What is it about?
Deep neural networks can detect malicious software with high accuracy, but their decisions are often difficult to understand. Their complexity can also hide weaknesses that attackers may exploit. This paper investigates whether explainable artificial intelligence can help identify the smallest set of input characteristics needed to build an accurate malware-detection model. The study compares feature rankings generated through a global explainable AI technique and Mutual Information analysis. These rankings are examined from two complementary perspectives: simplifying the model for cybersecurity defenders and assessing its vulnerability to adversarial manipulation.
Featured Image
Photo by Sasun Bughdaryan on Unsplash
Why is it important?
In cybersecurity, predictive accuracy alone is not enough. A malware-detection model should also be understandable, efficient and robust against attempts to evade it. Reducing the number of input characteristics can produce simpler models that are easier to analyse and potentially less expensive to operate. However, the same analysis may reveal a small number of influential characteristics whose manipulation could strongly affect the model’s decisions. Understanding both sides of this trade-off can help researchers design malware detectors that maintain good predictive performance while being more transparent and security-aware.
Perspectives
Our goal was to reconsider what makes a deep-learning model effective in cybersecurity. A highly accurate model is not necessarily a trustworthy one if its decisions are opaque or if small changes to a few input characteristics can allow malicious software to evade detection. Explainable AI can help identify the characteristics on which the model relies most strongly. This knowledge can support the development of simpler detection models, but it can also expose potential vulnerabilities that should be considered when evaluating and strengthening them. Key takeaways - Accuracy should not be the only criterion used to evaluate deep malware-detection models. - Explainable AI can identify the input characteristics that most influence model decisions. - A reduced set of characteristics may support simpler models while preserving strong predictive performance. - Feature importance can also reveal potential weaknesses against adversarial manipulation. - The study compares global XAI-based rankings with Mutual Information analysis. - Experiments were conducted using the CICMaldroid2020 and CICMalMem2022 malware datasets.
Prof. Donato Malerba
Universita degli Studi di Bari Aldo Moro
Read the Original
This page is a summary of: Striving for Simplicity in Deep Neural Models Trained for Malware Detection, January 2025, Springer Science + Business Media,
DOI: 10.1007/978-3-031-74633-8_40.
You can read the full text:
Contributors
The following have contributed to this page







