{
  "schema_version": "0.6.0",
  "paper_id": "emd-scs-malware-detection-sonification-system-calls",
  "page_url": "https://threadslab.org/research-publications/papers/emd-scs-malware-detection-sonification-system-calls/",
  "title": "EMD-SCS: A Dynamic Behavioral Approach for Early Malware Detection with Sonification of System Call Sequences",
  "title_variants": [],
  "authors": [
    "Raghav Bhardwaj",
    "Morteza Noferesti",
    "Madeline Janecek",
    "Naser Ezzati-Jivan"
  ],
  "author_details": [
    {
      "name": "Raghav Bhardwaj",
      "orcid": null,
      "profile_url": "https://dblp.org/pid/376/9675.html"
    },
    {
      "name": "Morteza Noferesti",
      "orcid": "https://orcid.org/0009-0000-5507-1461",
      "profile_url": "https://dblp.org/pid/82/10462.html"
    },
    {
      "name": "Madeline Janecek",
      "orcid": null,
      "profile_url": "https://dblp.org/pid/307/5913.html"
    },
    {
      "name": "Naser Ezzati-Jivan",
      "orcid": "https://orcid.org/0000-0003-1435-6297",
      "profile_url": "https://threadslab.org/"
    }
  ],
  "publication": {
    "year": 2023,
    "venue": "2023 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)",
    "type": "conference paper",
    "publication_date": "2023-11-01",
    "online_date": null,
    "print_date": "2023-11-01",
    "volume": null,
    "issue": null,
    "pages": "1728-1737",
    "article_number": null,
    "publisher": "IEEE",
    "issn": [],
    "isbn": [],
    "crossref_type": "proceedings-article"
  },
  "publication_type": "conference paper",
  "status": "published_metadata_record",
  "canonical_source_url": "https://doi.org/10.1109/TRUSTCOM60117.2023.00235",
  "source_record_id": "emd-scs-a-dynamic-behavioral-approach-for-early-malware-detection-with-sonification-of-system-ca-a3cdb10ccc",
  "identifiers": {
    "doi": "10.1109/TRUSTCOM60117.2023.00235"
  },
  "abstract": null,
  "abstract_source": "OpenAlex abstract metadata reviewed; publisher abstract not reproduced because reuse permission was not established.",
  "abstract_available": false,
  "scholar_eligibility": {
    "eligible": false,
    "basis": "not-eligible",
    "note": "The page is a discovery record; it does not claim Google Scholar article-host eligibility."
  },
  "description": "EMD-SCS combines sequence prediction of system calls with sonification so that partial execution prefixes can support early malware detection and an interpretable auditory alert.",
  "evidence_level": "full-text-reviewed",
  "evidence": {
    "source_basis": "full-text-reviewed",
    "coverage": "material paper sections",
    "summary_origin": "AI-assisted catalog editorial summary",
    "review_status": "catalog-reviewed; paper-author approval pending",
    "verified_on": "2026-08-26",
    "sources": [
      {
        "note": "Local PDF reviewed, including ADFA-LD preprocessing, LSTM configuration, partial-prefix evaluation, and sonification study"
      },
      {
        "note": "IEEE DOI record: https://doi.org/10.1109/TRUSTCOM60117.2023.00235"
      },
      {
        "note": "IEEE Xplore record: https://ieeexplore.ieee.org/document/10224235/"
      }
    ]
  },
  "summary": {
    "core_contribution": "EMD-SCS combines sequence prediction of system calls with sonification so that partial execution prefixes can support early malware detection and an interpretable auditory alert.",
    "problem": "Malware behavior can vary across executions, and waiting for a complete system-call trace delays detection. A detector must model sequential behavior from a prefix while presenting results in a form that can complement conventional visual monitoring.",
    "method": "The study uses the ADFA-LD Linux dataset, with system-call IDs from the stated 1–340 range, and evaluates prefixes with N=15 and M values 2, 3, 5, and 10. A sequence-to-sequence LSTM with two 256-unit layers, learning rate 0.001, and dropout 0.5 predicts future calls; BLEU and Hamming distance support classification. The output is mapped to natural and animal sounds using ChucK for sonification. Six attack categories are evaluated at partial input ratios.",
    "findings": "The paper reports 95.465% accuracy in its M=2 setting and detection rates of 86.8% and 87.7% at 25% and 40% input, respectively, rising above 90.6% with the full sequence. The false-positive rate decreases from about 15.5% to 14.4% across the reported partial/full comparison. A preliminary user study examines the auditory presentation, but it is not a substitute for operational human-factors validation.",
    "limitations": "ADFA-LD is an older, single-environment dataset, and the sequence split, attack diversity, and baseline comparability constrain generalization. The sonification study is preliminary, and the paper does not establish robustness to modern malware, noisy multi-process hosts, or adversarially manipulated call sequences.",
    "future_work": "Evaluate contemporary and cross-host datasets, calibrate early-warning thresholds, test concept drift and evasion, compare audio alerts with visual and multimodal interfaces, and conduct controlled human-monitoring studies with realistic alert loads."
