Hybrid Feature Image Mapping (HFIM): A Multi-Channel Image Approach for Malware Detection Using Static and Dynamic Features

Elgarduh, Anis and Zainal, Anazida and Ghaleb, Fuad A. and Qasem, Sultan Noman and Albarrak, Abdullah M. and Saeed, Faisal (2026) Hybrid Feature Image Mapping (HFIM): A Multi-Channel Image Approach for Malware Detection Using Static and Dynamic Features. IEEE Access, 14. pp. 114422-114440. ISSN 2169-3536

[thumbnail of Hybrid_Feature_Image_Mapping_HFIM_A_Multi-Channel_Image_Approach_for_Malware_Detection_Using_Static_and_Dynamic_Features.pdf]
Preview
Text
Hybrid_Feature_Image_Mapping_HFIM_A_Multi-Channel_Image_Approach_for_Malware_Detection_Using_Static_and_Dynamic_Features.pdf - Published Version
Available under License Creative Commons Attribution.

Download (3MB)

Abstract

Image-based malware detection has emerged as an alternative to high-dimensional handcrafted feature representations; however, most existing approaches rely primarily on static features or encode multiple features from a single analysis domain, which may limit robustness under code obfuscation and incomplete feature extraction. This paper proposes Hybrid Feature Image Mapping (HFIM), a multi-channel malware visualization technique that integrates structural (binary content), semantic (opcode transitions), and behavioral (API activity) information into a unified RGB representation. HFIM is designed as a representation-level approach that encodes complementary static and dynamic characteristics within a single image, allowing convolutional neural networks (CNNs) to exploit complementary cross-domain patterns while maintaining classification performance when certain feature streams are partially unavailable. HFIM is evaluated against three representative malware imaging methods, HIT4Mal, MC-ISA, and MTV, using seven CNN architectures under identical training conditions to ensure fair comparison and isolate the impact of feature representation. Experimental results based on 10-fold cross-validation demonstrate consistent improvements across multiple evaluation metrics, including accuracy, precision, recall, and F1-score. Additional analyses, including ablation and family-aware evaluation, further indicate that multi-domain integration provides a more discriminative and stable representation than single-domain approaches, particularly under variations in feature availability. These results indicate that integrating static and dynamic features at the representation level can improve robustness and classification performance in image-based malware detection.

Item Type: Article
Identification Number: 10.1109/ACCESS.2026.3716364
Dates:
Date
Event
13 July 2026
Accepted
23 July 2026
Published Online
Uncontrolled Keywords: Licenses, Malware, Modeling, Nuclear facility regulation, Signal detection, Visualization, Accuracy, Application programming interfaces, Convolutional neural networks, Computers
Subjects: CAH11 - computing > CAH11-01 - computing > CAH11-01-01 - computer science
Divisions: Architecture, Built Environment, Computing and Engineering > Computer Science
Depositing User: Gemma Tonks
Date Deposited: 24 Aug 2026 12:50
Last Modified: 24 Aug 2026 12:50
URI: https://www.open-access.bcu.ac.uk/id/eprint/17180

Actions (login required)

View Item View Item

Research

In this section...