<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>JavaScript Programs Obfuscation Detection Method that Uses Artificial Neural Network with Attention Mechanism</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Grigory Ponomarenko</string-name>
          <email>gs.ponomarenko@yandex.ru</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Petr Klyucharev</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Information Security Department Bauman Moscow State Technical University Moscow</institution>
          ,
          <country country="RU">Russia</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2019</year>
      </pub-date>
      <fpage>100</fpage>
      <lpage>104</lpage>
      <abstract>
        <p>-In this paper, we consider JavaScript code obfuscation detection using artificial neural network with attention mechanism as classifier algorithm. Obfuscation is widely used by malware writers that want to obscure malicious intentions, e.g. exploit kits, and also it is a common component of intellectual property protection systems. Non-obfuscated JavaScript code samples were obtained from software repository service Github.com. Obfuscated JavaScript code samples were created by obfuscators found on the same service. Before being fed to the network, each JavaScript program is converted to the general path-based representation, i.e. each program is described by the set of paths in an abstract syntax tree. Model proposed in this paper is a feedforward artificial neural network with attention mechanism. We aimed to build a model that relies on AST paths structures instead of statistical features. According to results of experiments, evaluated model potentially can be implemented with some improvements in malicious code detection systems, browser or mobile device fingerprint collection systems etc.</p>
      </abstract>
      <kwd-group>
        <kwd>obfuscation classification</kwd>
        <kwd>obfuscated code</kwd>
        <kwd>obfuscation recognition</kwd>
        <kwd>Javascript obfuscation</kwd>
        <kwd>general pathbased representation</kwd>
        <kwd>ECMAScripit obfuscation</kwd>
        <kwd>AST-based pattern recognition</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>
        According to Varnovsky et al. statements [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ], obfuscation
was firstly implicitly mentioned in 1976 in the famous Diffie
and Hellman paper [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], in which they introduced asymmetric
cryptography concept. Diffie and Hellman suggested inserting
a secret key into the encryption program, and then this secret
key initialized encryption program becomes tricky converted
so that the secret key extraction would be a very difficult task.
The concept of obfuscation was explicitly introduced in 1997
in the Kollberg, Tomborson and Lowe paper [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
      </p>
      <p>
        By Han Liu et al. obfuscation is defined as special program
transformation whose purpose is to obscure source code or
binary code in order to hide implemented algorithms and data
structures from being recovered [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]. Obfuscated program is
obtained from original after applying obfuscation, and
therefore original program is called non-obfuscated [
        <xref ref-type="bibr" rid="ref5">5, 6</xref>
        ].
      </p>
      <p>
        Schrittwieser et al. remark, that at the beginning of the
computer era obfuscation was commonly used, in particular, to
surprise users by displaying unexpected messages, but today
obfuscation is mostly used to protect intellectual property or
obscure malicious intentions [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Boaz Barak notices, that
obfuscation doesn't make protected program invincible, and
obfuscated program should be protected from reverse
engineering as much as an encryption system shouldn't be
broken using any sensible amount of time and computation
resources [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ].
      </p>
      <p>II.</p>
    </sec>
    <sec id="sec-2">
      <title>PROBLEM DEFINITION</title>
      <p>
        Obfuscated and non-obfuscated programs distinguishing
problem is indelibly linked to the source code properties
prediction and various programs classification types. To
formalize the problem, we will use the definitions introduced
by Silveo Cesar and Yang Xiang in the first chapter of their
book "Classification and similarity of programs" [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ].
