ORCID
- Bilal Yousuf: 0000-0001-6024-9084
Abstract
Modern malware detection rely on Deep neural networks to achieve high detection performance by leveraging a large feature space. However, these models often suffer from high dimensionality, limited interpretability, and reduced reliability due to redundant features. As a result, they obscure the true contribution of features to the rationale for the prediction. To address these challenges, this study proposes an explainability-aware feature pruning technique to improve the performance and efficiency of deep neural networks. The key focus of this study is the development of the novel SHAP–NCA Intersection Framework (SNIF), which integrates explainability with feature selection for efficient and trustworthy malware detection. The proposed SNIF framework distinguishes itself by integrating SHAP (Shapley Additive Explanations)-based, explainability-driven feature pruning with NCA (Neighborhood Component Analysis)-based statistical feature selection through a consensus-based intersection mechanism. The proposed SNIF integrates NCA and SHAP through an intersection strategy, which effectively reduced the feature space by 61.04% (1327 to 517 features), resulting in a compact explainability-guided feature subset. The competitive accuracy (0.9323%) and significantly improved precision (0.8358%), indicating fewer false positives with a significantly reduced inference time (0.1480%) while maintaining high detection accuracy. Unlike conventional approaches that rely solely on accuracy or lack interpretabilit, SNIF retains only discriminative and highly influential features through the agreement of NCA and SHAP with more focused and less redundant explanations.
Keywords
Artificial Intelligence, Cybersecurity, Deep Learning, Explainability, Feature extraction, Interpretability, Malware detection, Shapley Additive Explanations (SHAP)
DOI Link
Publication Date
2026-01-01
Publication Title
IEEE Access
Volume
14
First Page
119722
Last Page
119735
Acceptance Date
2026-01-01
Deposit Date
2026-09-04
Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International License.
Additional Links
Recommended Citation
Nazim, Sadia; Hussain, Syed Shujaa; Yousuf, Bilal; and Mustapha, Jawahir Che, "SNIF: Explainability-Driven feature selection through state-of-the-art SHAP–NCA intersection framework for malware detection" (2026). Research Outputs: 2025-Present. 16.
https://arrow.tudublin.ie/buschrsmro/16