  },
  "tags": [
    "system-tracing",
    "anomaly-detection",
    "machine-learning",
    "performance-analysis"
  ],
  "keywords": [
    "malware detection",
    "system-call sequences",
    "sonification",
    "Hamming distance",
    "detection rate",
    "false-positive rate",
    "EMD-SCS"
  ],
  "versions": [
    {
      "id": "published-version",
      "label": "Published version",
      "relation": "version-of-record",
      "title": "EMD-SCS: A Dynamic Behavioral Approach for Early Malware Detection with Sonification of System Call Sequences",
      "url": "https://doi.org/10.1109/TRUSTCOM60117.2023.00235",
      "pdf_url": null,
      "status": "published",
      "canonical_for_citation": true
    },
    {
      "id": "dblp-record",
      "label": "DBLP record",
      "relation": "source-record",
      "title": "EMD-SCS: A Dynamic Behavioral Approach for Early Malware Detection with Sonification of System Call Sequences",
      "url": "https://dblp.org/rec/conf/trustcom/BhardwajNJE23",
      "pdf_url": null,
      "status": "public_source_record",
      "canonical_for_citation": false
    }
  ],
  "access": {
    "status": "published_metadata_record",
    "note": "DOI, DBLP, IEEE, and J-GLOBAL metadata verify the record. Indexed terms are not treated as full-text results; the paper remains technically unevidenced.",
    "license": null
  },
  "resources": {
    "code": null,
    "data": null,
    "slides": null,
    "demo": null
  },
  "citation_guidance": {
    "when_to_cite": "Cite this paper when using sequence prediction and sonification for early malware detection from system-call prefixes.",
    "points": [
      "Seq2Seq LSTM prediction of future system calls from partial traces.",
      "BLEU/Hamming-based classification and ChucK auditory mapping.",
      "The ADFA-LD partial-input detection results.",
      "The preliminary human-factors and legacy-dataset limitations."
    ],
    "canonical_version_id": "published-version"
  },
  "provenance": {
    "metadata_verified_on": "2026-08-26",
    "metadata_source": [
      "Local PDF reviewed, including ADFA-LD preprocessing, LSTM configuration, partial-prefix evaluation, and sonification study",
      "IEEE DOI record: https://doi.org/10.1109/TRUSTCOM60117.2023.00235",
      "IEEE Xplore record: https://ieeexplore.ieee.org/document/10224235/"
    ],
    "summary_written_by": "AI-assisted",
    "summary_verified_by": "full-text-grounded catalog review; author approval pending",
    "linked_preprint_record": null,
    "author_order_note": null
  },
  "batch": {
    "phase": 2,
    "batch_label": "expanded forty-paper release",
    "status": "included_in_expanded_catalog",
    "selected_at": "2026-08-28"
  }
}