      </p>
      <p>Let r be a property for program p if for all possible
execution flaws r is true. A program q is called an obfuscated
copy of a program p if q is the result of transformations that
preserve the semantics (meaning) of algorithms and data
structures. Programs p and q are similar if they are based on the
same program.</p>
      <p>Let P be the set of source codes of programs, f1,..., fk are
functions that allocate features from program, i.e. fi: P → Di,
where Di is the i-th set of features. Let {p1, ... , pn} ⊂ P be the
training sample, {0,1} = Y - class labels (1 is assigned to
obfuscated programs, 0 is assigned to non-obfuscated). It is
necessary to find the map s: D1×...×Dk → {0,1} using training
sample {p1, ... , pn} that classifies all elements of P with the
smallest error function value.</p>
      <p>III.</p>
    </sec>
    <sec id="sec-3">
      <title>DATASET PREPARATION</title>
      <p>To create a dataset with obfuscated and non-obfuscated
Javascript code samples we used software repository
github.com. Github.com is one of the largest service platforms
that features software projects hosting and collaborative
development. There were downloaded 100 most popular
JavaScript projects. To get a list of the most popular projects,
we used a special search API (referenced as Github Search
API) provided by the service. Further all projects from the
resulting list were cloned to the local machine. Downloading
was done on March 22th, 2019 and all downloaded projects
took up 7.3 Gb of the disk space. 49612 files with the ".js"
extension (excluding files with the ".min.js" extension) were
retrieved from the obtained data. In order to simplify the
further creation of obfuscated code samples, it was decided to
retrieve functions from scripts. An example of a simple
JavaScript function is shown in fig. 1.</p>
      <p>
        Node.js script that retrieves functions from a Javascript
program was written using the Esprima library. With this
library abstract syntax tree (AST) can be formed for any
Javascript program that complies with the ECMAScript 2016
standard. An abstract syntax tree for a script is formed
according to the syntactic rules of the programming language.
You can apply the inverse transformation and generate the
correct program code from the tree. Unlike to plain source
code, ASTs do not include punctuation, delimiters, comments
and some other details, but they can be used to describe the
syntactic structure of the script along with lexical information
[
        <xref ref-type="bibr" rid="ref10">10</xref>
        ]. Abstract syntax tree example based on the simple
JavaScript program (fig. 1) is shown in fig. 2.
      </p>
      <p>There were built ASTs for all previously downloaded
scripts with the extension ".js" (49612 samples) using the
parseModule method provided by the Esprima API. Program
code for each element of the "FunctionDeclaration" was saved
into separate files during the tree traversal. Hereby 126276 files
were produced, each file contained a JavaScript function, all
files took up 527 Mb of the disk space.</p>
      <p>To generate obfuscated code samples, we used special
programs that implement JavaScript code obfuscation. On the
mentioned above github.com software repository hosting we
found 6 obfuscators that fit our needs. They are listed below:
• javascript-obfuscator/javascript-obfuscator
• zswang/jfogs
• anseki/gnirts
•</p>
      <p>mishoo/UglifyJS2
• alexhorn/defendjs
•</p>
      <p>wearefractal/node-obf
Obfuscators can work in different ways. Some obfuscators do
not significantly change the syntactic structure of the program,
e.g. jfogs and UglifyJS2, and mostly rename some identifier
and shuffle independent parts. Other obfuscators, such as gnirts
or defendjs, completely change the syntactic structure of the
scripts.</p>
      <p>
        PigeonJS library was used to extract features from the
JavaScript programs source codes [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]. It provides an API to
get a list of given length paths on the AST.
      </p>
      <p>
        One path on the AST formed by PingeonJS has following
structure called general path-based representation [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ]:
(1)
      </p>
      <p>The vertices are separated by v and ^ depending on whether
the left vertex is higher or lower on the tree in comparison with
right one. One of the paths retrieved from the basic JavaScript
program example (fig. 1) is shown in fig. 3.</p>
      <p>Not all scripts have been obfuscated with all of obfuscators
listed before and contexts were retrieved not from all programs.
Main purpose for this was that some of the downloaded
JavaScript files contained programs that have nonstandard
features and extensions. Besides, some obfuscated scripts took
up to 1Gb file storage space although original scripts had size
up to 200-300 Kb. We decided to take such samples away from
the dataset.</p>
      <p>IV.</p>
      <p>NEURAL NETWORK ARCHITECTURE</p>
      <p>
        The architecture of an artificial neural network was used in
this study is based on the network, proposed by Uri Alon et al.
in their paper "code2vec: Learning Distributed Representations
of Code" [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. Researchers attempted to create an artificial
neural network that predicts method names for programs
written in Java. They got excellent results: at the time of the
article publication, they had the best percentage of correctly
named methods among all known studies — about 60%. So we
decided to adapt that network for JavaScript code obfuscation
recognition problem solving.
      </p>
      <p>Main objects the network is working on are script contexts.
