<div class="csl-bib-body">
<div class="csl-entry">Anthony, P., Galadima, K. R., Adams, Z., Onoja, M., Arp, D., Homola, M., & Balogh, Š. (2025). Rule Extraction and Interaction-Aware Explainability for AI-Driven Malware Detection. In A. Hogan, K. Satoh, H. Dağ, A.-Y. Turhan, D. Roman, & A. Soylu (Eds.), <i>Rules and Reasoning : 9th International Joint Conference, RuleML+RR 2025, Istanbul, Turkey, September 22–24, 2025, Proceedings</i> (pp. 137–155). Springer. https://doi.org/10.1007/978-3-032-08887-1_9</div>
</div>
-
dc.identifier.uri
http://hdl.handle.net/20.500.12708/223656
-
dc.description.abstract
As machine learning becomes integral to malware detection, the demand for interpretability has become critical, not only to understand model decisions, but also to support actionable insights for analysts. While post-hoc techniques like SHAP, LIME, and Anchor offer feature attributions or instance-level rules, they fail to capture generalized semantic patterns across malware samples. To address this, we propose a unified and extensible explainability framework for binarized malware features, offering three levels of interpretability: (1) first-order explanations (individual feature effects), (2) second-order explanations (pairwise interactions revealing nonlinear dependencies), and (3) higher-order, rule-based explanations that formalize joint feature contributions for deeper analytical insight. Our framework builds on an MLP-based detector trained on the EMBER dataset. It first uses SHAP to assess global feature relevance and then introduces two key extensions: (i) a SHAP-based interaction formalism that reveals synergistic and antagonistic effects among features, and (ii) a generalized Anchor algorithm that extracts symbolic, reusable rules to illuminate model behavior and malware patterns. Our global rules achieve an F1 score of 83% on EMBER and perfectly reconstruct nonlinear decision boundaries in synthetic benchmarks (100% F1 on the XoR dataset). Analysis of EMBER’s extracted rules reveals that the black-box model’s logic often relies on structural anomalies, prioritizing statistical patterns rather than capturing meaningful behavioral patterns indicative of known malware tactics.
en
dc.description.sponsorship
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds
-
dc.language.iso
en
-
dc.relation.ispartofseries
Lecture Notes in Computer Science
-
dc.subject
Anchor Explainer
en
dc.subject
EMBER Dataset
en
dc.subject
Explainable Malware Detection
en
dc.subject
SHAP
en
dc.subject
XAI
en
dc.title
Rule Extraction and Interaction-Aware Explainability for AI-Driven Malware Detection
en
dc.type
Inproceedings
en
dc.type
Konferenzbeitrag
de
dc.contributor.affiliation
Comenius University Bratislava, Slovakia
-
dc.contributor.affiliation
Slovak University of Technology in Bratislava, Slovakia
-
dc.contributor.affiliation
Comenius University Bratislava, Slovakia
-
dc.contributor.affiliation
Comenius University Bratislava, Slovakia
-
dc.contributor.affiliation
Comenius University Bratislava, Slovakia
-
dc.contributor.affiliation
Slovak University of Technology in Bratislava, Slovakia
-
dc.contributor.editoraffiliation
Universidad de Santiago de Chile, Chile
-
dc.contributor.editoraffiliation
Kadir Has University, Turkey
-
dc.contributor.editoraffiliation
Paderborn University, Germany
-
dc.contributor.editoraffiliation
Høyskolen Kristiania, Norway
-
dc.relation.isbn
978-3-032-08887-1
-
dc.relation.doi
10.1007/978-3-032-08887-1
-
dc.relation.issn
0302-9743
-
dc.description.startpage
137
-
dc.description.endpage
155
-
dc.relation.grantno
VRG23-011
-
dc.type.category
Full-Paper Contribution
-
dc.relation.eissn
1611-3349
-
tuw.booktitle
Rules and Reasoning : 9th International Joint Conference, RuleML+RR 2025, Istanbul, Turkey, September 22–24, 2025, Proceedings
-
tuw.container.volume
16144
-
tuw.peerreviewed
true
-
tuw.relation.publisher
Springer
-
tuw.relation.publisherplace
Cham
-
tuw.project.title
Building Robust and Explainable AI-based Defenses for Computer Security
-
tuw.researchTopic.id
I1
-
tuw.researchTopic.id
I4
-
tuw.researchTopic.name
Logic and Computation
-
tuw.researchTopic.name
Information Systems Engineering
-
tuw.researchTopic.value
40
-
tuw.researchTopic.value
60
-
tuw.publication.orgunit
E192-06 - Forschungsbereich Security and Privacy
-
tuw.publisher.doi
10.1007/978-3-032-08887-1_9
-
dc.description.numberOfPages
19
-
tuw.author.orcid
0000-0002-9010-3075
-
tuw.author.orcid
0009-0009-1743-6269
-
tuw.author.orcid
0009-0006-3413-2409
-
tuw.author.orcid
0000-0003-2119-170X
-
tuw.author.orcid
0000-0003-3628-794X
-
tuw.author.orcid
0000-0001-6384-9771
-
tuw.author.orcid
0000-0003-0634-9476
-
tuw.editor.orcid
0000-0001-9482-1982
-
tuw.editor.orcid
0000-0002-9309-4602
-
tuw.event.name
9th International Joint Conference on Rules and Reasoning (RuleML+RR 2025)
en
tuw.event.startdate
22-09-2025
-
tuw.event.enddate
24-09-2025
-
tuw.event.online
On Site
-
tuw.event.type
Event for scientific audience
-
tuw.event.place
Istanbul
-
tuw.event.country
TR
-
tuw.event.presenter
Anthony, Peter
-
wb.sciencebranch
Informatik
-
wb.sciencebranch
Mathematik
-
wb.sciencebranch.oefos
1020
-
wb.sciencebranch.oefos
1010
-
wb.sciencebranch.value
80
-
wb.sciencebranch.value
20
-
item.openairetype
conference paper
-
item.openairecristype
http://purl.org/coar/resource_type/c_5794
-
item.cerifentitytype
Publications
-
item.languageiso639-1
en
-
item.grantfulltext
none
-
item.fulltext
no Fulltext
-
crisitem.author.dept
Comenius University Bratislava, Slovakia
-
crisitem.author.dept
Slovak University of Technology in Bratislava, Slovakia
-
crisitem.author.dept
Comenius University Bratislava, Slovakia
-
crisitem.author.dept
Comenius University Bratislava, Slovakia
-
crisitem.author.dept
E192-06 - Forschungsbereich Security and Privacy
-
crisitem.author.dept
Comenius University Bratislava, Slovakia
-
crisitem.author.dept
Slovak University of Technology in Bratislava, Slovakia
-
crisitem.author.orcid
0000-0002-9010-3075
-
crisitem.author.orcid
0009-0009-1743-6269
-
crisitem.author.orcid
0009-0006-3413-2409
-
crisitem.author.orcid
0000-0003-2119-170X
-
crisitem.author.orcid
0000-0003-3628-794X
-
crisitem.author.orcid
0000-0001-6384-9771
-
crisitem.author.orcid
0000-0003-0634-9476
-
crisitem.author.parentorg
E192 - Institut für Logic and Computation
-
crisitem.project.funder
WWTF Wiener Wissenschafts-, Forschu und Technologiefonds