{"id":"https://openalex.org/W3198931783","doi":"https://doi.org/10.1109/ijcnn52387.2021.9533803","title":"A Semi-Automated Explainability-Driven Approach for Malware Analysis through Deep Learning","display_name":"A Semi-Automated Explainability-Driven Approach for Malware Analysis through Deep Learning","publication_year":2021,"publication_date":"2021-07-18","ids":{"openalex":"https://openalex.org/W3198931783","doi":"https://doi.org/10.1109/ijcnn52387.2021.9533803","mag":"3198931783"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn52387.2021.9533803","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn52387.2021.9533803","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5080298186","display_name":"Giacomo Iadarola","orcid":"https://orcid.org/0000-0001-7060-6233"},"institutions":[{"id":"https://openalex.org/I4210130157","display_name":"Institute of Informatics and Telematics","ror":"https://ror.org/02gdcn153","country_code":"IT","type":"facility","lineage":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"]},{"id":"https://openalex.org/I4210155236","display_name":"National Research Council","ror":"https://ror.org/04zaypm56","country_code":"IT","type":"funder","lineage":["https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Giacomo Iadarola","raw_affiliation_strings":["Institute of Informatics and Telematics, National Research Council of Italy, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"Institute of Informatics and Telematics, National Research Council of Italy, Pisa, Italy","institution_ids":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5080873651","display_name":"Rosangela Casolare","orcid":null},"institutions":[{"id":"https://openalex.org/I129627893","display_name":"University of Molise","ror":"https://ror.org/04z08z627","country_code":"IT","type":"education","lineage":["https://openalex.org/I129627893"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Rosangela Casolare","raw_affiliation_strings":["University of Molise Pesche (IS), Italy"],"affiliations":[{"raw_affiliation_string":"University of Molise Pesche (IS), Italy","institution_ids":["https://openalex.org/I129627893"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101546784","display_name":"Fabio Martinelli","orcid":"https://orcid.org/0000-0002-6721-9395"},"institutions":[{"id":"https://openalex.org/I4210155236","display_name":"National Research Council","ror":"https://ror.org/04zaypm56","country_code":"IT","type":"funder","lineage":["https://openalex.org/I4210155236"]},{"id":"https://openalex.org/I4210130157","display_name":"Institute of Informatics and Telematics","ror":"https://ror.org/02gdcn153","country_code":"IT","type":"facility","lineage":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Fabio Martinelli","raw_affiliation_strings":["Institute of Informatics and Telematics, National Research Council of Italy, Pisa, Italy"],"affiliations":[{"raw_affiliation_string":"Institute of Informatics and Telematics, National Research Council of Italy, Pisa, Italy","institution_ids":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5023695406","display_name":"Francesco Mercaldo","orcid":"https://orcid.org/0000-0002-9425-1657"},"institutions":[{"id":"https://openalex.org/I4210130157","display_name":"Institute of Informatics and Telematics","ror":"https://ror.org/02gdcn153","country_code":"IT","type":"facility","lineage":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"]},{"id":"https://openalex.org/I129627893","display_name":"University of Molise","ror":"https://ror.org/04z08z627","country_code":"IT","type":"education","lineage":["https://openalex.org/I129627893"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Francesco Mercaldo","raw_affiliation_strings":["University of Molise & IIT-CNR, Campobasso, Italy"],"affiliations":[{"raw_affiliation_string":"University of Molise & IIT-CNR, Campobasso, Italy","institution_ids":["https://openalex.org/I129627893","https://openalex.org/I4210130157"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025775168","display_name":"Christian Peluso","orcid":"https://orcid.org/0009-0001-2972-4374"},"institutions":[{"id":"https://openalex.org/I129627893","display_name":"University of Molise","ror":"https://ror.org/04z08z627","country_code":"IT","type":"education","lineage":["https://openalex.org/I129627893"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Christian Peluso","raw_affiliation_strings":["University of Molise Pesche (IS), Italy"],"affiliations":[{"raw_affiliation_string":"University of Molise Pesche (IS), Italy","institution_ids":["https://openalex.org/I129627893"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5004599844","display_name":"Antonella Santone","orcid":"https://orcid.org/0000-0002-2634-4456"},"institutions":[{"id":"https://openalex.org/I129627893","display_name":"University of Molise","ror":"https://ror.org/04z08z627","country_code":"IT","type":"education","lineage":["https://openalex.org/I129627893"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Antonella Santone","raw_affiliation_strings":["Sciences University of Molise, Campobasso, Italy"],"affiliations":[{"raw_affiliation_string":"Sciences University of Molise, Campobasso, Italy","institution_ids":["https://openalex.org/I129627893"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5080298186"],"corresponding_institution_ids":["https://openalex.org/I4210130157","https://openalex.org/I4210155236"],"apc_list":null,"apc_paid":null,"fwci":1.3713,"has_fulltext":false,"cited_by_count":13,"citation_normalized_percentile":{"value":0.81548343,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9900000095367432,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9865999817848206,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8927163481712341},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8277122974395752},{"id":"https://openalex.org/keywords/interpretability","display_name":"Interpretability","score":0.7374005317687988},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.6202418208122253},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5961548686027527},{"id":"https://openalex.org/keywords/android-malware","display_name":"Android