Building defense against adaptive computer viruses

Patricia Raffaele

Aug 18, 2026

The COVID-19 pandemic changed the way that many people approached their work across the globe. For Carnegie Mellon University Africa's Jema Ndibwile, it changed the way he viewed a whole different type of virus: a computer virus.

The COVID-19 pandemic highlighted how rapidly biological systems can evolve and adapt. “Similarly, I was thinking, is it not possible that malware and other cyber threats also will do the same thing — keep evolving over time and challenge existing detection systems?” reflected Ndibwile, assistant teaching professor in cybersecurity.

Ndibwile shared this musing with his research team, including CMU-Africa research engineer and alumna Alvina Rwaichi Minja (MSIT ’26). They then co-wrote the paper Evaluation Endpoint Robustness Against Genetic Algorithm Driven Code Transformation, which was recently published by the IEEE International Conference on Cryptography, Security and Privacy.

Zoom meeting screen showing a shared presentation slide titled "Behavioral Parameters" and "Static Transformation Operators" alongside a speaker’s webcam video with an ICMIP/CSP 2026 backdrop.

Source: Alvina Minja

Minja was awarded a certificate for best presentation at an IEEE conference held in Sapporo, Japan in April. She made the presentation virtually because she was an exchange student in Pittsburgh at the time.

Minja presented this research virtually at the conference, which was held in Sapporo, Japan from April 25 to April 27, 2026. She was awarded a certificate of appreciation for Best Presentation on the topic AI Driven Cybersecurity Defense and Computational Cryptography Methods.

“This was the first time I presented a paper at a conference,” she said. “I presented the paper virtually because, at the time, I was an exchange student at CMU in Pittsburgh.”

The initial research focused on reverse shell code, a type of cybersecurity test artifact commonly used in controlled research environments to represent post-compromise remote command execution. “It is used by attackers because it easily bypasses firewalls,” Minja said.

“A reverse shell can be used to establish remote command execution capabilities after a connection is initiated from a target system. Researchers often use reverse shells in controlled laboratory environments to study how security monitoring and detection systems respond to post-compromise activity,” she said.

“The purpose of our research was not to develop offensive tools, but to understand how well modern cybersecurity defenses respond to automatically generated, functionally equivalent software variants," Ndibwile said.

“We sent samples to see how many of the reverse codes (malware called reverse shells) would be detected and observed with measurable differences in detection outcomes under the controlled laboratory conditions used in the study.” Minja said. “We used Python programming language and reverse shells, which are a small portion of the world of malware,” Ndibwile said.

The team expanded the research to six execution categories spanning multiple programming languages and computing environments.

“In the second phase of the research we expanded to using more and other types of malware. For example, we used keyloggers, which, in controlled cybersecurity research environments, can be used to evaluate how defensive systems respond to monitoring and surveillance-related behaviors,” Ndibwile said.

This research resulted in a second paper, TransForge: A Genetic Algorithm Framework for Cross-Category Evaluation of Endpoint Detection Robustness to Code Transformations, published online in Future Internet. Building on the success of the first two studies, the research has now entered its third phase following the award of a $100,000 research grant from Microsoft Corporation.

The initiative brings together Minja, Landon Ntung Ngela (MSIT ’26), Floride Tuyisenge (MSIT ‘26), and a broader team of research associates to develop a large-scale dataset of approximately 10,000 software variants for cybersecurity robustness, benchmarking, and endpoint detection research.

Working with Professor Jema was a privilege. I’m proud of the work I did.

Alvina Rwaichi Minja (MSIT ’26), Research engineer, CMU-Africa

“Working with Professor Jema was a privilege," Minja said. “I’m proud of the work I did; it was challenging to do all of the work in two semesters.”

Ndibwile noted, “Minja executed the research to perfection.”

Minja is continuing to work on the third phase of the research and plans to apply to Ph.D. programs next year, continuing her work in cybersecurity and staying in academia because she says, “teaching is my biggest dream."