A Hybrid Static–Dynamic Malware Analysis Framework Using Interpretable Neural Network

Kismat Chhillar, Dr. Deepak Tomar, Alok Verma · INTERANTIONAL JOURNAL OF SCIENTIFIC RESEARCH IN ENGINEERING AND MANAGEMENT · 2025

Abstract - Malware is constantly evolving, using a mix of polymorphism and stealth techniques that can outsmart traditional detection systems. In this paper, we introduce a hybrid framework for analyzing malware that merges static code and file-level features with dynamic behavioral data. This combined approach is then processed through an interpretable ensemble of neural networks. Our design focuses on achieving high detection rates while also providing explanations that are easy for security analysts to understand, aiding their decision-making process. We outline the architecture, the pipelines for feature extraction, the choices made in model design (including attention mechanisms and post-hoc explanation tools like SHAP/LIME and layer-wise relevance propagation), as well as our training and evaluation methods, and how we stack up against baseline models. Our experiments, which involved both malware and benign datasets, show that this hybrid interpretable method enhances detection metrics (like accuracy, F1 score, and AUC) while also delivering actionable insights that resonate with domain expertise. We wrap up by discussing the limitations, considerations for deployment, and exciting avenues for improving robustness and scalability. Key Words: Malware Analysis, hybrid analysis, static analysis, dynamic analysis, interpretable neural networks, explainable AI, malware detection, feature fusion, attention mechanisms.

Read the paper · More papers on PaperTik