining supervised and unsupervised learning for zero-day malware detection. In Proceedings of IEEE INFOCOM, pages 2022–2030.
Egele, M., Scholte, T., Kirda, E., and Kruegel, C. (2012). A survey on automated dynamic malware-analysis techniques and tools. ACM Computing Surveys, 44(2).
Filho, A. S. L., Guarisa, G. P., Filho, L. L., Oliveira, L. F. R., França, F. M. G., and Lima, P. M. V. (2020). wisardpkg — a library for WiSARD-based models. Disponível em: [link]. Acesso em: 08 maio 2026.
Gopinath, M. and Sethuraman, S. C. (2023). A comprehensive survey on deep learning based malware detection techniques. Computer Science Review, 47:100529.
Guo, Y. (2023). A review of machine learning-based zero-day attack detection: Challenges and future directions. Computer Communications, 198:175–185.
HUMIR Lab (2019). MaleVis: A dataset for vision based malware recognition. Disponível em: [link]. Acesso em: 08 maio 2026.
Kappaun, A., Camargo, K., Rangel, F., Firmino, F., Lima, P. M. V., and Oliveira, J. (2016). Evaluating binary encoding techniques for WiSARD. In 2016 5th Brazilian Conference on Intelligent Systems (BRACIS), pages 103–108.
Kim, J.-Y., Bu, S.-J., and Cho, S.-B. (2018). Zero-day malware detection using transferred generative adversarial networks based on deep autoencoders. Information Sciences, 460–461:83–102.
Nataraj, L. (2015). A Signal Processing Approach to Malware Analysis. PhD thesis, University of California, Santa Barbara.
Pillow Development Team (2025a). PIL.Image.Image.convert() — Pillow 12.0.0 documentation. Disponível em: [link]. Acesso em: 08 maio 2026.
Pillow Development Team (2025b). PIL.Image.Image.resize() — Pillow 12.0.0 documentation. Disponível em: [link]. Acesso em: 08 maio 2026.
Quertier, T., Marais, B., Barrué, G., Morucci, S., Azé, S., and Salladin, S. (2024). A lean transformer model for dynamic malware analysis and detection. Disponível em: [link]. Acesso em: 08 maio 2026.
Ramos, L., Filho, L. L., França, F., and Lima, P. (2020). Detecção estática e dinâmica de malwares usando redes neurais sem peso. In Anais do XX Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais, pages 369–381, Porto Alegre, RS, Brasil. SBC.
Rey, V., Sánchez, P. M. S., Celdrán, A. H., and Bovet, G. (2022). Federated learning for malware detection in IoT devices. Computer Networks, 204:108693.
Salas, M. P. and de Geus, P. L. (2024). Deep learning applied to imbalanced malware datasets classification. Journal of Internet Services and Applications, 15(1):342–359.
Susskind, Z., Arora, A., Miranda, I. D. S., Bacellar, A. T. L., Villon, L. A. Q., Katopodis, R. F., de Araújo, L. S., Dutra, D. L. C., Lima, P. M. V., França, F. M. G., Breternitz Jr., M., and John, L. K. (2023). ULEEN: A novel architecture for ultra-low-energy edge neural networks. ACM Transactions on Architecture and Code Optimization, 20(4).
Susskind, Z., Arora, A., Miranda, I. D. S., Villon, L. A. Q., Katopodis, R. F., Araújo, L. S. D., Dutra, D. L. C., Lima, P. M. V., França, F. M. G., Breternitz, M., and John, L. K. (2022). Weightless neural networks for efficient edge inference. In Proceedings of the 31st International Conference on Parallel Architectures and Compilation Techniques (PACT’22).
Ucci, D., Aniello, L., and Baldoni, R. (2019). Survey of machine learning techniques for malware analysis. Computers & Security, 81:123–147.
Publicado
01/09/2026
Como Citar
ROTAVA, André; LIMA, Priscila M. V.; DUTRA, Diego L. C..
Redes Neurais sem Pesos Aplicadas à Detecção Zero-day de Programas Maliciosos por Imagem. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 993-1008.
DOI: https://doi.org/10.5753/sbseg.2026.27749.
