---
格式版本: 2
标题: "A Comparison of Malware Image Transformations Using Grad-CAM and Hybrid Learning Models"
原文链接: "https://arxiv.org/abs/2608.12077"
发布日期: "2026-08-12"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 12 Aug 2026 14:00:44 UTC (15,150 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-13T18:33:34+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-13T18:24:32+08:00"
入库时间: "2026-08-13T10:33:34.416Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=AI&searchtype=all"
匹配关键词:
  - "AI"
  - "performance"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI质检状态: "评分失败"
AI评分尝试次数: 1
AI评分错误类型: "service_error"
AI评分错误: "LLM call failed; tried model chain: ali-deepseek-v4-flash -> tx-deepseek-v4-flash | Model ali-deepseek-v4-flash failed 500: {\"error\":{\"code\":\"\",\"message\":\"Database error, please contact the administrator (request id: 202608131033369542353508268d9d6ax4bLxqa)\",\"type\":\"new_api_error\"}} | Model tx-deepseek-v4-flash failed 500: {\"error\":{\"code\":\"\",\"message\":\"Database error, please contact the administrator (request id: 202608131033375291431248268d9d637ZgVW70)\",\"type\":\"new_api_error\"}}"
AI评分开始时间: "2026-08-13T10:33:34.423Z"
AI评分结束时间: "2026-08-13T10:33:37.673Z"
AI摘要: "该研究将 Grad-CAM 作为可解释 AI 工具，比较了 8 种恶意软件图像变换，并引入 HiResCAM 评估解释质量。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:40:26.668Z"
采集批次: "2026年8月13日18点24分27秒"
采集批次ID: "20260813-182427-1564e572"
去重键: "https://arxiv.org/abs/2608.12077"
---

## Computer Science > Cryptography and Security

## Title:A Comparison of Malware Image Transformations Using Grad-CAM and Hybrid Learning Models

Authors:[Vibha Bhavikatti](https://arxiv.org/search/cs?searchtype=author&query=Bhavikatti,+V), [Mark Stamp](https://arxiv.org/search/cs?searchtype=author&query=Stamp,+M)

[View PDF](https://arxiv.org/pdf/2608.12077)

> Abstract:Recent studies have shown that binary-to-image representations can enable effective machine learning-based results for malware detection and classification. However, performance can vary significantly, depending on the technique used to convert binaries to images. Furthermore, the explainability and interpretability of image-based models is largely unexplored within the malware domain. In this research, we employ Gradient-weighted Class Activation Maps (Grad-CAM) as an eXplainable AI (XAI) tool, which we use to analyze eight distinct image types derived from malware samples. We provide quantitative faithfulness and stability metrics for Grad-CAM heatmaps and we compare these heatmaps to High-Resolution Class Activation Mappings (HiResCAM). We also show that Grad-CAM heatmaps can provide useful information for malware classification. Specifically, we show that a Random Forest model trained on features extracted from Grad-CAM images via a MobileNetV2 Convolutional Neural Network (CNN) model achieves a test accuracy of 0.777 across 17 malware families, exceeding a previous benchmark of 0.750 for this same dataset. A key finding of this research is that for the malware image transformations considered, accuracy and explanation faithfulness do not coincide, e.g., image transformation techniques that produce the most faithful explanations yield only mid-tier accuracy.

| Comments: |  |
| --- | --- |
| Subjects: | Cryptography and Security (cs.CR) |
| Cite as: | [arXiv:2608.12077](https://arxiv.org/abs/2608.12077) \[cs.CR\] |
|  | (or [arXiv:2608.12077v1](https://arxiv.org/abs/2608.12077v1) \[cs.CR\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.12077](https://doi.org/10.48550/arXiv.2608.12077) |

## Submission history

From: Mark Stamp \[[view email](https://arxiv.org/show-email/8694fdcf/2608.12077)\]  
**\[v1\]** Wed, 12 Aug 2026 14:00:44 UTC (15,150 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.12077) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
