[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-125843-en":3,"doc-seo-125843-105":31,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},125843,1099523885074,"Ivy","https://ap-avatar.wpscdn.com/davatar_9964176cb1d06d4a9deccf72a44ae3dc",8,"Research & Report","PDF Malware Detection - Toward Machine Learning Modeling with Explainability Analysis - Journal Article","The Portable Document Format (PDF) is widely abused by fraudsters who insert harmful code to compromise victims. Conventional identification and security solutions often fail to fully prevent PDF malware due to PDF diversity and reliance on typical feature sets. This work aims to detect PDF malware efficiently by building a comprehensive dataset of 15,958 PDFs, extracting features with PDFiD, PDFINFO, and PDF-PARSER, and deriving additional helpful feature variants.","Edith Cowan University  \nResearch Online  \nResearch outputs 2022 to 2026  \n1-1-2024  \nPDF malware detection: Toward machine learning modeling with explainability analysis  \nG. M.Sakhawat Hossain  \nKaushik Deb  \nHelge Janicke  \nEdith Cowan University  \nIqbal H. Sarker  \nEdith Cowan University  \nFollow this and additional works at: [https://ro.ecu.edu.au/ecuworks2022-2026](https://ro.ecu.edu.au/ecuworks2022-2026)  \n Part of the Information Security Commons  \n10.1109/ACCESS.2024.3357620  \nHossain, G. M. S., Deb, K., Janicke, H., & Sarker, I . H. (2024) . PDF malware detection: Toward machine learning modeling with explainability analysis. IEEE Access, 12, 13833-13859 . [https://doi.org/10.1109/](https://doi.org/10.1109/)[ ](https://doi.org/10.1109/)ACCESS.2024.3357620  \nThis Journal Article is posted at Research Online.  \n[https://ro.ecu.edu.au/ecuworks2022-2026/3761](https://ro.ecu.edu.au/ecuworks2022-2026/3761)  \nReceived 29 December 2023, accepted 18 January 2024, date of publication 23 January 2024, date of current version 30 January 2024. Digital Object Identifier 10.1109/ACCESS.2024.3357620  \nPDF Malware Detection: Toward Machine Learning Modeling With  \nExplainability Analysis  \nG. M. SAKHAWAT HOSSAIN1,2, KAUSHIK DEB1, HELGE JANICKE3,4, AND IQBAL H. SARKER3,4,(Member, IEEE)  \n1Department of Computer Science and Engineering, Chittagong University of Engineering and Technology, Chattogram 4349, Bangladesh  \n2Department of Computer Science and Engineering, Rangamati Science and Technology University, Chattogram 4500, Bangladesh  \n3Cyber Security Cooperative Research Centre, Joondalup, WA 6027, Australia  \n4 Security Research Institute, School of Science, Edith Cowan University, Perth, WA 6027, Australia  \nCorresponding authors: Kaushik Deb ([debkaushik99@cuet.ac.bd](debkaushik99@cuet.ac.bd)) and Iqbal H. Sarker ([m.sarker@ecu.edu.au](m.sarker@ecu.edu.au))  \nThis work was supported by ECU Security Research Institute, School of Science, Edith Cowan University (ECU), Australia.  \nABSTRACT The Portable Document Format (PDF) is one of the most widely used file types, thus fraudsters insert harmful code into victims’ PDF documents to compromise their equipment. Conventional solutionsand identification techniques are often insufficient and may only partially prevent PDF malware because of their versatile character and excessive dependence on a certain typical feature set. The primary goal of this work is to detect PDF malware efficiently in order to alleviate the current difficulties. To accomplish the goal, we first develop a comprehensive dataset of 15958 PDF samples taking into account the non-malevolent, malicious, and evasive behaviors of the PDF samples. Using three well-known PDF analysis tools (PDFiD, PDFINFO, and PDF-PARSER), we extract significant characteristics from the PDF samples of our newly created dataset. In addition, we generate a number of derivations of features that have been experimentally proven to be helpful in classifying PDF malware. We develop a method to build an efficient and explicable feature set through the proper empirical analysis of the extracted and derived features. We explore different baseline machine learning classifiers and demonstrate an accuracy improvement of approx. 2% for the Random Forest classifier utilizing the selected feature set. Furthermore, we demonstrate the model’s explainability by creating a decision tree that generates rules for human interpretation. Eventually, we make a comparison with previous studies and point out some important findings.  \nINDEX TERMS Cybersecurity, PDF malware, data analytics, machine learning, decision rule, explainable AI, human interpretation.  \nI. INTRODUCTION  \nIn today’s digital world, the majority of our tasks are associated with the use of the global web, making it increasingly essential to protect our data, information, and applications, in the face of a variety of cyber criminals who continually attempt to construct brand-new illicit program","cbCaikoMwuEirXzC","https://ap.wps.com/l/cbCaikoMwuEirXzC","pdf",5128317,3,1,28,"English","en",105,"# Abstract\n# Introduction\n## Malware identification approaches\n# Dataset and feature extraction\n## Tools: PDFiD, PDFINFO, PDF-PARSER\n# Feature selection and explainability\n## Random Forest baseline and decision rules\n# Experiments and comparison\n## Findings versus prior studies","[{\"question\":\"What is the main goal of this PDF malware detection study?\",\"answer\":\"Detect PDF malware efficiently to address limitations of conventional approaches that may only partially prevent attacks.\"},{\"question\":\"How is the dataset built and what does it cover?\",\"answer\":\"A comprehensive dataset of 15,958 PDF samples is created, considering non-malicious, malicious, and evasive behaviors.\"},{\"question\":\"How do the authors improve both accuracy and interpretability?\",\"answer\":\"They build an efficient, explainable feature set from extracted and derived features, improve performance using a Random Forest classifier (~2% accuracy gain), and generate human-interpretable rules via a decision tree.\"}]","PDF Malware Detection - Toward Machine Learning Modeling with Explainability Analysis - Journal Article | PDF",1785901537,71,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":29},"pdf-malware-detection-toward-machine-learning-modeling-with-explainability-analysis-journal-article","",{"@graph":37,"@context":86},[38,54,69],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,51],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":20},"https://docshare.wps.com/document/research-report/",{"item":52,"name":13,"@type":44,"position":53},"https://docshare.wps.com/document/pdf-malware-detection-toward-machine-learning-modeling-with-explainability-analysis-journal-article/125843/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":42,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-24","2026-08-05",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What is the main goal of this PDF malware detection study?","Question",{"text":76,"@type":77},"Detect PDF malware efficiently to address limitations of conventional approaches that may only partially prevent attacks.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How is the dataset built and what does it cover?",{"text":81,"@type":77},"A comprehensive dataset of 15,958 PDF samples is created, considering non-malicious, malicious, and evasive behaviors.",{"name":83,"@type":74,"acceptedAnswer":84},"How do the authors improve both accuracy and interpretability?",{"text":85,"@type":77},"They build an efficient, explainable feature set from extracted and derived features, improve performance using a Random Forest classifier (~2% accuracy gain), and generate human-interpretable rules via a decision tree.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,121,124,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":47,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":47,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":47,"category_name":118,"show_sort_weight":119,"slug":120},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":122,"slug":123},30,"research-report",{"id":125,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},9,"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":107,"slug":139},19,"General","general"]