An Explainable Attention-Enhanced Deep Learning Model for Memory-Forensic Malware Detection
Memory-forensic malware detection can identify malicious activity from volatile memory and complement disk-based analysis. However, results are difficult to compare when datasets, preprocessing, model settings, and evaluation protocols differ. We propose a hybrid convolutional neural network and bidirectional gated recurrent unit (CNN–BiGRU) model with additive attention for binary malware detection on the CIC-MalMem-2022 dataset. It was compared with a one-dimensional convolutional neural network (CNN1D), bidirectional gated recurrent unit (BiGRU), bidirectional long short-term memory (BiLSTM), and Transformer models under a common protocol. All models used the same data partitions, preprocessing, optimization settings, training budget, and five training seeds. On the held-out test set of 8790 samples, the proposed model achieved 99.97% ± 0.04% accuracy, 99.97% ± 0.04% F1-score, and a Matthews correlation coefficient (MCC) of 99.93% ± 0.07%. Mean false-positive and false-negative rates (FPR and FNR) were 0.03% and 0.04%, respectively. Corrected pairwise tests did not establish statistically significant differences. SHapley Additive exPlanations (SHAP) and Local Interpretable Model-agnostic Explanations (LIME) showed a mean top-10 Jaccard overlap of 0.651 ± 0.136. SHAP required 7.96 s, compared with 35.38 s for LIME, and the proposed model had a 0.060 ms per-sample inference latency.
Authors
- Rajiv R. P. Singh (ORCID: https://orcid.org/0000-0003-1808-3433)
- Nsikak Pius Owoh (ORCID: https://orcid.org/0000-0002-4840-9345)
- Rajesh Prasad (ORCID: https://orcid.org/0000-0002-3456-6980)
- Moses Ashawa (ORCID: https://orcid.org/0000-0002-1016-0791)
- John Adejoh (ORCID: https://orcid.org/0009-0007-6133-6092)
- Chibuzor Ezeamasiobi
Institutions
- Glasgow Caledonian University (GB)
- African Institute of Science and Technology (NG)
- Ajay Kumar Garg Engineering College (IN)
Publication Details
- Journal
- Sensors
- Published
- 2026-10-09
- DOI
- https://doi.org/10.3390/s26206380
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00