Information for students interested in research projects
If you are interested in any of the following topics, please contact me with your CV and a brief statement of interest.
A systematic comparison of DST implementation strategies for malware detection, focusing on uncertainty management and evidence fusion. Achieves low false positive rates (0.16%–3.19%).
Status: Open for new student researchers | [Foundational Paper]Robust feature selection using a Genetic Algorithm with Rank-Based Adaptive Mutation (GA-RAM) to preserve semantically meaningful features against adversarial noise.
Status: Open for new student researchers | [Foundational Paper]Combines Siamese networks, deep forest feature extraction, and ensemble learning to handle complex Android application data, achieving 99% accuracy.
Status: Open for new student researchers | [Foundational Paper]Augments function call graphs with contextual features like function-level metadata and code embeddings from LLMs to boost performance by up to 8%.
Status: Open for new student researchers | [Foundational Paper]Uses leaked Conti source code to manipulate runtime parameters (thread count, encryption ratio) to evade AI-based detection systems.
Status: Open for new student researchers | [Foundational Paper]MalViT architecture operates directly in the JPEG frequency domain using DCT coefficients, offering 4.7x faster inference than MobileViT.
Status: Open for new student researchers | [Foundational Paper]Leverages Graph Isomorphism Networks (GIN) and Label Spreading to filter benign background flows, achieving 99.54% accuracy.
Status: Open for new student researchers | [Foundational Paper]Examines the effectiveness of adversarial training in NIDS, highlighting limitations of feature-space perturbations versus raw traffic manipulations.
Status: Open for new student researchers | [Foundational Paper]Integrates Federated Learning with adaptive, ensemble‑style K‑means to discover cluster structures without predefined K, preserving data privacy.
Status: Open for new student researchers | [Foundational Paper]Introduces Assembly Flow Graphs (AFGs) and Meta‑Coarsening for GNN‑based instruction‑level explainability in large-scale binary analysis.
Status: Open for new student researchers | [Foundational Paper]MSMC‑MobileNet uses SE attention and ASPP/FPP modules for multi‑scale feature extraction with reduced computational overhead via pruning.
Status: Open for new student researchers | [Foundational Paper]A two-stage framework for binary detection and family classification using a novel loss function to handle class imbalance and training stability.
Status: Open for new student researchers | [Foundational Paper]Uses a composite CBiLSTMSA architecture to capture spatial and temporal patterns, specifically targeting sophisticated evasion like dynamic code triggering.
Status: Open for new student researchers | [Foundational Paper]A plug‑and‑play module that enhances STPM‑generated images through γ‑mapping, achieving up to 99.82% accuracy on Malimg.
Status: Open for new student researchers | [Foundational Paper]Uses multi‑head cross‑attention for feature exchange and integrates Integrated Gradients, SHAP, and LIME for multi-method transparency.
Status: Open for new student researchers | [Foundational Paper]A stacked ensemble model with PCA and LIME for detecting malicious PDF files, reaching 97% accuracy on the CIC‑Evasive dataset.
Status: Open for new student researchers | [Foundational Paper]Compares user-facing 'intent' from the UI (via Vision-Language Models) with actual runtime behavior to spot hidden malicious activity.
Status: Open for new student researchers | [Foundational Paper]Swarm‑based Inline Machine Learning (SIML) using Gradient Boosting for real-time traffic analysis and policy-based blocking.
Status: Open for new student researchers | [Foundational Paper]Uses diffusion and WGAN-GP to fill semantic gaps in embedding space, rebalancing datasets adaptively during training for underrepresented malware behaviors.
Status: Open for new student researchersThe work presents a Federated Learning pipeline for malware detection that remains reliable even when training data contains both accidental label noise and deliberate adversarial sybil attacks. It isolates malicious clients through cluster‑based scoring and repairs corrupted labels through semi‑supervised refinement, preserving high accuracy despite corruption levels reaching 80%.
Status: Open for new student researchers | [Foundational Paper]This paper presents a malware detection method that uses Large Language Models to extract linguistic cues from Microsoft Office macros, enabling the identification of malicious behavior even under heavy obfuscation. It also contrasts this high‑precision but resource‑intensive approach with a faster statistical alternative, outlining a practical trade‑off for security analysts.