malware","score":0.5917736887931824},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5758302807807922},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.4690350294113159},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.46242231130599976},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.45898258686065674},{"id":"https://openalex.org/keywords/cryptovirology","display_name":"Cryptovirology","score":0.4543610215187073},{"id":"https://openalex.org/keywords/mobile-malware","display_name":"Mobile malware","score":0.4527372419834137},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4265998899936676},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.09318068623542786}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8927163481712341},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8277122974395752},{"id":"https://openalex.org/C2781067378","wikidata":"https://www.wikidata.org/wiki/Q17027399","display_name":"Interpretability","level":2,"score":0.7374005317687988},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.6202418208122253},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5961548686027527},{"id":"https://openalex.org/C2989133298","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android malware","level":3,"score":0.5917736887931824},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5758302807807922},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.4690350294113159},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.46242231130599976},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.45898258686065674},{"id":"https://openalex.org/C84525096","wikidata":"https://www.wikidata.org/wiki/Q3506050","display_name":"Cryptovirology","level":3,"score":0.4543610215187073},{"id":"https://openalex.org/C2780967490","wikidata":"https://www.wikidata.org/wiki/Q1291200","display_name":"Mobile malware","level":3,"score":0.4527372419834137},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4265998899936676},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.09318068623542786},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn52387.2021.9533803","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn52387.2021.9533803","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2021 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.6299999952316284,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":22,"referenced_works":["https://openalex.org/W2010065958","https://openalex.org/W2060537671","https://openalex.org/W2122672392","https://openalex.org/W2152149943","https://openalex.org/W2538940504","https://openalex.org/W2566681038","https://openalex.org/W2787931603","https://openalex.org/W2807026630","https://openalex.org/W2810666735","https://openalex.org/W2895401392","https://openalex.org/W2962688774","https://openalex.org/W2962858109","https://openalex.org/W2963095307","https://openalex.org/W2997180912","https://openalex.org/W3023854111","https://openalex.org/W3046343025","https://openalex.org/W3097730806","https://openalex.org/W3118864452","https://openalex.org/W3120704879","https://openalex.org/W3125596609","https://openalex.org/W3211182750","https://openalex.org/W6748061875"],"related_works":["https://openalex.org/W3195312353","https://openalex.org/W4383468964","https://openalex.org/W3200508744","https://openalex.org/W4200054778","https://openalex.org/W2233081671","https://openalex.org/W2507113366","https://openalex.org/W2717179875","https://openalex.org/W4249118297","https://openalex.org/W2311926078","https://openalex.org/W4312234627"],"abstract_inverted_index":{"Cybercriminals":[0],"are":[1,20],"continually":[2],"working":[3],"to":[4,10,24,59,82,96,100,129,148],"develop":[5],"increasingly":[6],"aggressive":[7],"malicious":[8,73,146,155],"code":[9,42,95],"steal":[11],"sensitive":[12],"and":[13,65,98,120],"private":[14],"information":[15],"from":[16],"mobile":[17],"devices.":[18],"Antimalware":[19],"not":[21,32],"always":[22],"able":[23],"detect":[25,60],"all":[26],"threats,":[27],"especially":[28],"when":[29],"they":[30],"do":[31],"have":[33],"previous":[34],"knowledge":[35],"of":[36,71,94,104,138,165,170,174,184],"the":[37,61,87,92,102,131,136,141,150,154,168,182,191],"malware":[38,41,62,110],"signature.":[39],"Moreover,":[40],"analysis":[43],"remains":[44],"a":[45,56,69,124,171],"time-consuming":[46],"process":[47],"for":[48,86,109],"security":[49,88,151],"analysts.":[50],"In":[51],"this":[52,78],"regard,":[53],"we":[54],"propose":[55],"method":[57,160],"aimed":[58,128],"belonging":[63,132],"family":[64,111],"automatically":[66],"pointing":[67],"out":[68,144],"subset":[70],"potentially":[72,145],"classes.":[74],"The":[75,158],"rationale":[76],"behind":[77],"work":[79],"aims":[80],"(i)":[81],"save":[83],"valuable":[84],"time":[85],"analyst":[89],"by":[90],"decreasing":[91],"amount":[93],"analyse,":[97],"(ii)":[99],"improve":[101],"interpretability":[103],"image-based":[105],"deep":[106,125,192],"learning":[107,126,193],"model":[108,127,194],"detection.":[112],"We":[113],"represent":[114],"an":[115,118,162],"application":[116],"as":[117],"image":[119],"classify":[121],"it":[122],"with":[123],"predict":[130],"family;":[133],"then,":[134],"exploiting":[135],"use":[137,183],"activation":[139,185],"maps,":[140],"approach":[142],"points":[143],"classes":[147],"help":[149],"analysts":[152],"in":[153,167],"behaviour":[156],"recognition.":[157],"proposed":[159],"obtains":[161],"overall":[163],"accuracy":[164],"0.944":[166],"evaluation":[169],"dataset":[172],"composed":[173],"8430":[175],"real-world":[176],"Android":[177],"malware,":[178],"showing":[179],"also":[180],"that":[181],"maps":[186],"can":[187],"provide":[188],"explainability":[189],"about":[190],"decision.":[195]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
