Design of an improved validation model with dynamic attribution and graph-based anomaly analysis for malware forensics
Abstract The increasing sophistication and polymorphic nature of malware necessitate intelligent, adaptive forensic frameworks that go beyond static rule-based detection. In particular, the traditional techniques for evidence collection and analysis would not catch the evolving behaviors of advanced malware, lack context-aware feature weighting, and fail to maintain accuracy under concept drifts or temporal drifts. Such limitations thus also impede timely threats attribution and malware family discovery processes. To bridge these gaps, we propose an iterative framework for evidence collection and malware activity analysis by utilizing machine learning and explainable AI paradigms. The framework integrates five newly proposed modules: (1) DynaTrace-XAI employs SHAP-based attribution for real-time reweighting of forensic features, dynamically enhancing the significance of impactful indicators in the process. (2) TempNet V introduces temporal ensemble validation at daily, weekly, and monthly levels, deploying heterogeneous models (e.g. LSTM, RF) to counter data drifts dependent on time. (3) GRAFIN-A reconstructs execution traces into behavior graphs through Graph Attention Networks, which are then subjected to unsupervised clustering with DBSCAN and anomaly detection through graph similarity scoring methods. (4) RiskActive-L blends anomaly-derived risk scores with model uncertainty to prioritize more unlabeled high-risk samples within an active learning loop, strongly improving data labeling efficiency. (5) DriftMon-F implements a forensic-context-aware drift detection mechanism via KL divergence and meta-log correlation to trigger timely retraining in the event of contextual shifts. In concert, these modules constitute a closed-loop system whereby evidence assignment, model validation, clustering, sample selection, and drift handling processes become continuously refined. Empirical evaluations demonstrate the empirical achievements: 15% increase in F1-score, 23% gain in variant detection, reduction of 45% in labeling effort, and 70% reduction in drift recovery lag, leading to considerable advances in adaptive malware forensics.
Authors
- Rijvan Beg (ORCID: https://orcid.org/0009-0008-6895-3576)
- Rajesh Kumar Pateriya (ORCID: https://orcid.org/0000-0001-7163-0024)
- Surendra Solanki (ORCID: https://orcid.org/0000-0002-5067-7621)
- Deepak Singh Tomar (ORCID: https://orcid.org/0000-0001-9025-1679)
Institutions
- SRM University (IN)
- Manipal University Jaipur
- Maulana Azad National Institute of Technology (IN)
Publication Details
- Journal
- Discover Computing
- Published
- 2026-10-06
- DOI
- https://doi.org/10.1007/s10791-026-10529-8
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00