WHPar: a novel API parameter handling method for malware detection

Hui Li & Anyang Yin

Computer Journal2026https://doi.org/10.1093/comjnl/bxag031article
AJG 2
Weight
0.50

What the paper says

In dynamic malware detection, analyzing application programming interface (API) parameters is proven to effectively complement the security information provided by APIs. Previous research on API parameters has focused on the security behavior of APIs and their parameters, while overlooking the behavioral correlation among parameters. This oversight results in limited generalizability of detection models and diminished accuracy. In this study, we present WHPar, a novel deep neural network-based malware detection approach for analyzing API parameters to identify behavioral relationships among them. It first employs the Word2Vec method to capture context-containing Information on security behavior from the API and its parameters, respectively. Then, it employs discrete cosine transform from the perceptual hash algorithm to transform the contextual information and perform embedding, for a sequence containing more comprehensive behavioral information derived from the API parameters. Finally, it feeds the sequences into the bidirectional long short-term memory model for training a binary classifier to detect malware. Experimental results demonstrate that WHPar significantly outperforms baseline methods. Moreover, when malicious samples are less prevalent than benign samples, WHPar yields superior detection results compared with other established methods in this field.

Open paper page →

Cite this paper

https://doi.org/https://doi.org/10.1093/comjnl/bxag031

Or copy a formatted citation

@article{hui2026,
  title        = {{WHPar: a novel API parameter handling method for malware detection}},
  author       = {Hui Li & Anyang Yin},
  journal      = {Computer Journal},
  year         = {2026},
  doi          = {https://doi.org/https://doi.org/10.1093/comjnl/bxag031},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

WHPar: a novel API parameter handling method for malware detection

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.