Status: Open for new student researchers | [Foundational Paper]Integrates compact neural architectures with built-in interpretability to achieve low-latency, accurate intrusion detection and transparent decision-making in resource-constrained IoT edge environments.
Status: Open for new student researchers | [Foundational Paper]Combines static decision trees with LLM-generated behavioral rules and direct report analysis via majority voting to enhance detection robustness against concept drift.
Status: Open for new student researchers | [Foundational Paper]Utilizes an ensemble of Random Forest and Gradient Boosting with entropy-based feature selection to outperform traditional classifiers in malware detection accuracy and adaptability.
Status: Open for new student researchers | [Foundational Paper]Introduces a multi-agent multi-armed bandit framework that collaboratively constructs functionality-preserving adversarial perturbations to significantly increase fooling rates against APT malware attribution models.
Status: Open for new student researchers | [Foundational Paper]Introduces a code-centric benchmark and a multi-layer retrieval-augmented LLM framework that integrates static analysis, verification, and curriculum-tuned models to improve malware attribution accuracy and reliability.
Status: Open for new student researchers | [Foundational Paper]Analyzes gray-box poisoning attacks using functionality-preserving binary manipulations and shows how subtle IAT injections degrade LightGBM detection while ensemble filtering mitigates up to 95.6% of poisoning attempts.
Status: Open for new student researchers | [Foundational Paper]Proposes a dynamic complex-network early warning system that uses temporal topology metrics and adaptive baselines to detect pre-propagation malware anomalies with low false positives and significant attack-scale reduction.
Status: Open for new student researchers | [Foundational Paper]Introduces a contrastive consistency model that prevents shortcut collapse in diffusion-based graph prediction by adding negative pairs and feature perturbations to stabilize sampling and improve accuracy.
Status: Open for new student researchers | [Foundational Paper]Evaluates how retrieval-augmented generation affects malware explanation quality and shows that external context often degrades LLM signal extraction when structured evidence is already sufficient.
Status: Open for new student researchers | [Foundational Paper]Proposes a few-shot malware detection framework combining binary visualization, frozen vision–language embeddings, and similarity-based retrieval to enable adaptation without model retraining.
Status: Open for new student researchers | [Foundational Paper]MAGMA decouples malware analysis into semantic retrieval and probabilistic verification, achieving a 98.4% detection rate via a stochastic consistency ensemble.
Status: Open for new student researchers | [Foundational Paper]TUANDROMD-X is a multiclass malware dataset featuring visual and entropy-based static features to facilitate faster and more efficient machine learning detection.
Status: Open for new student researchers | [Foundational Paper]This study introduces ATS, a defense methodology augmenting standard adversarial training with CTGAN-generated synthetic examples, effectively improving PE malware classifier robustness without reducing clean accuracy.
Status: Open for new student researchers | [Foundational Paper]A reinforcement learning framework named MalElves leverages a compact 21-dimensional state design and PPO-based reward shaping to generate functional cross-platform ELF malware adversarial examples.
Status: Open for new student researchers | [Foundational Paper]A hybrid CNN-ViT architecture achieves 93.8% baseline accuracy and 81.8% under localized noise by shifting its self-attention to persistent global payloads.
Status: Open for new student researchers | [Foundational Paper]MalwarePT leverages a 'ModernBERT-style' encoder and byte-pair encoding to create a binary-level foundation model, significantly improving performance across multiple malware analysis tasks
Status: Open for new student researchers | [Foundational Paper]A strictly additive 'Conditional Variational Autoencoder' injects targeted benign API imports into malware, dropping detector recall from 87.5% to 30% while preserving functionality.
Status: Open for new student researchers | [Foundational Paper]Combines ResNet-50 image embeddings and masked autoencoder MLP tabular features with adaptive cross-modal contrastive fusion to detect Android malware under adversarial and obfuscated conditions.
Status: Open for new student researchers | [Foundational Paper]Couples GAN-generated adversarial feature vectors with GitHub Copilot to produce compilable malware binaries that successfully bypass ML-based detectors and commercial antivirus tools.
Status: Open for new student researchers | [Foundational Paper]Leverages diffusion-based generative models to synthesize future malware variants for training detectors before threats emerge, closing the zero-day protection gap.
