[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120188-en":3,"doc-seo-120188-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120188,1099514068035,"Ezra","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Detecting new obfuscated malware variants - A lightweight and interpretable machine learning approach","Machine learning has been applied to malware detection, where accuracy is often prioritized while computational cost and interpretability receive increasing attention. A key gap remains: the ability of ML models to detect entirely new malware forms absent from training data. This study proposes a lightweight, interpretable system for detecting obfuscated malware that adapts to unseen attack types. Trained on one subtype, it detects 15 subtypes with >99.8% accuracy, fast processing, and explainability using SHAP values.","Intelligent Systems with Applications 25 (2025) 200472  \nContents lists available at ScienceDirect  \nIntelligent Systems with Applications  \njournal [homepage: www.journals.elsevier.com/intelligent-systems-with-applications](homepage: www.journals.elsevier.com/intelligent-systems-with-applications)  \n| Detecting new obfuscated malware variants: A lightweight and interpretable machine learning approach\u003Cbr>Oladipo A. Madamidola, Felix Ngobigha, Adnane Ez-zizi * \u003Cbr>University of Suffolk, Waterfront Building, IP4 1QJ Ipswich, UK |  |  |\n| --- | --- | --- |\n| A R T I C L E I N F O |  | A B S T R A C T |\n| Keywords:\u003Cbr>Cyber security\u003Cbr>Obfuscated malware Detection of unknown malware Machine learning\u003Cbr>Explainable machine learning |  | Machine learning has been successfully applied in developing malware detection systems, with a primary focus on accuracy, and increasing attention to reducing computational overhead and improving model interpretability. However, an important question remains underexplored: How well can machine learning-based models detect entirely new forms of malware not present in the training data? In this study, we present a machine learningbased system for detecting obfuscated malware that is not only highly accurate, lightweight and interpretable, but also capable of successfully adapting to new types of malware attacks. Our system is capable of detecting 15 malware subtypes despite being exclusively trained on one malware subtype, namely the Transponder from the Spyware family. This system was built after training 15 distinct random forest-based models, each on a different malware subtype from the CIC-MalMem-2022 dataset. These models were evaluated against the entire range of malware subtypes, including all unseen malware subtypes. To maintain the system’s streamlined nature, training was confined to the top five most important features, which also enhanced interpretability. The Transponderfocused model exhibited high accuracy, exceeding 99.8%, with an average processing speed of 5.7 µs per file. We also illustrate how the Shapley additive explanations technique can facilitate the interpretation of the model predictions. Our research contributes to advancing malware detection methodologies, pioneering the feasibility of detecting obfuscated malware by exclusively training a model on a single or a few carefully selected malware subtype and applying it to detect unseen subtypes. |\n\n1. Introduction  \nOver the last two decades, technological advancements in cloud computing, the Internet of Things (IoT) and the introduction of fifth Generation (5G) and beyond 5G mobile networks have revolutionised the way businesses and individuals access and store data (Mijwil et al., 2023). This technological paradigm shift has enabled individuals and organisations to access their data seamlessly from anywhere in the world, using any connected devices. However, malware (i.e., malicious software) poses a significant threat to the security of these technologies. Malicious actors can use malware to compromise the confidentiality, integrity, and availability of data (Gupta & Rani, 2020). The impact of malware can be devastating for businesses and individuals alike, as it can result in the loss of sensitive information, such as personal data and financial information. In 2021 alone, over 1.3 billion malware specimens were detected (Dener et al., 2022), and with increased connectivity, reliance on digital systems, and the growing number of connected devices, the attack landscape is expected to grow even more.  \nWith an unprecedented number of malware targeting various computing systems and online infrastructures, the detection of malware is of great importance. Unfortunately, traditional methods of malware detection, such as signature-based detection and behaviour-based detection, are becoming increasingly less effective against modern and sophisticated malware attacks. Malicious authors are using advanced technologies to design malw","cbCaidCZhELLruEY","https://ap.wps.com/l/cbCaidCZhELLruEY","pdf",3124209,1,13,"English","en",105,"# Introduction\n## Research contributions","[{\"question\":\"What problem does the study address in malware detection?\",\"answer\":\"The study focuses on whether machine learning models can detect entirely new malware variants that do not appear in the training data.\"},{\"question\":\"How is interpretability achieved in the proposed approach?\",\"answer\":\"Interpretability is supported by using the Shapley additive explanations (SHAP) technique to explain model predictions.\"},{\"question\":\"What performance does the Transponder-focused model achieve?\",\"answer\":\"The Transponder-focused model reaches accuracy above 99.8% while maintaining an average processing speed of about 5.7 µs per file.\"}]","Detecting new obfuscated malware variants - A lightweight and interpretable machine learning approach | PDF",1785728624,33,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"detecting-new-obfuscated-malware-variants-a-lightweight-and-interpretable-machine-learning-approach","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/detecting-new-obfuscated-malware-variants-a-lightweight-and-interpretable-machine-learning-approach/120188/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the study address in malware detection?","Question",{"text":75,"@type":76},"The study focuses on whether machine learning models can detect entirely new malware variants that do not appear in the training data.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is interpretability achieved in the proposed approach?",{"text":80,"@type":76},"Interpretability is supported by using the Shapley additive explanations (SHAP) technique to explain model predictions.",{"name":82,"@type":73,"acceptedAnswer":83},"What performance does the Transponder-focused model achieve?",{"text":84,"@type":76},"The Transponder-focused model reaches accuracy above 99.8% while maintaining an average processing speed of about 5.7 µs per file.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]