[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-121303-en":3,"doc-seo-121303-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},121303,1099514067415,"Rowan","https://ap-avatar.wpscdn.com/avatar/100002539d78ffe74a7?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779092875211072502",8,"Research & Report","Detecting new obfuscated malware variants - A lightweight and interpretable machine learning approach","Machine learning for malware detection has achieved strong accuracy, but faces growing demands for lower computational overhead and clearer interpretability. This work addresses a key gap: whether models can recognize entirely new malware forms absent from training data. A lightweight, accurate, and interpretable system is developed for obfuscated malware, trained exclusively on one subtype and evaluated across unseen subtypes. Using top selected features and random forests, the Transponder-focused model reaches over 99.8% accuracy with 5.7 µs per file, supported by SHAP-based explanations.","Detecting new obfuscated malware variants: A lightweight and interpretable machine learning approach  \nAuthors: Oladipo A. Madamidolaa, Felix Ngobighaa and Adnane Ez-zizia, *  \nAffiliations: a University of Suffolk, Waterfront Building, IP4 1QJ, Ipswich, UK  \nAbstract  \nMachine learning has been successfully applied in developing malware detection systems, with a primary focus on accuracy, and increasing attention to reducing computational overhead and improving model interpretability. However, an important question remains underexplored: How well can machine learning-based models detect entirely new forms of malware not present in the training data? In this study, we present a machine learning-based system for detecting obfuscated malware that is not only highly accurate, lightweight and interpretable, but also capable of successfully adapting to new types of malware attacks. Our system is capable of detecting 15 malware subtypes despite being exclusively trained on one malware subtype, namely the Transponder from the Spyware family. This system was built after training 15 distinct random forest-based models, each on a different malware subtype from the CICMalMem-2022 dataset. These models were evaluated against the entire range of malware subtypes, including all unseen malware subtypes. To maintain the system’s streamlined nature, training was confined to the top five most important features, which also enhanced interpretability. The Transponder-focused model exhibited high accuracy, exceeding 99.8%, with an average processing speed of 5.7 µs per file. We also illustrate how the Shapley additive explanations technique can facilitate the interpretation of the model predictions. Our research contributes to advancing malware detection methodologies, pioneering the feasibility of detecting obfuscated malware by exclusively training a model on a single or a few carefully selected malware subtype and applying it to detect unseen subtypes.  \n* Corresponding author. Email address: [a.ez-zizi@uos.ac.uk](a.ez-zizi@uos.ac.uk) (A. Ez-zizi)  \nKeywords  \nCyber security, Obfuscated malware, Detection of unknown malware, Machine learning, Explainable machine learning.  \n1. Introduction  \nOver the last two decades, technological advancements in cloud computing, the Internet of Things (IoT) and the introduction of fifth Generation (5G) and beyond 5G mobile networks have revolutionised the way businesses and individuals access and store data (Mijwil et al., 2023) . This technological paradigm shift has enabled individuals and organisations to access their data seamlessly from anywhere in the world, using any connected devices. However, malware (i.e., malicious software) poses a significant threat to the security of these technologies. Malicious actors can use malware to compromise the confidentiality, integrity, and availability of data (Gupta and Rani, 2020). The impact of malware can be devastating for businesses and individuals alike, as it can result in the loss of sensitive information, such as personal data and financial information. In 2021 alone, over 1.3 billion malware specimens were detected (Dener et al., 2022), and with increased connectivity, reliance on digital systems, and the growing number of connected devices, the attack landscape is expected to grow even more.  \nWith an unprecedented number of malware targeting various computing systems and online infrastructures, the detection of malware is of great importance. Unfortunately, traditional methods of malware detection, such as signature-based detection and behaviour-based detection, are becoming increasingly less effective against modern and sophisticated malware attacks. Malicious authors are using advanced technologies to design malware that is increasingly difficult to detect and exterminate (Mezina and Burget, 2022) . In recent years, there has been a pivot towards the use of machine learning (ML) for malware detection. Oneof the advantages of the ML-based approach is it","cbCaiuyGtBefjwpM","https://ap.wps.com/l/cbCaiuyGtBefjwpM","pdf",1042227,1,36,"English","en",105,"# Introduction\n## Research contributions","[{\"question\":\"What core challenge does the study address in malware detection?\",\"answer\":\"The study examines how well machine learning models can detect entirely new malware variants that do not appear in the training data.\"},{\"question\":\"How is the proposed system trained and why is it lightweight?\",\"answer\":\"The system is trained on one malware subtype and uses only the top five most important features, reducing training scope and maintaining low computational overhead.\"},{\"question\":\"What performance and interpretability results are reported?\",\"answer\":\"The Transponder-focused model exceeds 99.8% accuracy and averages 5.7 µs per file, while SHAP (Shapley additive explanations) is used to interpret model predictions.\"}]","Detecting new obfuscated malware variants - A lightweight and interpretable machine learning approach | PDF",1785734976,91,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"detecting-new-obfuscated-malware-variants-a-lightweight-and-interpretable-machine-learning-approach","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/detecting-new-obfuscated-malware-variants-a-lightweight-and-interpretable-machine-learning-approach/121303/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What core challenge does the study address in malware detection?","Question",{"text":75,"@type":76},"The study examines how well machine learning models can detect entirely new malware variants that do not appear in the training data.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is the proposed system trained and why is it lightweight?",{"text":80,"@type":76},"The system is trained on one malware subtype and uses only the top five most important features, reducing training scope and maintaining low computational overhead.",{"name":82,"@type":73,"acceptedAnswer":83},"What performance and interpretability results are reported?",{"text":84,"@type":76},"The Transponder-focused model exceeds 99.8% accuracy and averages 5.7 µs per file, while SHAP (Shapley additive explanations) is used to interpret model predictions.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]