arrow
Return

Malware classification using deep neural networks with Deep Q-Learning and eXplainable artificial intelligence

delete2026-01-21
delete0
PRE
AI
N
Nguyen Tan Cam *
T
Tran Minh Huy
N
Nguyen Thanh Tin
DOI:10.1016/j.engappai.2025.113622delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Malware variants evolve quickly and exhibit highly non-linear patterns that limit the effectiveness of conventional machine-learning classifiers. To address this challenge, this study proposes uitMalDeQ, a Windows malware classification framework that integrates Deep Q-Learning (DQL) with explainable artificial intelligence (XAI) to provide both competitive classification performance and interpretable decision-making. The key novelty lies in combining reinforcement learning's adaptive decision policies with post-hoc feature importance analysis, enabling the system to learn from data interactions while maintaining transparency. The pipeline trains the DQL agent on labeled samples and evaluates it against strong baselines using standard metrics. Shapley additive explanations (SHAP) integration serves dual purposes: quantifying feature contributions for interpretability and guiding feature selection to improve efficiency. On the Microsoft malware classification challenge dataset (BIG2015), uitMalDeQ attains 98.21% accuracy and a 97.19% macro-averaged F1-score, demonstrating competitive performance with traditional methods while offering superior interpretability. SHAP analyses reveal the most influential features and enable a compact feature set (top 500 features) that improves validation accuracy to 98.73% without degrading test performance. Cross-dataset evaluation on Blue Hexagon open dataset for malware analysis (BODMAS) (99.44% accuracy) and elastic malware benchmark for empowering researchers (EMBER) (91.90% accuracy) further validates generalization capability. In summary, the proposed approach delivers a unique combination of reinforcement learning adaptability and explainable artificial intelligence transparency, providing actionable insights that support operational trust and feature reduction in malware detection systems.
Keywords:
eXplainable artificial intelligence
Windows malware classification
Deep neural networks
Machine learning
Deep Q-learning

Journal

Engineering Applications of Artificial Intelligence cover
Engineering Applications of Artificial Intelligence
IF:
8
Papers:
5.4K
Citations:
3.5W

Organization

No organization information available