The context si = (xs, p, xt) is a tuple containing three elements:
the start vertex, the path, and the terminal vertex. Start vertex xs
and terminal vertex xt are elements of the start and terminal
vertices set T. Path p is an element of the paths set P. Every
JavaScript program (it does not matter, is it obfuscated or
nonobfuscated) is described with a set of contexts:</p>
      <p>Each element x of the vertices set T has its own vector
representation vx in VectT (128-dimensional rational vector).
Similarly, each element p of the paths set P has its own vector
representation vp in VectP (128-dimensional rational vector). In
that way each context has 384-dimensional vector
representation that looks like this:</p>
      <p>Then each script is described by a tuple of contexts vector
representations:</p>
      <p>Maximum number of contexts per script was 200. If there
were less then 200 contexts for some script then contexts tuple
was padded with zero-filled contexts:
Artificial neural network architecture used in this research
is shown in fig. 4. First of all, there is fully connected layer to
which Dropout regularization method was applied. Thanks to
this 75% randomly chosen neurons are ignored (not considered
during forward pass) on each epoch. This helps to prevent
over-fitting of training data and increases model performance
on non-observed samples.</p>
      <p>Fully connected layer have tanh activation function:
where</p>
      <p>is a context vector representation,
is a combined context vector representation
(2)
(3)
(4)
(5)
(6)</p>
      <p>is a fully connected layer weights matrix.</p>
      <p>Based on the combined contexts {d1, ... , d200} and the
attention vector α, the attention weights αi are calculated for
each di. Vector α is initialized with random variables and
updated during the training.</p>
      <p>Obviously, the sum of all αi equals 1. After that a code
vector v is calculated using the attention weights αi as follows:</p>
      <p>Since all attention weights αi are nonnegative, and their
sum equals to 1, we can consider the calculation of the code
vector as the calculation of the weighted average over all
combined contexts di.</p>
      <p>
        The idea behind the attention mechanism can be described
as choosing the most interesting part of the resulting set. The
softmax transformation (7) is a key component of several
statistical learning models but recently it has also been used to
design attention mechanisms in neural networks [
        <xref ref-type="bibr" rid="ref13">13</xref>
        ]. Attention
mechanisms are used to solve various applied problems with
the help of artificial neural networks, e.g. multilingual
translation [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ], sentiment classification [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ], time-series
classification [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ], vehicle images classification [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ] or speech
recognition [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ].
      </p>
      <p>At the last step the final solution is calculated using
128dimensional real vectors yobf and ynotobf: obfuscated or
nonobfuscated script was passed to the network input. Vectors yobf
and ynotobf are initialized randomly and updated during model
training. JavaScript program obfuscation probability q(v) is
calculated based on code vector (7):
(7)
(8)
If q(v) &gt; 0.5 then script is thought to be obfuscated. Script
non-obfuscation probability is estimated as 1−q(v) respectively.
For one script, the loss function (cross-entropy function) is
computed as follows:
where p(v) = 1 for obfuscated scripts and p(v) = 0 for
nonobfuscated scripts. To minimize the loss function, the method
of adaptive moment estimation (Adam) was used as an
optimization algorithm.</p>
      <p>MODEL TRAINIG AND EVALUATION</p>
      <p>Model training and evaluation were proceeded on the
workstation with the following equipment: Intel Core i7-7700
processor (3.6 GHz) with 8 cores, 16 GB of RAM, NVIDIA
GeForce GTX 1080 GPU. The training dataset was formed as
follows: 115504 context samples describing non-obfuscated
functions and 117990 context samples describing obfuscated
functions, among them 36000 randomly chosen from all
samples obfuscated with "javascript-obfuscator" , 36000
randomly chosen from all samples obfuscated with "jfogs",
36000 randomly chosen from all samples obfuscated with
"UglifyJS2" and 9990 – from samples obfuscated with
"defendjs". There were 233494 context samples in sum.</p>
      <p>A set Tp (|Tp|=776830) of the most popular names of start
and final context vertices and a set Pp (|Pp|=1008102) were
obtained from the training sample so that for each script s at
least one context c contains two elements from T and one
element from P.</p>
      <p>Testing dataset contained 8444 contexts describing
obfuscated functions (7655 samples obfuscated with "gnirts"
and 789 samples obfuscated with "jfogs") and 8444 contexts
describing non-obfuscated functions.</p>
      <p>We decided to use precision (10), recall (11) and F1-score
(12) as model evaluation metrics explaining model
performance.</p>
      <p>Model training was 9 epochs long. Precision, recall and
F1score obtained after model training completion are shown in
Table 1.
