API Call-Based Windows Malware Detection Using CNN-LSTM-Attention and Explainable SHAP

Authors

  • Febby Viona Fakultas Teknologi dan Desain, Universitas Bunda Mulia, Indonesia
  • Puguh Hiskiawan Fakultas Teknologi dan Desain, Universitas Bunda Mulia, Indonesia

DOI:

10.33395/sinkron.v10i4.16646

Keywords:

API Call Sequence; CNN-LSTM-Attention; Digital Forensics; Explainable AI; Malware Detection; SHAP

Abstract

The Windows operating system remains a primary target for cyberattacks, with modern malicious software increasingly relying on obfuscation, packing, and polymorphism to evade signature-based detection. This research addresses this challenge by developing a hybrid Convolutional Neural Network, Long Short-Term Memory, and Multi-Head Attention model to classify Windows malicious software from sequences of the first 100 dynamic Application Programming Interface calls. Drawing on the Kaggle "Malware Analysis Datasets: API Call Sequences" refined to 13,206 unique samples with a severe class imbalance of 95.36% malware versus 4.64% benign, the model employs a class-weighting strategy to ensure robust learning. Rigorous evaluation through five-fold cross-validation demonstrates that the proposed architecture achieves a mean Area Under the Receiver Operating Characteristic Curve of 0.9562 (± 0.0186) and an accuracy of 95.78% (± 1.05%). Ablation studies confirm that the Multi-Head Attention mechanism is statistically indispensable (p < 0.05), as its removal degrades performance to an Area Under the Receiver Operating Characteristic Curve of 0.9073. While competitive with ensemble baselines such as Random Forest and XGBoost, the proposed approach provides superior interpretability by integrating SHapley Additive Explanations. This enables local and global forensic accountability by pinpointing critical temporal execution windows specifically at steps t1, t50, and t­75 that drive malicious predictions. These results indicate that combining hybrid deep learning with post-hoc explainability produces malware detection that is both robust and forensically transparent.

GS Cited Analysis

Downloads

Download data is not yet available.

References

Aboaoja, F. A., Zainal, A., Ghaleb, F. A., Al-rimy, B. A. S., Eisa, T. A. E., & Elnour, A. A. H. (2022). Malware Detection Issues, Challenges, and Future Directions: A Survey. Applied Sciences (Switzerland), 12(17). https://doi.org/10.3390/app12178482

Akhtar, M. S., & Feng, T. (2022). Detection of Malware by Deep Learning as CNN-LSTM Machine Learning Techniques in Real Time. Symmetry, 14(11). https://doi.org/10.3390/sym14112308

Bensaoud, A., & Kalita, J. (2024). CNN-LSTM and transfer learning models for malware classification based on opcodes and API calls. Knowledge-Based Systems, 290. https://doi.org/10.1016/j.knosys.2024.111543

Cannarile, A., Dentamaro, V., Galantucci, S., Iannacone, A., Impedovo, D., & Pirlo, G. (2022). Comparing Deep Learning and Shallow Learning Techniques for API Calls Malware Prediction: A Study. Applied Sciences (Switzerland), 12(3). https://doi.org/10.3390/app12031645

Catak, F. O., Yazi, A. F., Elezaj, O., & Ahmed, J. (2020). Deep learning based Sequential model for malware analysis using Windows exe API Calls. PeerJ Computer Science, 6, 1–23. https://doi.org/10.7717/PEERJ-CS.285

Galli, A., La Gatta, V., Moscato, V., Postiglione, M., & Sperlì, G. (2024). Explainability in AI-based behavioral malware detection systems. Computers and Security, 141(March). https://doi.org/10.1016/j.cose.2024.103842

Gyamfi, N. K., Goranin, N., Ceponis, D., & Čenys, H. A. (2023). Automated System-Level Malware Detection Using Machine Learning: A Comprehensive Review. Applied Sciences (Switzerland), 13(21). https://doi.org/10.3390/app132111908

Hermosilla, P., Díaz, M., Berríos, S., & Allende-Cid, H. (2025). Use of Explainable Artificial Intelligence for Analyzing and Explaining Intrusion Detection Systems. Computers, 14(5), 1–25. https://doi.org/10.3390/computers14050160

Hiskiawan, P., Chen, C.-C., & Ye, Z.-K. (2023). Processing of electrical resistivity tomography data using convolutional neural network in ERT-NET architectures. Arabian Journal of Geosciences, 16(10), 1–14. https://doi.org/10.1007/s12517-023-11690-w

Hiskiawan, P., Geasela, Y. M., Heryanto, H., Stephanie, E., Ardianti, M., & Sukarno, F. A. (2025). Trustworthy Data Science Framework for Non-Invasive Nutritional Screening Using Computer Vision. 2025 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS), 1743–1748. https://doi.org/10.1109/ICIMCIS68501.2025.11327268

Hiskiawan, P., Sari, M. K., Siregar, R. E., Valencia, N. A., & Wijayanti, T. P. (2026). A Deep Learning Data Fusion Approach for Prostate MRI Zonal Segmentation Using Dual-Channel U-Net with T2 and ADC Images. 2026 International Conference on Current Research in Artificial Intelligence and Data Science (ICCRAIDS), 1, 1–7. https://doi.org/10.1109/ICCRAIDS67816.2026.11519671

