Pith. sign in

REVIEW 2 cited by

Virus-MNIST: A Benchmark Malware Dataset

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2103.00602 v1 pith:4NIS6HCT submitted 2021-02-28 cs.CR cs.LG

classification cs.CRcs.LG
keywords datasetfamiliesimagemalwarevirusbytesexecutableaccuracy
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The short note presents an image classification dataset consisting of 10 executable code varieties and approximately 50,000 virus examples. The malicious classes include 9 families of computer viruses and one benign set. The image formatting for the first 1024 bytes of the Portable Executable (PE) mirrors the familiar MNIST handwriting dataset, such that most of the previously explored algorithmic methods can transfer with minor modifications. The designation of 9 virus families for malware derives from unsupervised learning of class labels; we discover the families with KMeans clustering that excludes the non-malicious examples. As a benchmark using deep learning methods (MobileNetV2), we find an overall 80% accuracy for virus identification by families when beneware is included. We also find that once a positive malware detection occurs (by signature or heuristics), the projection of the first 1024 bytes into a thumbnail image can classify with 87% accuracy the type of virus. The work generalizes what other malware investigators have demonstrated as promising convolutional neural networks originally developed to solve image problems but applied to a new abstract domain in pixel bytes from executable files. The dataset is available on Kaggle and Github.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Signal-Based Malware Classification Using 1D CNNs

    cs.CR 2025-09 conditional novelty 5.0 of 10

    Resizing malware binaries to 1D signals and classifying them with 1D CNNs yields slight F1 improvements over 2D byteplot image models on MalNet.

  2. MalVol-25: A Diverse, Labelled and Detailed Volatile Memory Dataset for Malware Detection and Response Testing and Validation

    cs.CR 2025-07 conditional novelty 4.0 of 10

    MalVol-25 is a new dataset of 30 clean and infected Windows memory dumps from 15 malware variants, intended for ML and agentic AI detection research.

Pith tools