[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119077-en":3,"doc-seo-119077-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119077,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","Enhancing Malware Detection through Machine Learning using XAI with SHAP Framework","Malware poses a major cybersecurity threat that can disrupt organizational operations, making proactive detection essential yet difficult due to ever-growing malware data and rapidly evolving attacker techniques. Machine learning offers effective identification of malware features, but many existing ML approaches remain difficult to interpret, leaving uncertainty about feature selection and decision pathways. This research applies Explainable AI with the SHAP framework to improve transparency by revealing how individual features contribute to model conclusions. Experiments train Random Forest, AdaBoost, SVM, and Artificial Neural Network models, then explain decisions using XAI.","Enhancing Malware Detection through Machine Learning using XAI with SHAP Framework  \nNihala Basheer 1, Bernardi Pranggono1, Shareeful Islam 1,2, Spyridon Papastergiou2,3 ,  \nHaralambos Mouratidis4  \n1 School of Computing and Information Science  \nAnglia Ruskin University, East Road, Cambridge, UK  \n2 Research and Innovation, MAGGIOLI S.P.A., Italy  \n32Department of Informatics, University of Piraeus, Greece  \n4Institute for Analytics and Data Science, University of Essex, UK {nihala.basheer, bernardi.pranggono, [shareeful.islam}@aru.ac.uk](shareeful.islam}@aru.ac.uk),  \n[spyros.papastergiou@maggioli.gr](spyros.papastergiou@maggioli.gr), [h.mouratidis@essex.ac.uk](h.mouratidis@essex.ac.uk)  \nAbstract. Malware represents a significant cyber threat that can potentially disrupt any activities within an organization. There is a need to devise effective proactive methods for malware detection, thereby minimizing the associated risks. However, this task is challenging due to the ever-growing volume of malware data and the continuously evolving techniques employed by malicious actors. In this context, machine learning models offer a promising approach to identify key malware features and facilitate accurate detection. Machine learning has proven to be effective in detecting malware and has recently gained widespread attention from both the academic and research sectors. Despite their effectiveness, current research on machine learning (ML) models for malware detection often lacks necessary explanations for the selection of key features. This opacity of ML models can complicate the understanding of the outputs, errors, and decisionmaking processes. To address this challenge, this research uses Explainable AI (XAI), particularly the SHAP framework, to enhance transparency and interpretability. By providing extensive insights into how each feature contributes to the model’s conclusions, the approach further improves the model’s accountability. An experiment was conducted to demonstrate the applicability of the proposed method, beginning with the training of the chosen machine learning models, including Random Forest, Adaboost, Support Vector Machine and Artificial Neural Network, for detecting malware, and concluding with the explanation of the decision-making process using XAI techniques. The results showed high accuracy in malware detection, along with comprehensive explanations of the feature contributions, which justifies the outputs produced by the models.  \nKeywords: Explainable Artificial Intelligence, Cyber Security, SHAP, Malware Detection, Artificial Neural Network, Random Forest  \n1 Introduction  \nIn the ever-changing environment of digital security, the evolving nature of malware attacks poses a significant increase in sophisticate threats, which can disrupt the resilience of organizational business continuity. Recent data from Statista reveals a  \nstaggering 5.5 billion malware attacks in 2022 alone [1], with notorious incidents like WannaCry [2] underscoring the urgent need for advanced detection strategies. Both industry and research communities are actively engaged in the development of methods for malware detection, highlighting the pressing need to identify and manage potential digital infrastructure risks. Machine learning stands out as a promising approach for malware detection, particularly given the vast volume of malware data [3]. By enabling systems to learn from data, machine learning offers a proactive means to detect threatsand continually adapt to evolving malware variants. However, the issue of explainability in malware detection using machine learning is a significant concern [4], particularly in the domain of cybersecurity where the stakes are high and the need for trust and transparency is paramount. Machine learning models, especially those based on complex algorithms like deep learning, can often function as \"black boxes,” providing little to no insight into how they arrive at their predictions [5] . Thi","cbCairOa2jf5hhDX","https://ap.wps.com/l/cbCairOa2jf5hhDX","pdf",556346,1,14,"English","en",105,"# Abstract\n# Introduction\n# Contributions\n# Methodology and Experiments","[{\"question\":\"Why is explainability important for malware detection using machine learning?\",\"answer\":\"Machine learning models can behave like black boxes, providing limited insight into how predictions are formed. This opacity can hinder informed decisions and slow adoption in security-critical applications.\"},{\"question\":\"How does the research improve transparency in malware detection?\",\"answer\":\"It uses Explainable AI (XAI), specifically the SHAP framework, to show the contribution of each feature to model outputs. This enhances interpretability and supports accountability.\"},{\"question\":\"Which machine learning models are used in the malware detection experiment?\",\"answer\":\"The experiment trains Random Forest, AdaBoost, Support Vector Machine (SVM), and Artificial Neural Network (ANN) models for malware detection.\"}]","Enhancing Malware Detection through Machine Learning using XAI with SHAP Framework | PDF",1785722209,35,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"enhancing-malware-detection-through-machine-learning-using-xai-with-shap-framework","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/enhancing-malware-detection-through-machine-learning-using-xai-with-shap-framework/119077/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-05","2026-08-03",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"Why is explainability important for malware detection using machine learning?","Question",{"text":76,"@type":77},"Machine learning models can behave like black boxes, providing limited insight into how predictions are formed. This opacity can hinder informed decisions and slow adoption in security-critical applications.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does the research improve transparency in malware detection?",{"text":81,"@type":77},"It uses Explainable AI (XAI), specifically the SHAP framework, to show the contribution of each feature to model outputs. This enhances interpretability and supports accountability.",{"name":83,"@type":74,"acceptedAnswer":84},"Which machine learning models are used in the malware detection experiment?",{"text":85,"@type":77},"The experiment trains Random Forest, AdaBoost, Support Vector Machine (SVM), and Artificial Neural Network (ANN) models for malware detection.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":46,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":46,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":46,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]