Explainable Memory-Based Privacy Malware Classification Using Machine Learning and Deep Learning
Abstract
Current malware detection systems face obstacles because modern malware operates with increasingly complex patterns which signature-based detection systems cannot identify. Malware developers use obfuscation and encryption and polymorphism techniques to protect their malware from detection by security systems. Memory forensics has developed into an effective method for detecting harmful activities through the examination of artifacts which exist in a computer system's memory during operational times. The research proposes a malware classification system based on machine learning, using memory features from the CIC-MalMem-2022 dataset to detect and categorize malicious software. The research proposes a malware classification system based on machine learning, using memory features from the CIC-MalMem-2022 dataset to detect and categorize malicious software. The proposed architecture utilises a stacked ensemble model combining a Random Forest classifier, a neural network meta-learner and a Bidirectional LSTM-GRU deep learning model. The final classification results from merging probability predictions which both systems created through their different prediction methods. The proposed framework demonstrates strong performance in detecting binary malware, achieving high accuracy with minimal false positives and false negatives, and AUC scores of approximately $\mathbf{0. 9 6 - 0. 9 7}$ across malware categories, with classification accuracy of 85% or higher across all 15 tested malware families. SHAP (SHapley Additive exPlanations) forms the basis for enhancing interpretability because it identifies memory-derived features which most influence model predictions, thus making the system more understandable. The framework functions as a tool for cyber security professionals because memory acquisition and forensic analysis need specific tools and administrative access rights.