Open Access

A Review of Explainable Machine Learning Methods for Malware Detection and Classification

4 Assistant Professor, Department of Computer Sciences and Applications, Mandsaur University, Mandsaur, India

Abstract

Traditional cybersecurity solutions have been greatly challenged by the fast growth of malware, making accurate and interpretable malware detection crucial. In recent years, deep learning (DL) and machine learning (ML) have gained traction as potent methods for identifying malware, both known and undiscovered, polymorphic, and zero-day. These methods learn intricate patterns from both static and dynamic data analysis. Many ML and DL models, however, are opaque and untrustworthy because to their black-box design, which is particularly problematic for applications that rely on security. Malware detection and categorisation using explainable machine learning approaches is thoroughly reviewed in this study. Starting with a general introduction to malware detection and the most frequent kinds of malware, it moves on to cover the three main classical detection approaches: signature-based, behavioral-based, and heuristic-based. Advanced malware detection approaches based on ML and DL are further examined in the paper, which highlights frequently used algorithms, their working principles, and benefits. Along with that, it delves into XAI approaches like LIME, KernelSHAP, and Shapley values, which are model-agnostic, to enhance the interpretability of malware detection models. These techniques use transparent machine learning models and both global and local explanations. Accumulated Local Effects (ALE), Individual Conditional Expectation (ICE), and Partial Dependence Plot (PDP) are among the visual methods of explanation that are covered. The study concludes with a review of the literature, an analysis of the current state of affairs, and a plan for the future of research into the topic of malware detection systems as it pertains to building confidence among users and facilitating educated cybersecurity decisions.

