To Compare Various Frameworks that Integrate XAI, GANs and LLMs for Dynamic Malware Behavior Analysis

Authors

  • Amar Singh Verma Computer Science and Engineering Dr. K. N. Modi University India
  • Neha Gupta Computer Science and Engineering Dr. K. N. Modi University India
  • Akash Saxena Computer Science and Engineering CITM, Jaipur India
  • Amit Kumar Thakore Computer Science and Engineering Dr. K. N. Modi University India

DOI:

https://doi.org/10.69968/ijisem.2026v5i3426-439

Keywords:

Malware analysis, Explainable AI, Generative Adversarial Networks, Large Language Models, Cybersecurity

Abstract

Modern malware frameworks use advanced evasion techniques that bypass traditional detection methods; thus entail advanced analytical frameworks for comprehensive and robust analysis. This study provides a comparative analysis of several frameworks that utilize Explainable Artificial Intelligence (XAI), Generative Adversarial Networks (GANs), and Large Language Models (LLMs) to provide a dynamic approach to malware behaviour. The review consisted of five key metrics to assess these three frameworks: detection performance, explainability, robustness against adversarial attacks, behavioral interpretation, and automated reporting capabilities. The results indicate that Deep Learning models have attained high accuracy in detect-ing and identifying malicious code, but are not interpretable. The GAN-based frameworks are highly effective in generating adversarial samples for robustness testing. Conversely, LLM-based approaches are highly effective for generating automated forensic reports, but are not yet fully integrated into malware detection workflows. The analysis highlights a research gap pertaining to the lack of integrated frameworks for adversarial analysis, explainability and automated forensic reporting. This study proposes a unified approach of malware analysis incorpo-rating XAI, GAN and LLM to enable the development of more effective malware detection tools with more transparency, deeper analytical insight and advanced forensic decision-making.

References

[1] Djenna, “Artificial intelligence-based malware detection, analysis, and mitigation,” Symmetry, vol. 15, no. 3, pp. 1–21, 2023.

[2] Faruk, M. Rahman, and A. Islam, “Malware detection and prevention using artificial intelligence techniques,” in Proc. IEEE Int. Conf. Big Data, Orlando, FL, USA, 2021, pp. 4635–4642.

[3] Willems, T. Holz, and F. Freiling, “Toward Automated Dynamic Malware Analysis Using Cuckoo Sandbox,” IEEE Security & Privacy, vol. 5, no. 2, pp. 32–39, 2019.

[4] Gautam, R. Kumar, and S. Gupta, “CNN–LSTM Hybrid Model for Enhanced Malware Analysis and Detection,” Procedia Computer Science, vol. 233, pp. 492–503, 2024.

[5] Ghebrebrhan, H. Lee, and M. Park, “Generative adversarial networks for dynamic malware behavior: A comprehensive review, categorization, and analysis,” IEEE Transactions on Artificial Intelligence, 2025.

[6] Goodfellow et al., “Generative Adversarial Networks,” Advances in Neural Information Processing Systems (NeurIPS), vol. 27, pp. 2672–2680, 2014.

[7] Won, Y. Jang, and S. Lee, “PlausMal-GAN: Plausible Malware Train-ing Based on Generative Adversarial Networks for Zero-Day Malware Detection,” IEEE Transactions on Emerging Topics in Computing, vol. 10, no. 3, pp. 1234–1245, 2022.

[8] P. Preeti, S. K. Sharma, and R. Singh, “Generative Adversarial Networks: Introduction, Taxonomy, Variants, and Applications,” Multimedia Tools and Applications, vol. 83, pp. 10215–10248, 2024.

[9] W. Willone, M. Adams, and J. Clarke, “Future of Generative Adversarial Networks for Anomaly Detection in Network Security,” Computers & Security, vol. 139, 2024.

[10] Antonio, R. Delgado, and M. Torres, “Explainability in AI-based behavioral malware detection systems,” Computers & Security, vol. 141, p. 103842, 2024.

[11] Harikha, S. Reddy, and M. Patel, “Explainable Artificial Intelligence (XAI) for Malware Analysis: A Survey of Techniques, Applications, and Challenges,” in Proc. Asian Conference on Innovation in Technology, 2024.

[12] S. M. Lundberg and S. I. Lee, “A Unified Approach to Interpreting Model Predictions,” in Advances in Neural Information Processing Systems, 2017.

[13] M. T. Ribeiro, S. Singh, and C. Guestrin, “Why Should I Trust You? Explaining the Predictions of Any Classifier,” in Proc. ACM SIGKDD Int. Conf. Knowledge Discovery and Data Mining, 2016.

