Skip to main navigation Skip to search Skip to main content

Packing Induced Bias in Deep Learning Malware Classifiers: A Systematic Experimental Study

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Packing is a highly used malware evasion technique that compresses, encrypts, or obfuscates executable content, significantly altering the structural characteristics that static malware detectors rely on. While prior work has studied the impact of packing on traditional feature based classifiers, limited attention has been given to understanding how modern deep learning based static detectors behave under realistic packing conditions. This paper investigates the robustness and generalization capabilities of a CNN based malware detector trained on image representations of Windows Portable Executable (PE) binaries by conducting two controlled experiments. The first evaluates how increasing exposure to packed benign ware affects a model's ability to correctly distinguish packed malware from packed benign binaries. Results show initial improvement in true negative rates, followed by instability as packing artifacts dominate learned representations. The second experiment analyzes cross packer generalization and demonstrates strong packer dependency, where models perform well only on packers seen during training and collapse when confronted with unseen packers. Overall, our findings demonstrate that packing significantly undermines the reliability of static deep learning based malware detectors, highlighting the need for packing aware training strategies and more resilient detection models.

Original languageEnglish (US)
Title of host publication2026 IEEE 5th International Conference on AI in Cybersecurity, ICAIC 2026
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781665477611
DOIs
StatePublished - 2026
Event5th IEEE International Conference on AI in Cybersecurity, ICAIC 2026 - Houston, United States
Duration: Feb 18 2026Feb 20 2026

Publication series

Name2026 IEEE 5th International Conference on AI in Cybersecurity, ICAIC 2026

Conference

Conference5th IEEE International Conference on AI in Cybersecurity, ICAIC 2026
Country/TerritoryUnited States
CityHouston
Period2/18/262/20/26

Keywords

  • Deep Learning
  • Malware Detection
  • Software Packing

ASJC Scopus subject areas

  • Information Systems and Management
  • Safety, Risk, Reliability and Quality
  • Artificial Intelligence
  • Computer Science Applications
  • Decision Sciences (miscellaneous)

Fingerprint

Dive into the research topics of 'Packing Induced Bias in Deep Learning Malware Classifiers: A Systematic Experimental Study'. Together they form a unique fingerprint.

Cite this