{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T10:48:55Z","timestamp":1775213335222,"version":"3.50.1"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032088864","type":"print"},{"value":"9783032088871","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T00:00:00Z","timestamp":1761350400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T00:00:00Z","timestamp":1761350400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-08887-1_9","type":"book-chapter","created":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T11:28:13Z","timestamp":1761305293000},"page":"137-155","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Rule Extraction and\u00a0Interaction-Aware Explainability for\u00a0AI-Driven Malware Detection"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9010-3075","authenticated-orcid":false,"given":"Peter","family":"Anthony","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-1743-6269","authenticated-orcid":false,"given":"Kefas Rimamnuskeb","family":"Galadima","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-3413-2409","authenticated-orcid":false,"given":"Zekeri","family":"Adams","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2119-170X","authenticated-orcid":false,"given":"Monday","family":"Onoja","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3628-794X","authenticated-orcid":false,"given":"Daniel","family":"Arp","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6384-9771","authenticated-orcid":false,"given":"Martin","family":"Homola","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0634-9476","authenticated-orcid":false,"given":"\u0160tefan","family":"Balogh","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,25]]},"reference":[{"key":"9_CR1","doi-asserted-by":"publisher","unstructured":"Durgaraju, S., Vel, D.V.T.,\u00a0Madathala, H.: The evolution of cyber threats and defenses: a review of innovations and challenges. In: 2025 6th International Conference on Mobile Computing and Sustainable Informatics (ICMCSI) (2025). https:\/\/doi.org\/10.1109\/ICMCSI64620.2025.10883230","DOI":"10.1109\/ICMCSI64620.2025.10883230"},{"key":"9_CR2","unstructured":"Szor, P.: The Art of Computer Virus Research and Defense. Addison-Wesley Professional (2005). https:\/\/dl.acm.org\/doi\/abs\/10.5555\/1050957"},{"key":"9_CR3","doi-asserted-by":"publisher","unstructured":"Anderson, R.J., et al.: Measuring the cost of cybercrime. Econ. Inf. Secur. Priva. (2013). https:\/\/doi.org\/10.1007\/978-3-642-39498-0_12","DOI":"10.1007\/978-3-642-39498-0_12"},{"key":"9_CR4","doi-asserted-by":"publisher","first-page":"46717","DOI":"10.1109\/ACCESS.2019.2906934","volume":"7","author":"R Vinayakumar","year":"2019","unstructured":"Vinayakumar, R., Alazab, M., Soman, K.P., Poornachandran, P., Venkatraman, S.: Robust intelligent malware detection using deep learning. IEEE Access 7, 46717\u201346738 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2906934","journal-title":"IEEE Access"},{"key":"9_CR5","doi-asserted-by":"publisher","unstructured":"Arrieta, A.B., et\u00a0al.: Explainable artificial intelligence (XAI): concepts, taxonomies, opportunities and challenges toward responsible AI. Inf. Fus. 58 (2020). https:\/\/doi.org\/10.1016\/j.inffus.2019.12.012","DOI":"10.1016\/j.inffus.2019.12.012"},{"key":"9_CR6","doi-asserted-by":"crossref","unstructured":"de\u00a0Magalh\u00e3es, S.T.: The European Union\u2019s General Data Protection Regulation (GDPR). 1st Edition, World Scientific, Singapore, Ch.\u00a015, pp. 529\u2013558 (2020). https:\/\/worldscientific.com\/doi\/abs\/10.1142\/9789811204463_0015","DOI":"10.1142\/9789811204463_0015"},{"key":"9_CR7","doi-asserted-by":"publisher","unstructured":"Lundberg, S.M., Lee, S.