(9)
(10)
(11)
(12)
(13)</p>
      <p>Metric
Precision
Recall
F1</p>
      <p>
        Our model showed less well performance than the model
proposed by Tellenbach et. al. Their model used features
reflecting the frequencies of JavaScript keywords and other
statistical statistical calculations and had following evaluations:
precision – 95%, recall – 90%, F1-score – 92% [
        <xref ref-type="bibr" rid="ref19">19</xref>
        ].
      </p>
      <p>At the same time the presented model has sufficient
improvement potential gives rise to further research of
obfuscation detection models that do not rely on pre-calculated
statistical features. First of all, second fully connected layer and
activation function replacement with different one could
positively impact model quality scores.</p>
      <p>
        Beyond that, code vector v (7) can be passed to additional
classifier input, e.g. SVM-based or Random Forest based. A
similar approach Ndichu et al. proposed to solve the JavaScript
malware detection problem using feedforward neural network
[
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. They divided model training process into two stages: on
the first one they trained neural network classifier based on
Doc2vec and on the second one they passed fully connected
layer output to the SMV. As a result, SVM was trained on the
code embeddings [
        <xref ref-type="bibr" rid="ref20">20</xref>
        ]. Their model that combines Doc2vec
and SMV had following evaluation results: precision – 94%,
recall – 92% and F1-score - 93% on the obfuscated samples.
      </p>
      <p>VI.</p>
    </sec>
    <sec id="sec-4">
      <title>CONCLUSION</title>
      <p>In this paper we explored JavaScript (ECMAScript 2016)
code obfuscation detection method that uses artificial neural
network with attention mechanism as classifier algorithm.</p>
      <p>First of all, a set of samples of obfuscated and
nonobfuscated code was obtained using projects and repositories
hosted on github.com. Secondly, an artificial neural network
model with an attention mechanism was adapted to solve the
problem of scripts classification on the obfuscation basis.
Thirdly, non-obfuscated dataset could be checked for the
presence of obfuscated samples uploaded to github.com
repository, downloaded during the dataset preparation stage
and erroneously labeled as non-obfuscated.</p>
      <p>The characteristics of the obtained model show that the
considered method potentially can be implemented with some
improvements in malicious code detection systems, browser or
mobile device fingerprint collection systems or other software
that use obfuscation recognition.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>N.P.</given-names>
            <surname>Varnovsky</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.A.</given-names>
            <surname>Zakharov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.N.</given-names>
            <surname>Kuzurin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.A.</given-names>
            <surname>Shokurov</surname>
          </string-name>
          .
          <article-title>The current state of art in program obfuscations:definitions of obfuscation security</article-title>
          .
          <source>Proceedings of the Institute for System Programming</source>
          , vol.
          <volume>26</volume>
          , issue 3,
          <year>2014</year>
          , pp.
          <fpage>167</fpage>
          -
          <lpage>198</lpage>
          . DOI:
          <volume>10</volume>
          .15514/ISPRAS-2014-
          <volume>26</volume>
          (
          <issue>3</issue>
          )-
          <fpage>9</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <surname>Diffie</surname>
            <given-names>W.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hellman</surname>
            <given-names>M</given-names>
          </string-name>
          . New directions in cryptography // IEEE Transactions on Information Theory, IT-
          <volume>22</volume>
          (
          <issue>6</issue>
          ),
          <year>1976</year>
          , p.
          <fpage>644</fpage>
          -
          <lpage>654</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <surname>Collberg</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Thomborson</surname>
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Low D</surname>
          </string-name>
          . A Taxonomy of Obfuscating Transformations //
          <source>Technical Report, N 148, Univ. of Auckland</source>
          ,
          <year>1997</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <surname>Liu</surname>
            ,
            <given-names>H.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Sun</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Su</surname>
            ,
            <given-names>Z.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Jiang</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gu</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Sun</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <year>2017</year>
          , May.
