This invention discloses an imbalanced
malware detection enhancement method based on the fusion of CWGAN-GP data augmentation and TEXTCNN–
TRANSFORMER, comprising the following steps: S1,
data acquisition and preprocessing: running an
executable file in a controlled sandbox environment to dynamically capture its API call sequence, standardizing the API call sequence, and mapping it into a dense vector sequence; S2, data augmentation based on Conditional Wasserstein
Generative Adversarial Network (CWGAN-GP) with gradient penalty mechanism: constructing a CWGAN-GP model conditioned on the category labels of minority
malware classes, the model including a conditional generator G and a
discriminator D with gradient penalty; inputting the minority
malware samples obtained in step S1 and their corresponding category labels into the CWGAN-GP model for adversarial training until the model converges. The advantages of this invention are: high-
quality data augmentation with semantic fidelity; comprehensive and complementary
feature extraction; significant end-to-end
performance improvement, especially in
minority class identification; and strong model robustness and generalization ability.