Jithin S., Roshin Sleeba C., Anvin Mariya P. B., Asmitha K. A., Vinod P., Serena Nicolazzo, Antonino Nocera
This paper proposes a unified multi-task malware analysis framework using Mixture of Experts (MoE) architectures to address the challenges of heterogeneity, packed binaries, and diverse family distributions in malware classification.
Malware classification is difficult due to inherent heterogeneity, packed binaries, and diverse family distributions. Traditional single-model detection mechanisms often fail to generalize across such diverse data, leading to degraded performance, especially on obfuscated and rare samples.
The framework uses two input representations (EMBER features and raw 1D byte arrays) to simultaneously perform three tasks: malware family classification, packed/unpacked detection, and malware/benign identification. It decomposes the problem into specialized expert networks with adaptive gating mechanisms for task-specific learning while maintaining scalability. Multiple architectural variants, including Homogeneous MoE, Heterogeneous MoE, and Multi-Gate MoE (MMoE), are investigated.
The Multi-Gate MoE model achieves the best performance with a combined detection rate of 0.9744 and a failure rate of only 2.56%. It also exhibits improved robustness under mutation-induced distribution shifts. The findings highlight the effectiveness of expert specialization and task-specific routing in handling complex malware distributions, making the framework a promising direction for scalable and resilient malware detection systems.