On the Consistency of GNN Explanations for Malware Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Shokouhinejad, Hossein, Higgins, Griffin, Razavi-Far, Roozbeh, Mohammadian, Hesamodin, Ghorbani, Ali A.
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909747439992832
author Shokouhinejad, Hossein
Higgins, Griffin
Razavi-Far, Roozbeh
Mohammadian, Hesamodin
Ghorbani, Ali A.
author_facet Shokouhinejad, Hossein
Higgins, Griffin
Razavi-Far, Roozbeh
Mohammadian, Hesamodin
Ghorbani, Ali A.
contents Control Flow Graphs (CFGs) are critical for analyzing program execution and characterizing malware behavior. With the growing adoption of Graph Neural Networks (GNNs), CFG-based representations have proven highly effective for malware detection. This study proposes a novel framework that dynamically constructs CFGs and embeds node features using a hybrid approach combining rule-based encoding and autoencoder-based embedding. A GNN-based classifier is then constructed to detect malicious behavior from the resulting graph representations. To improve model interpretability, we apply state-of-the-art explainability techniques, including GNNExplainer, PGExplainer, and CaptumExplainer, the latter is utilized three attribution methods: Integrated Gradients, Guided Backpropagation, and Saliency. In addition, we introduce a novel aggregation method, called RankFusion, that integrates the outputs of the top-performing explainers to enhance the explanation quality. We also evaluate explanations using two subgraph extraction strategies, including the proposed Greedy Edge-wise Composition (GEC) method for improved structural coherence. A comprehensive evaluation using accuracy, fidelity, and consistency metrics demonstrates the effectiveness of the proposed framework in terms of accurate identification of malware samples and generating reliable and interpretable explanations.
format Preprint
id arxiv_https___arxiv_org_abs_2504_16316
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle On the Consistency of GNN Explanations for Malware Detection
Shokouhinejad, Hossein
Higgins, Griffin
Razavi-Far, Roozbeh
Mohammadian, Hesamodin
Ghorbani, Ali A.
Cryptography and Security
Artificial Intelligence
Machine Learning
Control Flow Graphs (CFGs) are critical for analyzing program execution and characterizing malware behavior. With the growing adoption of Graph Neural Networks (GNNs), CFG-based representations have proven highly effective for malware detection. This study proposes a novel framework that dynamically constructs CFGs and embeds node features using a hybrid approach combining rule-based encoding and autoencoder-based embedding. A GNN-based classifier is then constructed to detect malicious behavior from the resulting graph representations. To improve model interpretability, we apply state-of-the-art explainability techniques, including GNNExplainer, PGExplainer, and CaptumExplainer, the latter is utilized three attribution methods: Integrated Gradients, Guided Backpropagation, and Saliency. In addition, we introduce a novel aggregation method, called RankFusion, that integrates the outputs of the top-performing explainers to enhance the explanation quality. We also evaluate explanations using two subgraph extraction strategies, including the proposed Greedy Edge-wise Composition (GEC) method for improved structural coherence. A comprehensive evaluation using accuracy, fidelity, and consistency metrics demonstrates the effectiveness of the proposed framework in terms of accurate identification of malware samples and generating reliable and interpretable explanations.
title On the Consistency of GNN Explanations for Malware Detection
topic Cryptography and Security
Artificial Intelligence
Machine Learning
url https://arxiv.org/abs/2504.16316