-I.: A unified approach to interpreting model predictions. In: Advances in Neural Information Processing Systems, vol. 30 (NeurIPS 2017), Curran Associates, Inc., pp. 4765\u20134774 (2017). https:\/\/doi.org\/10.48550\/arXiv.1705.07874","DOI":"10.48550\/arXiv.1705.07874"},{"key":"9_CR8","doi-asserted-by":"publisher","unstructured":"Ribeiro, M.T.,\u00a0Singh, S.,\u00a0Guestrin, C.: why should I trust you?: explaining the predictions of any classifier. In: Proceedings of the Interenational Conference on Knowledge Discovery (KDD) (2016). https:\/\/doi.org\/10.1145\/2939672.2939778","DOI":"10.1145\/2939672.2939778"},{"key":"9_CR9","doi-asserted-by":"publisher","unstructured":"Ribeiro, M.T., Singh, S., Guestrin, C.: Anchors: High-precision model-agnostic explanations. In: Proceedings of the AAAI Conference on Artificial Intelligence (2018). https:\/\/doi.org\/10.1609\/AAAI.V32I1.11491","DOI":"10.1609\/AAAI.V32I1.11491"},{"key":"9_CR10","doi-asserted-by":"publisher","unstructured":"Schnake, T., et al.: Towards symbolic XAI \u2014 explanation through human understandable logical relationships between features. Inf. Fus. 118, 102923 (2025). https:\/\/doi.org\/10.1016\/j.inffus.2024.102923","DOI":"10.1016\/j.inffus.2024.102923"},{"key":"9_CR11","doi-asserted-by":"publisher","unstructured":"Warnecke, A., Arp, D., Wressnegger, C., Rieck, K.: Evaluating explanation methods for deep learning in security (2020). https:\/\/doi.org\/10.1109\/EuroSP48549.2020.00018","DOI":"10.1109\/EuroSP48549.2020.00018"},{"key":"9_CR12","unstructured":"Anderson, H.S.,\u00a0Roth, P.: EMBER: an open dataset for training static PE malware machine learning models. arXiv preprint arXiv:1804.04637 (2018)"},{"key":"9_CR13","doi-asserted-by":"crossref","unstructured":"Svec, P.,\u00a0Balogh, S.,\u00a0Homola, M.: Experimental evaluation of description logic concept learning algorithm for static malware detection. In: ICISSP, pp. 792\u2013799 (2021)","DOI":"10.5220\/0010429707920799"},{"key":"9_CR14","doi-asserted-by":"publisher","unstructured":"Manthena, H.,\u00a0Shajarian, S., Kimmell, J.C.,\u00a0Abdelsalam, M.,\u00a0Khorsandroo, S.,\u00a0Gupta, M.: Explainable artificial intelligence (XAI) for malware analysis: a survey of techniques, applications, and open challenges. IEEE Access 13 (2025). https:\/\/doi.org\/10.1109\/ACCESS.2025.3555926","DOI":"10.1109\/ACCESS.2025.3555926"},{"key":"9_CR15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103842","volume":"141","author":"A Galli","year":"2024","unstructured":"Galli, A., La Gatta, V., Moscato, V., Postiglione, M., Sperl\u00ec, G.: Explainability in AI-based behavioral malware detection systems. Comput. Secur. 141, 103842 (2024). https:\/\/doi.org\/10.1016\/j.cose.2024.103842","journal-title":"Comput. Secur."},{"issue":"9","key":"9_CR16","doi-asserted-by":"publisher","first-page":"170","DOI":"10.3126\/nprcjmr.v1i9.74177","volume":"1","author":"D Adhikari","year":"2024","unstructured":"Adhikari, D., Thapaliya, S.: Explainable AI for cyber security: interpretable models for malware analysis and network intrusion detection. NPRC J. Multidiscip. Res. 1(9), 170\u2013179 (2024). https:\/\/doi.org\/10.3126\/nprcjmr.v1i9.74177","journal-title":"NPRC J. Multidiscip. Res."},{"key":"9_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103637","volume":"137","author":"J Mitchell","year":"2024","unstructured":"Mitchell, J., McLaughlin, N., del Rincon, J.M.: Generating sparse explanations for malicious android opcode sequences using hierarchical lime. Comput. Secur. 137, 103637 (2024). https:\/\/doi.org\/10.1016\/j.cose.2023.103637","journal-title":"Comput. Secur."},{"key":"9_CR18","doi-asserted-by":"publisher","unstructured":"Basheer, N.,\u00a0Pranggono, B.,\u00a0Islam, S.,\u00a0Papastergiou, S.,\u00a0Mouratidis, H.: Enhancing malware detection through machine learning using XAI with SHAP framework. In: AIAI, pp. 316\u2013329 (2024). https:\/\/doi.org\/10.1007\/978-3-031-63211-2_24","DOI":"10.1007\/978-3-031-63211-2_24"},{"key":"9_CR19","doi-asserted-by":"publisher","unstructured":"Baghirov, E.: A comprehensive investigation into robust malware detection with explainable AI. Cyber Secur. Appl. 3 (2025). https:\/\/doi.org\/10.1016\/j.csa.2024.100072","DOI":"10.1016\/j.csa.2024.100072"},{"key":"9_CR20","doi-asserted-by":"publisher","unstructured":"Hafiz, M.F.B., Khan, N.A., Kamal, Z., Hossain, S., Barman, S.: A robust malware classification approach leveraging explainable AI. In: International Conference on Intelligence System for Cybersecurity (ISCS), pp. 1\u20136 (2024). https:\/\/doi.org\/10.1109\/ISCS61804.2024.10581382","DOI":"10.1109\/ISCS61804.2024.10581382"},{"key":"9_CR21","doi-asserted-by":"publisher","unstructured":"Alenezi, R., Ludwig, S.A.: Explainability of cybersecurity threats data using shap. In: IEEE Symposium Series on Computational Intelligence (SSCI), 01\u201310 (2021). https:\/\/doi.org\/10.1109\/SSCI50451.2021.9659888","DOI":"10.1109\/SSCI50451.2021.9659888"},{"key":"9_CR22","doi-asserted-by":"publisher","unstructured":"Gulmez, S.,\u00a0Gorgulu Kakisim, A.,\u00a0Sogukpinar, I.: XRAN: explainable deep learning-based ransomware detection using dynamic analysis. Comput. Secur. 