Evidence-Constrained Explainable Malware Detection Using Large Language Models
Students & Supervisors
Student Authors
Supervisors
Abstract
Machine learning-based malware detection systems achieve high accuracy but lack transparent, auditable ex- planations necessary for analyst trust and incident response. While Large Language Models (LLMs) can generate natural- language reasoning, unconstrained generation produces hallu- cinated claims and unverifiable assertions. This work presents Constrained Evidence Reasoning (CER), a complete implementa- tion of evidence-grounded explainable malware detection. CER integrates an XGBoost classifier trained on 2,568 static PE features with a rule-based evidence extraction layer that de- terministically derives human-interpretable artifacts (suspicious imports, entropy anomalies, packing indicators) from feature vectors. Explanations are generated via LLMs operating strictly over extracted evidence, with dual-layer constraint enforcement at prompt construction and post-generation validation. The authors define computable metrics for faithfulness, hallucination rate, and behavioral coverage, achieving strong empirical results on 1,000 labeled test samples. Results demonstrate that CER maintains baseline detection performance while producing ver- ifiable, evidence-anchored explanations suitable for operational security workflows.
Keywords
Publication Details
- DOI: 10.1109/QPAIN69676.2026.11546322
- Type of Publication:
- Conference Name: 2026 IEEE 2nd International Conference on Quantum Photonics, Artificial Intelligence & Networking (QPAIN)
- Date of Conference: 16/04/2026 - 16/04/2026
- Venue: Chittagong, Bangladesh