[14] Jelodar, M. Rahman, and T. Nguyen, “Large language models for software security: Code analysis, malware analysis, and reverse engineering,” arXiv preprint arXiv:2504.07137, 2025.

[15] Wickramasekara, F. Breitinger, and M. Scanlon, “Exploring the potential of large language models for improving digital forensic inves-tigation efficiency,” Forensic Science International: Digital Investigation, vol. 52, p. 301859, 2025.

[16] G. Michelet and F. Breitinger, “ChatGPT, Llama, can you write my report? An experiment on assisted digital forensic reports written using large language models,” in Proc. Digital Forensics Research Workshop (DFRWS EU), 2024.

[17] S. Gulmez, A. GorguluKakisim, and I. Sogukpinar, “XRan: Explainable deep learning-based ransomware detection using dynamic analysis,” Computers & Security, vol. 139, p. 103703, 2024.

[18] Baghirov, “A comprehensive investigation into robust malware detec-tion with explainable AI,” Cyber Security and Applications, vol. 3, p. 100072, 2025.

[19] Harikha, K. Ramesh, and P. Rao, “Explainable artificial intelligence for malware analysis: A survey of techniques, applications, and chal-lenges,” in Proc. IEEE Asian Conf. Innovation Technology, 2024.

[20] M. Guven, “A comprehensive review of large language models in cybersecurity,” International Journal of Computational and Experimental Science and Engineering, vol. 10, no. 3, pp. 507–516, 2024.

[21] W. Zhang, J. Liu, and H. Wang, “When large language models meet cybersecurity: A systematic literature review,” arXiv preprint arXiv:2405.03644, 2024.

[22] Farzad, A. Khan, and M. Saleh, “Large language models in cyber-security: State-of-the-art and future research directions,” arXiv preprint arXiv:2402.00891, 2024.

[23] X. Xingzhi, L. Zhang, and Y. Chen, “LAMD: Context-driven Android malware detection and classification with large language models,” in Proc. IEEE Symposium on Security and Privacy Workshops, 2025.

[24] Y. Yeali, T. Kim, and H. Park, “Unleashing malware analysis and understanding with generative AI,” IEEE Security & Privacy, vol. 22, no. 3, pp. 54–63, 2024.

[25] M. Mohamed, A. Al-Khalifa, and R. Hassan, “Generative AI in cy-bersecurity: A comprehensive review of LLM applications and vulner-abilities,” Internet of Things and Cyber-Physical Systems, vol. 5, pp. 120–134, 2025.

[26] Al-Karaki, M. A. Khan, and M. Omar, “Exploring large language models for malware detection: Review, framework design, and counter-measure approaches,” arXiv preprint arXiv:2409.07587, 2024.

[27] P. Dharani, S. Kumar, and A. Nair, “GLEAM: GAN and LLM for evasive adversarial malware,” in Proc. IEEE Int. Conf. Information and Communication Technology Convergence (ICTC), 2023.

[28] R. Reza, A. Ahmed, and M. Patel, “ProveRAG: Provenance-driven vulnerability analysis with retrieval-augmented large language models,” arXiv preprint arXiv:2410.17406, 2024.

[29] D.-O. Won, Y.-N. Jang, and S.-W. Lee, “PlausMal-GAN: Plausible malware training based on generative adversarial networks for analogous zero-day malware detection,” IEEE Transactions on Emerging Topics in Computing, vol. 11, no. 2, pp. 1453–1465, 2023.

[30] Nataraj, S. Karthikeyan, G. Jacob, and B. Manjunath, “Malware Images: Visualization and Automatic Classification,” Proc. ACM VizSec, 2011.

[31] Kolosnjaji, A. Zarras, G. Webster, and C. Eckert, “Deep Learning for Classification of Malware System Call Sequences,” Australasian Joint Conference on Artificial Intelligence, 2016.

[32] Rigaki and S. Garcia, “Bringing a GAN to a Knife Fight: Adapting Malware Communication to Avoid Detection,” IEEE Security & Privacy Workshops, 2018.

[33] T. Fawcett, “An Introduction to ROC Analysis,” Pattern Recognition Letters, 2006.

[34] Gautam et al., “Hybrid Deep Learning for Malware Detection,” Procedia Computer Science, 2024.

Downloads

Published

22-08-2026

Issue

Section

Articles

How to Cite

[1]
Amar Singh Verma et al. 2026. To Compare Various Frameworks that Integrate XAI, GANs and LLMs for Dynamic Malware Behavior Analysis. International Journal of Innovations in Science, Engineering And Management. 5, 3 (Aug. 2026), 426–439. DOI:https://doi.org/10.69968/ijisem.2026v5i3426-439.