PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 28, 2026PeerJ Computer Science0 citationsOpen Access

Explainable AI for malware analysis: a systematic review of benchmark datasets, traffic-oriented detection, and interpretability methods

View Full Paper
BYBowen YuWZWanting ZhangYLYishen Liu

Key Points

  • The review aims to synthesize recent advancements in malware analysis, focusing on explainable AI and benchmark datasets.
  • Conducted a systematic review of literature from the past 5 years.
  • Evaluated technologies for traffic-oriented detection and interpretability methods.
  • Discussed specific benchmark datasets relevant to various malware-analysis contexts.
  • Identified strengths and limitations of current explainable AI application in malware analysis.
  • Highlighted challenges related to interpretability overhead and dataset dependence.
  • Outlined critical research gaps and proposed directions for enhancing scalability and trustworthiness.

Abstract

In recent years, malicious software (malware) has remained a persistent and evolving threat, affecting both personal and organizational devices across diverse computing environments. This article presents a systematic review of recent progress in malware analysis over the past 5 years, with particular emphasis on benchmark datasets, traffic-oriented detection settings, deep learning methods, and explainable artificial intelligence (XAI) approaches. Representative benchmark resources discussed in the reviewed literature include CIC IoMT 2024, CIC-MalMem-2022, and CICMalDroid 2020, which reflect different malware-analysis contexts such as IoMT/network traffic, memory-based Windows malware behavior, and Android malware analysis. The review examines how prior studies characterize malicious behaviors, evaluate detection paradigms, and employ interpretability techniques such as Local Interpretable Model-Agnostic Explanations (LIME) and Shapley Additive Explanations (SHAP) to improve model transparency and analyst understanding. In addition to summarizing the practical strengths of these approaches, the article discusses current limitations related to interpretability overhead, dataset dependence, scalability, and deployment constraints. The review concludes by identifying major research gaps and outlining future directions for building more scalable, explainable, and trustworthy malware-analysis systems.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Yu et al. (2026) studied this question.

synapsesocial.com/papers/6a17dd4e3fad632b0f9da08fhttps://doi.org/10.7717/peerj-cs.3902
Ask AI
Helpful
Bookmark
Share
View Full Paper