Malware Analysis Using Hashing and Explainable AI: A Comparative Study of LIME and SHAP Techniques
Ujan Pradhan, K M Navaneeth, M.N. Aditya · 2025
Malware analysis stands out as one of the major tasks in cybersecurity as it involves the identification and classification of malware specimens that could potentially pose threats. The traditional methods of malware detection have been effective, although the transparency level in decision-making is very low. Thus, this paper proposes the combination of hashing techniques with explainable AI (XAI) methods to make the output of machine learning models more understandable in malware classification. Specifically, this work introduces a new integration of SHAP and LIME to address the “black-box” problem of providing both global and local explanations. SHAP points to the global importance of opcodes and n-grams, LIME provides instance-specific insights with explanatory power beyond Random Forest classifiers trained over TF-IDF vectorized textual features extracted from malware binaries. The results illustrate not only how XAI methods explain the model decision-making process but also how they contribute to identifying the most important features for malware classification. This new approach enables the creation of even more transparent and efficient AI-driven cybersecurity solutions, thus obviating important challenges in malware detection.