Comparative Evaluation of Machine Learning and Deep Learning Paradigms in Modern Malware Detection: Performance, Trade-Offs and Deployment Architectures
Author
Abdullateef Ajibola Adepoju, Saidu Sunbo Akanji, Rukayya Abdulganiyu Adepoju, Atuma Ochenu Lawrence
Abstract
Malware detection remains a vital cornerstone of modern cybersecurity infrastructure. However, selecting between classical machine learning (ML) algorithms and advanced deep learning (DL) frameworks involves complex architectural and operational trade-offs. This study presents a detailed, multi-dimensional comparative analysis evaluating classical ML models (such as Random Forest, Support Vector Machines and XGBoost) alongside deep neural architectures (including Convolutional Neural Networks, LSTMs and autoencoders). Based on a comprehensive synthesis of empirical studies across standard benchmark repositories (EMBER, Drebin, Malimg) and enterprise environments, we evaluate detection metrics, computational resource overheads, model interpretability and resilience against adversarial evasion. The empirical findings reveal that while deep learning frameworks consistently achieve superior classification performance (achieving overall detection accuracies of 96–99% on raw byte streams and sequential API traces), classical machine learning classifiers trained on domain-engineered features offer competitive detection rates (90–95%), vastly superior inference speed (<50 ms), lower false-positive rates (1–3%), and lightweight execution footprints ideal for edge deployment. Furthermore, deep neural networks exhibit heightened vulnerability to adversarial perturbations, suffering significant performance drops (15–40%) unless hardened through specialized defenses. Building upon these empirical insights, we establish actionable decision principles and operational guidelines tailored for cloud, endpoint, IoT and hybrid deployment scenarios, concluding with strategic directions for future research in hybrid architectures and adversarial resilience.
Keywords
Malware Detection, Machine Learning, Deep Learning, Adversarial Robustness, Cybersecurity Infrastructure, Explainable AI, Empirical Synthesis.
Full Text:
References
AlDhaqm, A., Abd Razak, S., Othman, S. H., Nagappan, G., & Ali, A. (2023). API injection and feature masking techniques in machine learning-based malware detection. Journal of Information Security and Applications, 75, 103480.
Alshmarni, A. F., & Alliheedi, M. A. (2023). Enhancing malware detection by integrating machine learning with Cuckoo Sandbox. arXiv preprint arXiv:2308.04211.
Anderson, H. S., & Roth, P. (2018). EMBER: An open dataset for training static PE malware machine learning models. arXiv preprint arXiv:1804.04619.
Bensaoud, A., Kalita, J., & Bensaoud, M. (2024). A survey of malware detection using deep learning. arXiv preprint arXiv:2401.03123.
Berrios, S., Leiva, D., Olivares, B., Allende-Cid, H., & Hermosilla, P. (2025). Systematic review: Malware detection and classification in cybersecurity. Applied Sciences, 15(14), 7747.
Bilot, T., El Madhoun, N., Al Agha, K., & Zouaoui, A. (2023). A survey on malware detection with graph representation learning. arXiv preprint arXiv:2303.02115.
Dambra, S., Han, Y., Aonzo, S., Kotzias, P., Vitale, A., Caballero, J., & Bilge, L. (2023). Decoding the secrets of machine learning in malware classification: A deep dive into datasets, feature extraction, and model performance. arXiv preprint arXiv:2305.11021.
Demetrio, L., Biggio, B., Lagorio, G., & Roli, F. (2021). Explaining vulnerabilities of deep learning to adversarial malware evasion. IEEE Transactions on Dependable and Secure Computing, 19(4), 2210–2222.
Gaber, M., Ahmed, M., & Janicke, H. (2022). Malware detection with artificial intelligence: A systematic literature review. ACM Computing Surveys, 55(7), 1–37.
Kang, B., McLaughlin, N., Martinez-Perez, C., & Yerima, S. (2019). N-Gram CNN for Android malware classification. arXiv preprint arXiv:1903.01234.
Kinder, J., & Veith, H. (2023). Malware behavior modelling with graph neural networks. In Proceedings of the IEEE Security and Privacy Workshops (SPW) (pp. 112–125). IEEE.
Kolosnjaji, B., Zarras, A., Webster, G., & Eckert, C. (2016). Deep learning for classification of malware system call sequences. In Research in Attacks, Intrusions, and Defenses (pp. 137–156). Springer.
Lee, S., & Yoon, S. (2020). Malimg dataset: Malware visual representation for deep learning-based detection. IEEE Access, 8, 124500–124512.
Maulana, R., Stiawan, D., & Budiarto, R. (2023). Detection of Android malware with deep learning method using convolutional neural network model. Computer Science and Information Technology, 4(2), 88–97.
Pascanu, R., Stokes, J. W., Sanossian, H., Marinescu, M., & Thomas, A. (2016). Malware classification with recurrent networks. In ICLR Workshop Proceedings.
Raff, E., Barker, J., Sylvester, J., Brandon, R., Catanzaro, B., & Nicholas, C. (2017). Malware detection by eating a whole EXE. arXiv preprint arXiv:1710.09435.
Rathore, H., et al. (2021). A comprehensive survey on machine learning techniques for malware detection. arXiv preprint arXiv:2104.03211.
Rusak, G., Chen, C., & Stokes, J. W. (2020). Adversarial example detection in malware classification using statistical behavior modeling. In Proceedings of the 36th Annual Computer Security Applications Conference (ACSAC) (pp. 410–422).
Saxe, J., & Berlin, K. (2015). Deep neural network based malware detection using two-dimensional binary program features. In Proceedings of the 10th USENIX Workshop on Offensive Technologies (WOOT).
Shaheen, N., Lohana, S., & Ramzan, M. (2025). Intelligent malware detection using neural architectures: A comparative study of CNN, LSTM, FNN and Bi-LSTM. Spectrum of Engineering Sciences, 3(4), 582–596.
Sharmeen, S., Weng, S. H., et al. (2020). Android malware detection: A survey on machine learning and deep learning approaches. IEEE Access, 8, 167821–167841.
Shaukat, K., et al. (2020). A review of artificial intelligence techniques for malware detection. Future Internet, 12(11), 184.
Xu, W., Qi, Y., & Evans, D. (2016). Automatically thwarting unknown malware by sequence learning. arXiv preprint arXiv:1605.04321.
Yerima, S., & Sezer, S. (2013). A novel Android malware detection approach using Bayesian classification. In IEEE 27th International Conference on Advanced Information Networking and Applications (AINA) (pp. 1201–1208). IEEE.
Yuan, X., He, P., Zhu, Q., & Li, X. (2019). Adversarial examples: Attacks and defenses for deep learning. IEEE Transactions on Neural Networks and Learning Systems, 30(9), 2805–2824.