Status: Open for new student researchers | [Foundational Paper]Combines semi-supervised continual learning, active learning, and SVD-based representation pairing to achieve robust malware detection under limited labeling budgets with 40% AUT improvement.
Status: Open for new student researchers | [Foundational Paper]Fuses static and dynamic malware features via dual Mamba encoders with prototype-guided zero-shot inference, achieving 96.01% accuracy and 88.93% zero-day detection at ~8ms latency.
Status: Open for new student researchers | [Foundational Paper]Constructs 44,347 adversarial PE samples achieving 98.35% evasion against EMBER, showing 0.5% poisoned training data raises evasion rates from 26.1% to 92.8%.
Status: Open for new student researchers | [Foundational Paper]Evaluates adversarial robustness across a decade of Android apps under three deployment protocols, finding temporal drift degrades clean and adversarial accuracy while expanding-window retraining partially mitigates loss.
Status: Open for new student researchers | [Foundational Paper]Introduces host-space perturbations as a realistic adversarial constraint, demonstrating via literature review and experiments that ML-NIDS are evaded by minimal attacker-controlled input changes.
Status: Open for new student researchers | [Foundational Paper]Proposes a unified evaluation framework comparing Hipcheck and Scorecard metrics, revealing low correlation and foundational scoring inconsistencies that undermine software development security measurement reliability.
Status: Open for new student researchers | [Foundational Paper]ARSNet integrates the BASA module with DHM loss to address class imbalance in visualization-based malware detection, achieving 98.6% accuracy and 23% minority recall improvement.
Status: Open for new student researchers | [Foundational Paper]A two-level stacking ensemble using PE file structural features with entropy-based selection achieves 99.37% detection accuracy and 1500 files per second throughput.
Status: Open for new student researchers | [Foundational Paper]A single-encoder Transformer employing multi-head self-attention on Linux process-level kernel telemetry achieves a 0.99 F1-score, outperforming CNN and LSTM baselines by up to 32%.
Status: Open for new student researchers | [Foundational Paper]This study utilizes multiple machine learning models combined with generative adversarial networks to enhance classification accuracy and robustness against Android malware attacks.
Status: Open for new student researchers | [Foundational Paper]This paper proposes FEDWIDroid, utilizing feature embedding, gating, and attention mechanisms for dynamic weighting to accurately classify Android malware from binary features.
Status: Open for new student researchers | [Foundational Paper]This work introduces AMD-FCG, a 30,000-instance dataset integrating function call graphs and topological features to streamline static malware classification across fifty-one classes.
Status: Open for new student researchers | [Foundational Paper]This paper proposes a multi-view framework using a linear cross-attention mechanism to fuse visual and graph representations, significantly improving Android malware detection efficiency.
Status: Open for new student researchers | [Foundational Paper]This study leverages variational autoencoders to generate high-quality synthetic data, effectively mitigating malware data scarcity and enhancing the classification accuracy of baseline machine learning models.
Status: Open for new student researchers | [Foundational Paper]This article introduces a decentralized framework combining localized convolutions with temporal attention mechanisms to ensure private, accurate malware and botnet classification in heterogeneous IoT networks.
Status: Open for new student researchers | [Foundational Paper]This research maps bytecode and volatile memory snapshots into audio waveforms to capture low-level structural signal patterns, achieving robust malware detection without semantic feature engineering.
Status: Open for new student researchers | [Foundational Paper]This work introduces a multi-criteria scoring system that evaluates operational metrics against constraints to systematically rank and recommend machine learning configurations for malware detection.
Status: Open for new student researchers | [Foundational Paper]This work introduces a comprehensive evaluation framework assessing five large language models across lexical, semantic, fluency, and efficiency metrics during assembly-to-source program translation.
Status: Open for new student researchers | [Foundational Paper]This paper introduces a dual-branch framework utilizing a frozen stability branch, a trainable plasticity branch, and median-based prototype learning to mitigate catastrophic forgetting under concept drift.
Status: Open for new student researchers | [Foundational Paper]This paper introduces a hybrid CNN-BiLSTM framework mapping malware byte sequences to 1D signals, integrating SHAP explanations and adversarial training to maximize robustness and transparency.
Status: Open for new student researchers | [Foundational Paper]