Return
Malware classification using deep neural networks with Deep Q-Learning and eXplainable artificial intelligence
DOI:10.1016/j.engappai.2025.113622.png)
Abstract
En 中文
Malware variants evolve quickly and exhibit highly non-linear patterns that limit the effectiveness of conventional machine-learning classifiers. To address this challenge, this study proposes uitMalDeQ, a Windows malware classification framework that integrates Deep Q-Learning (DQL) with explainable artificial intelligence (XAI) to provide both competitive classification performance and interpretable decision-making. The key novelty lies in combining reinforcement learning's adaptive decision policies with post-hoc feature importance analysis, enabling the system to learn from data interactions while maintaining transparency. The pipeline trains the DQL agent on labeled samples and evaluates it against strong baselines using standard metrics. Shapley additive explanations (SHAP) integration serves dual purposes: quantifying feature contributions for interpretability and guiding feature selection to improve efficiency. On the Microsoft malware classification challenge dataset (BIG2015), uitMalDeQ attains 98.21% accuracy and a 97.19% macro-averaged F1-score, demonstrating competitive performance with traditional methods while offering superior interpretability. SHAP analyses reveal the most influential features and enable a compact feature set (top 500 features) that improves validation accuracy to 98.73% without degrading test performance. Cross-dataset evaluation on Blue Hexagon open dataset for malware analysis (BODMAS) (99.44% accuracy) and elastic malware benchmark for empowering researchers (EMBER) (91.90% accuracy) further validates generalization capability. In summary, the proposed approach delivers a unique combination of reinforcement learning adaptability and explainable artificial intelligence transparency, providing actionable insights that support operational trust and feature reduction in malware detection systems.
Keywords:
eXplainable artificial intelligence
Windows malware classification
Deep neural networks
Machine learning
Deep Q-learning
Journal
IF:
8
Papers:
5.4K
Citations:
3.5W
Organization
No organization information available