139 103703 (2024). https:\/\/doi.org\/10.1016\/j.cose.2024.103703","DOI":"10.1016\/j.cose.2024.103703"},{"key":"9_CR23","unstructured":"Mane, S.,\u00a0Rao, D.: Explaining network intrusion detection system using explainable AI framework, pp. 1\u201310. arXiv preprint arXiv:2103.07110 (2021)"},{"key":"9_CR24","doi-asserted-by":"crossref","unstructured":"Sharma, Y.,\u00a0Birnbach, S.,\u00a0Martinovic, I.: Exploiting TTPS to design an extensible and explainable malware detection system, vol. 30","DOI":"10.3897\/jucs.131753"},{"key":"9_CR25","doi-asserted-by":"publisher","unstructured":"Moj\u017ei\u0161, J.,\u00a0Kenyeres, M.: Interpretable rules with a simplified data representation - a case study with the ember dataset. In:\u00a0Silhavy, R.,\u00a0Silhavy, P. (eds.), Data Analytics in System Engineering, Springer International Publishing, pp. 1\u201310 (2024). https:\/\/doi.org\/10.1007\/978-3-031-53552-9_1","DOI":"10.1007\/978-3-031-53552-9_1"},{"issue":"1","key":"9_CR26","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1007\/s42454-024-00055-7","volume":"6","author":"FS Prity","year":"2024","unstructured":"Prity, F.S., et al.: Machine learning-based cyber threat detection: an approach to malware detection and security with explainable AI insights. Hum. Intell. Syst. Integr. 6(1), 61\u201390 (2024). https:\/\/doi.org\/10.1007\/s42454-024-00055-7","journal-title":"Hum. Intell. Syst. Integr."},{"key":"9_CR27","doi-asserted-by":"publisher","first-page":"25237","DOI":"10.1109\/ACCESS.2023.3255176","volume":"11","author":"H Manthena","year":"2023","unstructured":"Manthena, H., Kimmel, J.C., Abdelsalam, M., Gupta, M.: Analyzing and explaining black-box models for online malware detection. IEEE Access 11, 25237\u201325252 (2023). https:\/\/doi.org\/10.1109\/ACCESS.2023.3255176","journal-title":"IEEE Access"},{"key":"9_CR28","doi-asserted-by":"publisher","unstructured":"Nwakanma, C.I., Ahakonye, L.A.C., Jun, T., Lee, J.M., Kim, D.S.: Explainable scada-edge network intrusion detection system: tree-lime approach. https:\/\/doi.org\/10.1109\/SmartGridComm57358.2023.10333968","DOI":"10.1109\/SmartGridComm57358.2023.10333968"},{"key":"9_CR29","unstructured":"Lundberg, S.M., Erion, G.G., Lee, S.-I.: Consistent individualized feature attribution for tree ensembles (2019). arXiv:1802.03888"},{"key":"9_CR30","doi-asserted-by":"publisher","unstructured":"Lakkaraju, H., Bach, S.H.,\u00a0Leskovec, J.: Interpretable decision sets: a joint framework for description and prediction. In: Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining (KDD) (2016). https:\/\/doi.org\/10.1145\/2939672.2939874","DOI":"10.1145\/2939672.2939874"}],"container-title":["Lecture Notes in Computer Science","Rules and Reasoning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-08887-1_9","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,3]],"date-time":"2026-04-03T09:56:49Z","timestamp":1775210209000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-08887-1_9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,25]]},"ISBN":["9783032088864","9783032088871"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-08887-1_9","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,25]]},"assertion":[{"value":"25 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"RuleML+RR","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Joint Conference on Rules and Reasoning","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Istanbul","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"T\u00fcrkiye","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"rulemlrr2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/2025.declarativeai.net\/events\/ruleml-rr","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}