{"id":"https://openalex.org/W7131437412","doi":"https://doi.org/10.48550/arxiv.2602.19025","title":"Routing-Aware Explanations for Mixture of Experts Graph Models in Malware Detection","display_name":"Routing-Aware Explanations for Mixture of Experts Graph Models in Malware Detection","publication_year":2026,"publication_date":"2026-02-22","ids":{"openalex":"https://openalex.org/W7131437412","doi":"https://doi.org/10.48550/arxiv.2602.19025"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2602.19025","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.19025","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2602.19025","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5095782617","display_name":"Hossein Shokouhinejad","orcid":"https://orcid.org/0009-0001-6342-2740"},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Shokouhinejad, Hossein","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5126808106","display_name":"Roozbeh Razavi-Far","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Razavi-Far, Roozbeh","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5114151097","display_name":"Griffin Higgins","orcid":"https://orcid.org/0009-0001-2494-8360"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Higgins, Griffin","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5126783067","display_name":"Ali. A Ghorbani","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ghorbani, Ali. A","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5095782617"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.5263000130653381,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.5263000130653381,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12026","display_name":"Explainable Artificial Intelligence (XAI)","score":0.14100000262260437,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.05180000141263008,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.7422999739646912},{"id":"https://openalex.org/keywords/pooling","display_name":"Pooling","score":0.7365999817848206},{"id":"https://openalex.org/keywords/router","display_name":"Router","score":0.6567999720573425},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.5038999915122986},{"id":"https://openalex.org/keywords/node","display_name":"Node (physics)","score":0.4487999975681305},{"id":"https://openalex.org/keywords/control-flow-graph","display_name":"Control flow graph","score":0.41659998893737793}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7422999739646912},{"id":"https://openalex.org/C70437156","wikidata":"https://www.wikidata.org/wiki/Q7228652","display_name":"Pooling","level":2,"score":0.7365999817848206},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6923999786376953},{"id":"https://openalex.org/C2775896111","wikidata":"https://www.wikidata.org/wiki/Q642560","display_name":"Router","level":2,"score":0.6567999720573425},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.5038999915122986},{"id":"https://openalex.org/C62611344","wikidata":"https://www.wikidata.org/wiki/Q1062658","display_name":"Node (physics)","level":2,"score":0.4487999975681305},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.44440001249313354},{"id":"https://openalex.org/C27458966","wikidata":"https://www.wikidata.org/wiki/Q1187693","display_name":"Control flow graph","level":2,"score":0.41659998893737793},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3831999897956848},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3458000123500824},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.33820000290870667},{"id":"https://openalex.org/C143299363","wikidata":"https://www.wikidata.org/wiki/Q900584","display_name":"Attribution","level":2,"score":0.33390000462532043},{"id":"https://openalex.org/C159246509","wikidata":"https://www.wikidata.org/wiki/Q5428725","display_name":"Factor graph","level":3,"score":0.3287000060081482},{"id":"https://openalex.org/C75608658","wikidata":"https://www.wikidata.org/wiki/Q44395","display_name":"Pascal (unit)","level":2,"score":0.2806999981403351},{"id":"https://openalex.org/C16311509","wikidata":"https://www.wikidata.org/wiki/Q4148050","display_name":"Dependency graph","level":3,"score":0.2696000039577484},{"id":"https://openalex.org/C146380142","wikidata":"https://www.wikidata.org/wiki/Q1137726","display_name":"Directed graph","level":2,"score":0.2567000091075897},{"id":"https://openalex.org/C149810388","wikidata":"https://www.wikidata.org/wiki/Q5374873","display_name":"Emulation","level":2,"score":0.25279998779296875}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2602.19025","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.19025","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2602.19025","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.19025","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.43316203355789185,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Mixture-of-Experts":[0],"(MoE)":[1],"offers":[2],"flexible":[3],"graph":[4,12,23],"reasoning":[5],"by":[6,57],"combining":[7,178],"multiple":[8,47],"views":[9],"of":[10,189],"a":[11,14,58,64,92,105],"through":[13],"learned":[15],"router.":[16],"We":[17],"investigate":[18],"routing-aware":[19],"explanations":[20,109],"for":[21,192],"MoE":[22,156,190],"models":[24],"in":[25,68,81],"malware":[26,193],"detection":[27,159],"using":[28,119],"control":[29],"flow":[30],"graphs":[31],"(CFGs).":[32],"Our":[33],"architecture":[34],"builds":[35],"diversity":[36,184],"at":[37],"two":[38],"levels.":[39],"At":[40,83],"the":[41,84,101,120,124,150,154,174,187],"node":[42,74,180],"level,":[43,86],"each":[44,89,129],"layer":[45],"computes":[46],"neighborhood":[48],"statistics":[49],"and":[50,63,117,132,147,177],"fuses":[51],"them":[52],"with":[53,112,182],"an":[54],"MLP,":[55],"guided":[56],"degree":[59],"reweighting":[60],"factor":[61],"rho":[62],"pooling":[65],"choice":[66],"lambda":[67],"{mean,":[69],"std,":[70],"max},":[71],"producing":[72],"distinct":[73],"representations":[75],"that":[76,100,172],"capture":[77],"complementary":[78],"structural":[79],"cues":[80],"CFGs.":[82],"readout":[85],"six":[87],"experts,":[88],"tied":[90],"to":[91],"specific":[93],"(rho,":[94],"lambda)":[95],"view,":[96],"output":[97],"graph-level":[98],"logits":[99],"router":[102,121,175],"weights":[103],"into":[104],"final":[106],"prediction.":[107],"Post-hoc":[108],"are":[110],"generated":[111],"edge-level":[113],"attributions":[114,165],"per":[115],"expert":[116,130],"aggregated":[118],"gates":[122],"so":[123],"rationale":[125],"reflects":[126],"both":[127],"what":[128],"highlights":[131],"how":[133],"strongly":[134],"it":[135],"is":[136],"selected.":[137],"Evaluated":[138],"against":[139],"single-expert":[140],"GNN":[141],"baselines":[142],"such":[143],"as":[144],"GCN,":[145],"GIN,":[146],"GAT":[148],"on":[149],"same":[151],"CFG":[152],"dataset,":[153],"proposed":[155],"achieves":[157],"strong":[158],"accuracy":[160],"while":[161],"yielding":[162],"stable,":[163],"faithful":[164],"under":[166],"sparsity-based":[167],"perturbations.":[168],"The":[169],"results":[170],"indicate":[171],"making":[173],"explicit":[176],"multi-statistic":[179],"encoding":[181],"expert-level":[183],"can":[185],"improve":[186],"transparency":[188],"decisions":[191],"analysis.":[194]},"counts_by_year":[],"updated_date":"2026-02-26T06:34:08.959763","created_date":"2026-02-26T00:00:00"}
