Back to feed
Review

A Review of Explainable Machine Learning Methods for Malware Detection and Classification

Jul 2026 · International Journal of Cyber Threat Intelligence and Secure Networking · 0 citations

Abstract

Traditional cybersecurity solutions have been greatly challenged by the fast growth of malware, making accurate and interpretable malware detection crucial. In recent years, deep learning (DL) and machine learning (ML) have gained traction as potent methods for identifying malware, both known and undiscovered, polymorphic, and zero-day. These methods learn intricate patterns from both static and dynamic data analysis. Many ML and DL models, however, are opaque and untrustworthy because to their black-box design, which is particularly problematic for applications that rely on security. Malware detection and categorisation using explainable machine learning approaches is thoroughly reviewed in this study. Starting with a general introduction to malware detection and the most frequent kinds of malware, it moves on to cover the three main classical detection approaches: signature-based, behavioral-based, and heuristic-based. Advanced malware detection approaches based on ML and DL are further examined in the paper, which highlights frequently used algorithms, their working principles, and benefits. Along with that, it delves into XAI approaches like LIME, KernelSHAP, and Shapley values, which are model-agnostic, to enhance the interpretability of malware detection models. These techniques use transparent machine learning models and both global and local explanations. Accumulated Local Effects (ALE), Individual Conditional Expectation (ICE), and Partial Dependence Plot (PDP) are among the visual methods of explanation that are covered. The study concludes with a review of the literature, an analysis of the current state of affairs, and a plan for the future of research into the topic of malware detection systems as it pertains to building confidence among users and facilitating educated cybersecurity decisions.

View source