Design of an improved validation model with dynamic attribution and graph-based anomaly analysis for malware forensics

Abstract The increasing sophistication and polymorphic nature of malware necessitate intelligent, adaptive forensic frameworks that go beyond static rule-based detection. In particular, the traditional techniques for evidence collection and analysis would not catch the evolving behaviors of advanced malware, lack context-aware feature weighting, and fail to maintain accuracy under concept drifts or temporal drifts. Such limitations thus also impede timely threats attribution and malware family discovery processes. To bridge these gaps, we propose an iterative framework for evidence collection and malware activity analysis by utilizing machine learning and explainable AI paradigms. The framework integrates five newly proposed modules: (1) DynaTrace-XAI employs SHAP-based attribution for real-time reweighting of forensic features, dynamically enhancing the significance of impactful indicators in the process. (2) TempNet V introduces temporal ensemble validation at daily, weekly, and monthly levels, deploying heterogeneous models (e.g. LSTM, RF) to counter data drifts dependent on time. (3) GRAFIN-A reconstructs execution traces into behavior graphs through Graph Attention Networks, which are then subjected to unsupervised clustering with DBSCAN and anomaly detection through graph similarity scoring methods. (4) RiskActive-L blends anomaly-derived risk scores with model uncertainty to prioritize more unlabeled high-risk samples within an active learning loop, strongly improving data labeling efficiency. (5) DriftMon-F implements a forensic-context-aware drift detection mechanism via KL divergence and meta-log correlation to trigger timely retraining in the event of contextual shifts. In concert, these modules constitute a closed-loop system whereby evidence assignment, model validation, clustering, sample selection, and drift handling processes become continuously refined. Empirical evaluations demonstrate the empirical achievements: 15% increase in F1-score, 23% gain in variant detection, reduction of 45% in labeling effort, and 70% reduction in drift recovery lag, leading to considerable advances in adaptive malware forensics.

Authors

Institutions

Publication Details

Journal
Discover Computing
Published
2026-10-06
DOI
https://doi.org/10.1007/s10791-026-10529-8
Primary Topic
Advanced Malware Detection Techniques
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

Design of an improved validation model with dynamic attribution and graph-based anomaly analysis for malware forensics

Rijvan Beg, Rajesh Kumar Pateriya, Surendra Solanki, Deepak Singh Tomar
Discover Computing
Advanced Malware Detection Techniques
article

Design of an improved validation model with dynamic attribution and graph-based anomaly analysis for malware forensics

Rijvan Beg, Rajesh Kumar Pateriya, Surendra Solanki, Deepak Singh Tomar
article en

Abstract

Abstract The increasing sophistication and polymorphic nature of malware necessitate intelligent, adaptive forensic frameworks that go beyond static rule-based detection. In particular, the traditional techniques for evidence collection and analysis would not catch the evolving behaviors of advanced malware, lack context-aware feature weighting, and fail to maintain accuracy under concept drifts or temporal drifts. Such limitations thus also impede timely threats attribution and malware family discovery processes. To bridge these gaps, we propose an iterative framework for evidence collection and malware activity analysis by utilizing machine learning and explainable AI paradigms. The framework integrates five newly proposed modules: (1) DynaTrace-XAI employs SHAP-based attribution for real-time reweighting of forensic features, dynamically enhancing the significance of impactful indicators in the process. (2) TempNet V introduces temporal ensemble validation at daily, weekly, and monthly levels, deploying heterogeneous models (e.g. LSTM, RF) to counter data drifts dependent on time. (3) GRAFIN-A reconstructs execution traces into behavior graphs through Graph Attention Networks, which are then subjected to unsupervised clustering with DBSCAN and anomaly detection through graph similarity scoring methods. (4) RiskActive-L blends anomaly-derived risk scores with model uncertainty to prioritize more unlabeled high-risk samples within an active learning loop, strongly improving data labeling efficiency. (5) DriftMon-F implements a forensic-context-aware drift detection mechanism via KL divergence and meta-log correlation to trigger timely retraining in the event of contextual shifts. In concert, these modules constitute a closed-loop system whereby evidence assignment, model validation, clustering, sample selection, and drift handling processes become continuously refined. Empirical evaluations demonstrate the empirical achievements: 15% increase in F1-score, 23% gain in variant detection, reduction of 45% in labeling effort, and 70% reduction in drift recovery lag, leading to considerable advances in adaptive malware forensics.

Discover ComputingVol. 29(1)
SRM University (IN), Manipal University Jaipur, Maulana Azad National Institute of Technology (IN)
Openalex Percentile: Top 11%
Advanced Malware Detection Techniques
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.