---
格式版本: 2
标题: "Malformer: A Multi-Modal Malware Detector Using Transformers"
原文链接: "https://arxiv.org/abs/2608.19052"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 19 Aug 2026 15:46:28 UTC (5,849 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:32:09+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:26:21+08:00"
入库时间: "2026-08-20T07:32:09.895Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=performance&searchtype=all"
匹配关键词:
  - "performance"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 5
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "内容为恶意软件检测的学术论文，与超节点、AI Rack、机柜级AI基础设施、供电散热互连等主题完全无关，不涉及任何项目关注点。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:34:49+08:00"
AI主题相关性: 0
AI来源权威性: 5
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 5
AI摘要: "Malformer 是一种基于 Transformer 的四模态恶意软件检测模型，将 Windows 可执行文件的文本、图像、图和音频表征融合用于分类。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:18:54.624Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.19052"
---

## Computer Science > Cryptography and Security

## Title:Malformer: A Multi-Modal Malware Detector Using Transformers

[View PDF](https://arxiv.org/pdf/2608.19052) [HTML (experimental)](https://arxiv.org/html/2608.19052v1)

> Abstract:Traditional malware detection systems that rely on a single representation of malware often fail to identify novel threats. These representations of malware binaries, also known as modalities, do not provide the models with sufficient information to discriminate among all samples. Additionally, individual representations introduce new failure modes, with some modality extraction being dependent upon the success of disassembling. Past works have integrated either additional modalities or more discriminative representations for classification. In this work, we present Malformer, a quadrimodal malware detection model that incorporates text, image, graph, and audio representations of Windows executables. We demonstrate that multimodal transformer fusion can enhance the performance of Windows malware detectors over that of unimodal and bimodal detectors. Malformer employs a combination of two RoBERTa encoders paired with a modified Vision Transformer for image data, WavLM for audio data, and an adaptive loss-weighting scheme to fuse modality-specific representations. Evaluated on a dataset of 201,549 binary samples, Malformer achieved 98.3% accuracy and an F1 score of 0.9833, outperforming both unimodal baselines and bimodal detectors by 4.6-17.6 percentage points. Malformer demonstrates that multimodal fusion provides a promising foundation for countering the growing scale of malware threats, equipping defenders with generalized and resilient detection capabilities.

| Subjects: | Cryptography and Security (cs.CR) |
| --- | --- |
| Cite as: | [arXiv:2608.19052](https://arxiv.org/abs/2608.19052) \[cs.CR\] |
|  | (or [arXiv:2608.19052v1](https://arxiv.org/abs/2608.19052v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.19052](https://doi.org/10.48550/arXiv.2608.19052) |

## Submission history

From: Kshitiz Aryal \[[view email](https://arxiv.org/show-email/3ac6e420/2608.19052)\]  
**\[v1\]** Wed, 19 Aug 2026 15:46:28 UTC (5,849 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.19052) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