          <article-title>Stochastic optimization of program obfuscation</article-title>
          .
          <source>In 2017 IEEE/ACM 39th International Conference on Software Engineering (ICSE)</source>
          (pp.
          <fpage>221</fpage>
          -
          <lpage>231</lpage>
          ). IEEE.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <surname>Kozachok</surname>
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bochkov</surname>
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tuan L.M. Indistinguishable Obfuscation Security Theoretical Proof</surname>
          </string-name>
          .
          <source>Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          ,
          <source>2016. N</source>
          <volume>1</volume>
          (
          <issue>14</issue>
          ). P.
          <volume>36</volume>
          -
          <fpage>46</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <given-names>Markin D.</given-names>
            ,
            <surname>Makeev</surname>
          </string-name>
          <string-name>
            <surname>S</surname>
          </string-name>
          .
          <source>Protection System of Terminal Programs Against Analysis Based on Code Virtualization. Voprosy kiberbezopasnosti [Cybersecurity issues]</source>
          ,
          <year>2020</year>
          , N
          <volume>1</volume>
          (
          <issue>35</issue>
          ), pp.
          <fpage>29</fpage>
          -
          <lpage>41</lpage>
          . DOI:
          <volume>10</volume>
          .21681/
          <fpage>2311</fpage>
          - 3456-2020-01-29-41.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <surname>Schrittwieser</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Katzenbeisser</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kinder</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Merzdovnik</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Weippl</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <source>Protecting Software through Obfuscation. ACM Computing Surveys</source>
          ,
          <volume>49</volume>
          (
          <issue>1</issue>
          ),
          <fpage>1</fpage>
          -
          <lpage>37</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <surname>Barak</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          (
          <year>2016</year>
          ).
          <article-title>Hopes, fears, and software obfuscation</article-title>
          .
          <source>Commun. ACM</source>
          ,
          <volume>59</volume>
          (
          <issue>3</issue>
          ),
          <fpage>88</fpage>
          -
          <lpage>96</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <surname>Silvio</surname>
            <given-names>Cesare</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Yang</given-names>
            <surname>Xiang</surname>
          </string-name>
          .
          <source>Software Similarity and Classification</source>
          . Springer-Verlag,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <surname>Zhang</surname>
            , Jian,
            <given-names>Xu</given-names>
          </string-name>
          <string-name>
            <surname>Wang</surname>
            , Hongyu Zhang, Hailong Sun,
            <given-names>Kaixuan</given-names>
          </string-name>
          <string-name>
            <surname>Wang</surname>
            , and
            <given-names>Xudong</given-names>
          </string-name>
          <string-name>
            <surname>Liu</surname>
          </string-name>
          .
          <article-title>"A novel neural source code representation based on abstract syntax tree."</article-title>
          <source>In Proceedings of the 41st International Conference on Software Engineering</source>
          , pp.
          <fpage>783</fpage>
          -
          <lpage>794</lpage>
          . IEEE Press,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <surname>Alon</surname>
            , Uri, Meital Zilberstein,
            <given-names>Omer Levy</given-names>
          </string-name>
          ,
          <string-name>
            <given-names>Eran</given-names>
            <surname>Yahav</surname>
          </string-name>
          .
          <article-title>A general pathbased representation for predicting program properties</article-title>
          .
          <source>ACM SIGPLAN Notices</source>
          , vol.
          <volume>53</volume>
          , no.
          <issue>4</issue>
          , pp.
          <fpage>404</fpage>
          -
          <lpage>419</lpage>
          . ACM,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <surname>Uri</surname>
            <given-names>Alon</given-names>
          </string-name>
          , Meital Zilberstein,
          <string-name>
            <surname>Omer Levy</surname>
          </string-name>
          , Eran Yahav.
          <article-title>Сode2vec: Learning Distributed Representationsof Code</article-title>
          .
          <source>Proc. ACM Program. Lang.3</source>
          ,
          <string-name>
            <surname>POPL</surname>
          </string-name>
          ,
          <year>2019</year>
          , 40, P.
          <fpage>1</fpage>
          -
          <lpage>29</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <surname>Martins</surname>
            , Andre, and
            <given-names>Ramon</given-names>
          </string-name>
          <string-name>
            <surname>Astudillo</surname>
          </string-name>
          .