Hiskiawan, P., Wijayanti, T. P., Heryanto, H., Everlin, S., Yasodhara, S. A., & Alexander, D. (2025). Mel-Frequency Cepstral Coefficients and Neural Networks for Indonesian Traditional Music Recognition. 2025 International Conference on Informatics, Multimedia, Cyber and Information System (ICIMCIS), 1707–1712. https://doi.org/10.1109/ICIMCIS68501.2025.11327436

Li, C., Lv, Q., Li, N., Wang, Y., Sun, D., & Qiao, Y. (2022). Computers & Security A novel deep framework for dynamic malware detection based on API sequence intrinsic features. 116. https://doi.org/10.1016/j.cose.2022.102686

Liang, J., Shen, J., Wang, P., Liang, F., & Deng, X. (2026). Dynamic Malware Detection Method Based on API Multiple Subsequences. Computers, Materials and Continua, 87(1). https://doi.org/10.32604/cmc.2025.073076

Lundberg, S. M., Erion, G., Chen, H., DeGrave, A., Prutkin, J. M., Nair, B., Katz, R., Himmelfarb, J., Bansal, N., & Lee, S. I. (2020). From local explanations to global understanding with explainable AI for trees. Nature Machine Intelligence, 2(1), 56–67. https://doi.org/10.1038/s42256-019-0138-9

Lundberg, S. M., & Lee, S. I. (2017). A unified approach to interpreting model predictions. Advances in Neural Information Processing Systems, 2017-Decem(Section 2), 4766–4775.

Maniriho, P., Mahmood, A. N., & Chowdhury, M. J. M. (2023). API-MalDetect: Automated malware detection framework for windows based on API calls and deep learning techniques. Journal of Network and Computer Applications, 218(June), 103704. https://doi.org/10.1016/j.jnca.2023.103704

Maniriho, P., Mahmood, A. N., & Chowdhury, M. J. M. (2024). A systematic literature review on Windows malware detection: Techniques, research issues, and future directions. Journal of Systems and Software, 209(December 2023), 111921. https://doi.org/10.1016/j.jss.2023.111921

Manthena, H., Kimmel, J. C., Abdelsalam, M., & Gupta, M. (2023). Analyzing and Explaining Black-Box Models for Online Malware Detection. IEEE Access, 11(March), 25237–25252. https://doi.org/10.1109/ACCESS.2023.3255176

Manthena, H., Shajarian, S., Kimmell, J. C., Abdelsalam, M., Khorsandroo, S., & Gupta, M. (2025). Explainable Artificial Intelligence (XAI) for Malware Analysis: A Survey of Techniques, Applications, and Open Challenges. IEEE Access, 13(April), 61611–61640. https://doi.org/10.1109/ACCESS.2025.3555926

Palma Salas, M., & de Geus, P. L. (2024). Deep Learning Applied to Imbalanced Malware Datasets Classification. Journal of Internet Services and Applications, 15(1), 342–359. https://doi.org/10.5753/jisa.2024.3907

Saqib, M., Mahdavifar, S., Fung, B. C. M., & Charland, P. (2024). A Comprehensive Analysis of Explainable AI for Malware Hunting. ACM Computing Surveys, 56(12). https://doi.org/10.1145/3677374

Vuran Sarı, N., & Acı, M. (2025). A hybrid CNN-GRU model with XAI-Driven interpretability using LIME and SHAP for static analysis in malware detection. PeerJ Computer Science, 11. https://doi.org/10.7717/peerj-cs.3258

Wang, P., Lin, T., Wu, D., Zhu, J., & Wang, J. (2024). TTDAT: Two-Step Training Dual Attention Transformer for Malware Classification Based on API Call Sequences. Applied Sciences (Switzerland), 14(1). https://doi.org/10.3390/app14010092

Yao, Y., Zhu, Y., Jia, Y., Shi, X., Zhang, L., Zhong, D., & Duan, J. (2024). Research on Malware Detection Technology for Mobile Terminals Based on API Call Sequence. Mathematics, 12(1). https://doi.org/10.3390/math12010020

Yousuf, M. I., Anwer, I., Riasat, A., Zia, K. T., & Kim, S. (2023). Windows malware detection based on static analysis with multiple features. PeerJ Computer Science, 9, 1–29. https://doi.org/10.7717/PEERJ-CS.1319

Yu, B., Zhang, W., Liu, Y., Ahmad, A., Obidallah, W. J., Yousef, A., Ullah, F., Yoshigoe, K., & Zhao, Y. (2026). Explainable AI for malware analysis: a systematic review of benchmark datasets, traffic-oriented detection, and interpretability methods. PeerJ Computer Science, (5), 1–59. https://doi.org/10.7717/peerj-cs.3902

Zhang, S., Wu, J., Zhang, M., & Yang, W. (2023). Dynamic Malware Analysis Based on API Sequence Semantic Fusion. Applied Sciences (Switzerland), 13(11). https://doi.org/10.3390/app13116526

Downloads


Crossmark Updates

How to Cite

Viona, F. ., & Hiskiawan, P. (2026). API Call-Based Windows Malware Detection Using CNN-LSTM-Attention and Explainable SHAP. Sinkron : Jurnal Dan Penelitian Teknik Informatika, 10(4), 2368-2381. https://doi.org/10.33395/sinkron.v10i4.16646