Keywords

References

S. Chatterjee, “Advanced Malware Detection in Operational Technology: Signature-Based Vs. Behaviour-Based Approaches,” ESP J. Eng. Technol. Adv., vol. 1, no. 2, pp. 272–279, 2021, doi: 10.56472/25832646/JETA-V1I2P128.
J. Ferdous, R. Islam, A. Mahboubi, and M. Z. Islam, “A Survey on ML Techniques for Multi-Platform Malware Detection: Securing PC, Mobile Devices, IoT, and Cloud Environments,” 2025. doi: 10.3390/s25041153.
P. H. Desai, P. Mahalle, and P. Chandre, “Intelligent Access Control Schemes for the Internet of Everything: A Survey of Techniques, Challenges, and Future Directions,” 2026, pp. 95–105. doi: 10.1007/978-3-032-13196-6_9.
N. Adik, “The Rise of Open and Free Networks: A Community-Driven Paradigm for Decentralized Connectivity,” in 2025 IEEE First International Conference on Innovations in Engineering and Next-Generation Technologies for Sustainability (ICINVENTS), IEEE, Nov. 2025, pp. 1–9. doi: 10.1109/ICINVENTS64613.2025.11402224.
S. Kakkar, S. Janarthanan, B. Makkena, and A. Kakkar, “Deep Learning Approaches for Predicting Attack Vulnerabilities in Quantum-Secure Financial Networks,” in 2026 International Conference on Emerging Systems and Intelligent Computing (ESIC), IEEE, Feb. 2026, pp. 780–785. doi: 10.1109/ESIC68176.2026.11496277.
Y. Wu, H. Zhuang, Y. Jia, and Y. Zhang, “A Survey of Machine Learning Approaches for Malware Detec-tion,” in Proceedings of 2025 5th International Conference on Computer Network Security and Software Engineering, CNSSE 2025, 2025. doi: 10.1145/3732365.3732410.
A. Joon, B. K. R. Janumpally, A. Gogineni, and P. Chatterjee, “Efficient Large-Scale Intrusion Identification and Prevention in Distributed Cloud Networks Using Artificial Intelligence,” in 2025 5th International Conference on Intelligent Technologies (CONIT), IEEE, Jun. 2025, pp. 1–8. doi: 10.1109/CONIT65521.2025.11167760.
M. Mittal, “The Emergence of Blockchain: Security and Scalability Challenges in Decentralized Ledgers,” Int. J. Multidiscip. Sci. Emerg. Res., vol. 04, no. 01, Jan. 2016, doi: 10.15662/IJMSERH.2016.0401002.
L. A. Yeruva, D. Singh, S. Suddala, N. Bhatt, and R. Uddin, “Augmented Data Management for Cache Performance, Cybersecurity, and Mobile Integration,” J. Comput. Mech. Manag., vol. 5, no. 3, Jun. 2026, doi: 10.57159/jcmm.5.3.26691.
R. N. Rajendran, D. K. Rai, S. K. Anumula, and S. Agrawal, “Zero Trust Security Model Implementation in Microservices Architectures Using Identity Federation,” in 2025 2nd International Conference on Recent Trends in Electrical, Electronics and Computing Technologies (ICRTEECT), IEEE, Oct. 2025, pp. 1–6. doi: 10.1109/ICRTEECT67512.2025.11448625.
S. Jain and D. Jain, “Artifact Comparison Analyzer: Evaluating Microservice Build Metrics for Performance and Efficiency Improvements,” in 2026 IEEE International Conference on AI Engineering and Innovations (AIEI), IEEE, Mar. 2026, pp. 1–6. doi: 10.1109/AIEI69164.2026.11497468.
Y. Muni, “Understanding the Evolution of Internet Protocols: An In-Depth Review of IPV4 and IPV6: A Comparative Review of Transition Challenges and Solutions,” Int. J. Adv. Res. Comput. Sci., vol. 16, no. 4, pp. 109–117, Aug. 2025, doi: 10.26483/ijarcs.v16i4.7307.
S. Pawar, G. Patil, K. Patel, P. Pawar, S. Khedkar, and B. More, “Falsified News Detection Using Deep Learning Approach,” 2021 Asian Conf. Innov. Technol., pp. 1–5, 2021.
J. Landage, “Malware and Malware Detection Techniques: A Survey,” Int. J. Eng. Res. Technol., vol. 2, no. 12, pp. 1–8, 2013, [Online]. Available: https://www.ijert.org/research/malware-and-malware-detection-techniques-a-survey-IJERTV2IS120163.pdf
A. Warrier, “Securing and Scaling API Gateways in Hybrid Environments,” J. Artif. Intell. Mach. Learn. Data Sci., vol. 3, no. 3, pp. 2914–2920, Sep. 2025, doi: 10.51219/JAIMLD/Arjun-warrier/607.
F. A. Aboaoja, A. Zainal, F. A. Ghaleb, B. A. S. Al-rimy, T. A. E. Eisa, and A. A. H. Elnour, “Malware Detection Issues, Challenges, and Future Directions: A Survey,” 2022. doi: 10.3390/app12178482.
Vandana Chaturvedi, “A Review on AI-Driven Project Management for Transforming Software Engineering Perspectives,” Int. J. Adv. Res. Sci. Commun. Technol., vol. 4, no. 2, p. 895, Dec. 2024, doi: 10.48175/IJARSCT-22800E.
K. R. Kiran, “API Integration Barriers in Case-Based Process Management: A Review of Interoperability and Real-Time Response Constraints Outline,” Qual. Res., vol. 25, no. 3, pp. 21–48, 2025, doi: https://doi.org/10.5281/zenodo.16782616.
S. K. Malaraju and S. K. Madishetty, “AI-Augmented Compiler Optimization for Energyefficient Software Execution on Embedded Systems,” in 2025 14th International Conference on System Modeling & Advancement in Research Trends (SMART), IEEE, Nov. 2025, pp. 1–6. doi: 10.1109/SMART66937.2025.11389313.
M. R. C. Mukkolakkal, “Deploy, Calibrate, Monitor, Heal -- No Human Required: An Autonomous AI SRE Agent for Elasticsearch,” arvix.org, Apr. 2026, [Online]. Available: http://arxiv.org/abs/2604.03933
R. Palwe, “SAFIRE: Secure AI Framework for Institutional Readiness & Enablement,” Int. J. Comput. Artif. Intell., vol. 7, no. 4, pp. 136–139, 2026.
S. P.Sivashanmugam, S. Kumara, A. Mohile, and D. R. Suram, “Improving Detection Accuracy of Phishing Attacks with Feature Selection and Machine learning Techniques in Cybersecurity,” in 2026 1st International Conference on Emerging Trends in Advancements and Applications of Computational Intelligence Techniques (ETAACT), Bhubaneswar, India: IEEE, Apr. 2026, pp. 1–6. doi: 10.1109/ETAACT69135.2026.11542138.
