<p>The rise of Android malware presents a critical challenge to mobile device security, highlighting the need for effective and transparent detection mechanisms. This study develops an Explainable AI-based approach for Android Malware Detection using the CICAndMal2017 dataset. Our primary objective is to enhance the transparency and interpretability of AI-powered security solutions, essential for building trust and usability. We utilize a suite of distinct categories of algorithms such as Advanced Deep Learning (GRU, LSTM and CNN), Basic machine learning (Decision Tree and Logistic Regression) and ensemble-based models (Random Forest, Gradient Boosting, AdaBoost and a custom-developed ensemble). The evaluation carried out using the CICAndMAL2017 dataset shows that these models achieve accuracies ranging from 89.4% to 98.82%. Further, we integrate Local Interpretable Model-agnostic Explanations (LIME) and Shapley Additive Explanations (SHAP) frameworks to generate local and global analyses. Our analysis using the frameworks reveals that key features such as ‘Timestamp’ and ‘Fwd IAT Max’ contribute to the model predictions with high precision. Results obtained demonstrate the effectiveness of the proposed approach for malware classification as well as feature importance. Thus this study emphasizes the importance of explainable AI for improving the interpretability and explainability of models for malware detection, which enhances the security of mobile devices.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Explainable AI-based Android Malware Detection

  • M. V. Shiva Sharma,
  • M. Tilak,
  • Udita Pareek,
  • Sriram Sankaran,
  • Amita Sharma

摘要

The rise of Android malware presents a critical challenge to mobile device security, highlighting the need for effective and transparent detection mechanisms. This study develops an Explainable AI-based approach for Android Malware Detection using the CICAndMal2017 dataset. Our primary objective is to enhance the transparency and interpretability of AI-powered security solutions, essential for building trust and usability. We utilize a suite of distinct categories of algorithms such as Advanced Deep Learning (GRU, LSTM and CNN), Basic machine learning (Decision Tree and Logistic Regression) and ensemble-based models (Random Forest, Gradient Boosting, AdaBoost and a custom-developed ensemble). The evaluation carried out using the CICAndMAL2017 dataset shows that these models achieve accuracies ranging from 89.4% to 98.82%. Further, we integrate Local Interpretable Model-agnostic Explanations (LIME) and Shapley Additive Explanations (SHAP) frameworks to generate local and global analyses. Our analysis using the frameworks reveals that key features such as ‘Timestamp’ and ‘Fwd IAT Max’ contribute to the model predictions with high precision. Results obtained demonstrate the effectiveness of the proposed approach for malware classification as well as feature importance. Thus this study emphasizes the importance of explainable AI for improving the interpretability and explainability of models for malware detection, which enhances the security of mobile devices.