Website of D. Serikbayev EKTU
  • Font Size
    16px
    Website Colors
    Images

APPLICATION OF EXPLAINABLE AI METHODS TO IMPROVE THE INTERPRETABILITY OF MALWARE DETECTION SYSTEMS

Authors

Name Affiliation
Ruslan Edeev Евразийский национальный университет им. Л.Н. Гумиева

Downloads

Published:

2026-07-08

Article language:

English

Views:

15

Downloads:

12

Keywords:

Explainable AI, Malware Detection, SHAP, LightGBM, Model Interpretability, cybersecurity

Abstract

Machine learning–based malware detection systems achieve high accuracy but often lack transparency, limiting their trustworthiness in cybersecurity operations. This study presents an interpretable malware detection framework that integrates a LightGBM classifier trained on the EMBER dataset with SHAP-based Explainable AI (XAI) techniques. Unlike prior works that apply explainability only post hoc, our framework embeds interpretability directly into the model pipeline without compromising predictive performance. The model achieved 97.35% accuracy and a ROC-AUC of 0.9963, confirming its high discriminative capability. SHAP analysis identified key influential features such as file entropy, import table size, and suspicious API usage, improving transparency in automated malware analysis and supporting more reliable decision-making in cybersecurity environments.

Edeev, R. (2026). APPLICATION OF EXPLAINABLE AI METHODS TO IMPROVE THE INTERPRETABILITY OF MALWARE DETECTION SYSTEMS. EKTU Journal of Information Security and Cryptography, 1(1). Retrieved from https://journals.ektu.kz/jisc/article/view/1893