R. Dandigam and C. Agrawal, “Comparative Study of Machine Learning Algorithms for Predictive Analytics in Web Applications,” in 2026 International Conference on Artificial Intelligence, Systems, and Emerging Technologies (ICAISET), IEEE, Apr. 2026, pp. 1–6. doi: 10.1109/ICAISET66439.2026.11542167.
M. H. Hamza Afzal, “Securing AI Systems Against Adversarial Attacks: A Framework for Building Robust and Trustworthy Machine Learning Models,” Comput. Fraud Secur., no. 5, pp. 65–74, May 2024, doi: 10.52710/cfs.867.
M. Kari, “Intelligent Deep Learning-Based System for Improved Phishing Identification Accuracy in Web Platforms,” in 2026 IEEE International Conference for Convergence in Computing Technology (I3CTCON), IEEE, Mar. 2026, pp. 1–6. doi: 10.1109/I3CTCON68242.2026.11508030.
S. Irfan, “Enhancing Email Security Through Accurate Phishing Detection Using Deep Transformer Models,” in 2026 World Conference on Computational Science and Technology (WcCST), IEEE, Mar. 2026, pp. 239–244. doi: 10.1109/WcCST67302.2026.11495864.
S. Chandrappa, S. Paheding, and Y. Cai, “Leveraging Large Language Models for Automated Detection of Cookie and Session Management Vulnerabilities,” in 2025 Northeast Section Conference Proceedings, ASEE Conferences, 2025. doi: 10.18260/1-2--55022.
R. Lingam, “Integrating Trustworthiness Into the AI Lifecycle (Trustworthiness),” in AI Safety and Preventing Harm in AI Systems, IGI Global Scientific Publishing, 2026, pp. 213–248. doi: 10.4018/979-8-3373-6935-8.ch008.
S. K. Sarangi, R. Lenka, J. Mishra, R. Sahu, and A. Nanda, “Malicious detection and trust calculation using residual recurrent neural network for trust with quality of service-aware multicast routing in mobile ad-hoc network system,” Eng. Appl. Artif. Intell., vol. 161, p. 112130, Dec. 2025, doi: 10.1016/j.engappai.2025.112130.
A. Blanco-Justicia and J. Domingo-Ferrer, “Machine Learning Explainability Through Comprehensible Decision Trees,” in Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2019. doi: 10.1007/978-3-030-29726-8_2.
B. Singh, M. Augie, H. Singh, and T. Banerjee, “Strengthening Modern IAM Authentication with Quantum Cryptography and Anti-Phishing Techniques,” Sarcouncil J. Eng. Comput. Sci., vol. 04, no. 10, pp. 1–8, 2025, doi: 10.5281/zenodo.17260292.
M. T. Ribeiro, S. Singh, and C. Guestrin, “‘why should i trust you?’ explaining the predictions of any classifier,” in NAACL-HLT 2016 - 2016 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Proceedings of the Demonstrations Session, 2016. doi: 10.18653/v1/n16-3020.
S. M. Lundberg and S. I. Lee, “A unified approach to interpreting model predictions,” in Advances in Neural Information Processing Systems, 2017.
S. Kukar, “Explainable AI Models for Transparent and Ethical Customer Relationship Management Decision,” in 2026 IEEE 2nd International Conference on Secure IoT, Assured and Trusted Computing (SATC), IEEE, Mar. 2026, pp. 1–7. doi: 10.1109/SATC69565.2026.11542554.
H. Manthena, S. Shajarian, J. C. Kimmell, M. Abdelsalam, S. Khorsandroo, and M. Gupta, “Explainable Artificial Intelligence (XAI) for Malware Analysis: A Survey of Techniques, Applications, and Open Challenges,” IEEE Access, vol. 13, no. February, pp. 61611–61640, 2025, doi: 10.1109/ACCESS.2025.3555926.
A. Goldstein, A. Kapelner, J. Bleich, and E. Pitkin, “Peeking Inside the Black Box: Visualizing Statistical Learning With Plots of Individual Conditional Expectation,” J. Comput. Graph. Stat., 2015, doi: 10.1080/10618600.2014.907095.
P. Sen and M. Chowdhury, “Generalizable Detection of Document-Based Phishing Malware: An Explainable Machine Learning Approach on CIC-Trap4Phish,” in 2026 IEEE 2nd International Conference on Quantum Photonics, Artificial Intelligence & Networking (QPAIN), IEEE, Apr. 2026, pp. 1–6. doi: 10.1109/QPAIN69676.2026.11546321.
M. S. Mia, I. T. Moon, N. Hasan, and M. S. R. Jahin, “MalXAI: Explainable Malware Detection Using Dynamic Graph-Based Data with Machine and Deep Learning,” in 2026 IEEE 2nd International Conference on Quantum Photonics, Artificial Intelligence & Networking (QPAIN), IEEE, Apr. 2026, pp. 1–6. doi: 10.1109/QPAIN69676.2026.11546230.
A. Alomar, A. AlJarullah, and S. Abu-Ghazalah, “Permissions-based Android malware detection using machine learning,” Neural Comput. Appl., 2025, doi: 10.1007/s00521-024-10950-4.
A. Mahato, R. Majumdar, and S. K. Ghosh, “Feature-Driven Malware Detection using Cascade Machine Learning Models,” SN Comput. Sci., 2025, doi: 10.1007/s42979-025-04342-1.
V. Sonawane, P. S. Patwal, and V. S. Wadne, “Android Malware Detection and Classification with Analysing Permission API’s using Recurrent Neural Network,” J. Inf. Syst. Eng. Manag., vol. 10, pp. 454–466, 2025, doi: 10.52783/jisem.v10i10s.1408.
R. Hilabi and A. Abu-Khadrah, “Windows operating system malware detection using machine learning,” Bull. Electr. Eng. Informatics, 2024, doi: 10.11591/eei.v13i5.8018.
A. Patel and S. M. Ghosh, “AMD-XAI-ML: Android Malware Detection based on an Explainable AI using Machine Learning for Smart Computing Environment,” in 2024 OPJU International Technology Conference on Smart Computing for Innovation and Advancement in Industry 4.0, OTCON 2024, 2024. doi: 10.1109/OTCON60325.2024.10687629.
S. K. Smmarwar, G. P. Gupta, and S. Kumar, “XAI-AMD-DL: An Explainable AI Approach for Android Malware Detection System Using Deep Learning,” in Proceedings - 2023 IEEE World Conference on Applied Intelligence and Computing, AIC 2023, 2023. doi: 10.1109/AIC57670.2023.10263974.

Similar Articles

21-30 of 33

You may also start an advanced similarity search for this article.