          <article-title>"From softmax to sparsemax: A sparse model of attention and multi-label classification."</article-title>
          <source>In International Conference on Machine Learning</source>
          , pp.
          <fpage>1614</fpage>
          -
          <lpage>1623</lpage>
          .
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <surname>Firat</surname>
            , Orhan,
            <given-names>Kyunghyun</given-names>
          </string-name>
          <string-name>
            <surname>Cho</surname>
            , and
            <given-names>Yoshua</given-names>
          </string-name>
          <string-name>
            <surname>Bengio</surname>
          </string-name>
          .
          <article-title>"Multi-way, multilingual neural machine translation with a shared attention mechanism." In 15th Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies</article-title>
          ,
          <source>NAACL HLT</source>
          <year>2016</year>
          , pp.
          <fpage>866</fpage>
          -
          <lpage>875</lpage>
          .
          <article-title>Association for Computational Linguistics (ACL</article-title>
          ),
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>Wang</surname>
            , Yequan,
            <given-names>Minlie</given-names>
          </string-name>
          <string-name>
            <surname>Huang</surname>
            ,
            <given-names>and Li</given-names>
          </string-name>
          <string-name>
            <surname>Zhao</surname>
          </string-name>
          .
          <article-title>"Attention-based LSTM for aspect-level sentiment classification."</article-title>
          <source>In Proceedings of the 2016 conference on empirical methods in natural language processing</source>
          , pp.
          <fpage>606</fpage>
          -
          <lpage>615</lpage>
          .
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <surname>Du</surname>
          </string-name>
          , Qianjin, Weixi Gu, Lin Zhang, and
          <string-name>
            <surname>Shao-Lun Huang</surname>
          </string-name>
          .
          <article-title>"Attentionbased LSTM-CNNs For Time-series Classification."</article-title>
          <source>In Proceedings of the 16th ACM Conference on Embedded Networked Sensor Systems</source>
          , pp.
          <fpage>410</fpage>
          -
          <lpage>411</lpage>
          . ACM,
          <year>2018</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <surname>Zhao</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chen</surname>
            ,
            <given-names>Y.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Lv</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          (
          <year>2017</year>
          ).
          <article-title>Deep Reinforcement Learning With Visual Attention for Vehicle Classification</article-title>
          .
          <source>IEEE Transactions on Cognitive and Developmental Systems</source>
          ,
          <volume>9</volume>
          (
          <issue>4</issue>
          ),
          <fpage>356</fpage>
          -
          <lpage>367</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <surname>Kim</surname>
            , Suyoun,
            <given-names>Takaaki</given-names>
          </string-name>
          <string-name>
            <surname>Hori</surname>
            , and
            <given-names>Shinji</given-names>
          </string-name>
          <string-name>
            <surname>Watanabe</surname>
          </string-name>
          .
          <article-title>"Joint CTC-attention based end-to-end speech recognition using multi-task learning."</article-title>
          <source>In 2017 IEEE international conference on acoustics, speech and signal processing (ICASSP)</source>
          , pp.
          <fpage>4835</fpage>
          -
          <lpage>4839</lpage>
          . IEEE,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [19]
          <string-name>
            <surname>Tellenbach</surname>
            <given-names>B</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Paganoni</surname>
            <given-names>S</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Rennhard</surname>
            <given-names>M.</given-names>
          </string-name>
          <article-title>Detecting obfuscated JavaScripts from known and unknown obfuscators using machine learning</article-title>
          .
          <source>International Journal on Advances in Security</source>
          .
          <year>2016</year>
          ;
          <volume>9</volume>
          (
          <issue>3</issue>
          /4):
          <fpage>196</fpage>
          -
          <lpage>206</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [20]
          <string-name>
            <surname>Ndichu</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kim</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ozawa</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Misu</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          and
          <string-name>
            <surname>Makishima</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ,
          <year>2019</year>
          .
          <article-title>A machine learning approach to detection of JavaScript-based attacks using AST features and paragraph vectors</article-title>
          .
          <source>Applied Soft Computing</source>
          ,
          <volume>84</volume>
          , p.
          <fpage>105721</fpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>