A Unified Explainable Transfer Learning Framework for Robust Cross-Domain Malware Analysis and IoT Network Intrusion Detection
Keywords:
Explainable AI (XAI), Intrusion Detection System, IoT security, Malware detection, Transfer learningAbstract
The proliferation of sophisticated cyber threats targeting both traditional endpoints and Internet of Things (IoT) devices requires unified detection frameworks that operate across heterogeneous domains while maintaining interpretability. This paper presents XPLAIN-Transfer, a novel framework integrating deep transfer learning with SHAP-based explainable AI (XAI) for robust cross-domain malware analysis and IoT network intrusion detection. The methodology employs a hybrid CNN-LSTM architecture pre-trained on the Malware Memory Dump dataset and fine-tuned for IoT (NF-TON-IoT) and network (UNSW-NB15) intrusion detection through a three-phase transfer learning strategy. Extensive benchmarking shows that XPLAIN-Transfer consistently outperformed conventional training approaches, achieving accuracies of 99.9%, 96.2%, and 96.0% for malware, IoT intrusion, and network intrusion detection, respectively, with performance gains ranging from 5.7% to 7.7%. Transfer learning reduces training time by 40% - 51%, while SHAP integration provides transparent, actionable explanations for security analysts. Robustness validation confirms resilience against adversarial attacks and concept drift. The findings establish that unified explainable frameworks can effectively bridge memory-based and network-based threat detection domains, offering practical deployment advantages to heterogeneous environments. XPLAIN-Transfer represents a significant advancement toward interpretable, efficient, and cross-domain cybersecurity solutions.
References
A. Ahmed, R. Mostafa, M. H. Qutqut, and N. Ragab, “A Systematic Literature Review on Machine Learning for Intrusion Detection Systems,” Future Internet, vol. 18, no. 9, p. 470, Sep. 2026.
A. Almadhor, U. Tandon, G. S. Sajja, S. A. Alqahtani, A. Alharbi, and I. R. Khan, "Transfer learning with XAI for robust malware and IoT network security," Scientific Reports, vol. 15, no. 1, p. 26971, Jan. 2025.
M. Ganesamoorthi, K. Subramanian and B. D, "A Comprehensive Review on Machine Learning and Deep Learning Based Malware Detection Methods," 2024 International Conference on Emerging Research in Computational Science (ICERCS), Coimbatore, India, 2024, pp. 1-8.
M. -M. Andronache, A. Vulpe and C. Burileanu, "A Malware Study using Static and Dynamic Analysis," 2024 15th International Conference on Communications (COMM), Bucharest, Romania, 2024, pp. 1-6.
C. Zhang, G. Wang, S. Wang, D. Zhan, and M. Yin, “Cross-Domain Network Attack Detection Enabled by Heterogeneous Transfer Learning,” Computer Networks, vol. 227, p. 109692, May 2023.
Y. Ge, Y. Gao, X. Li, B. Cai, J. Xi and S. Yu, "EMTD-SSC: An Enhanced Malicious Traffic Detection Model Using Transfer Learning Under Small Sample Conditions in IoT," in IEEE Internet of Things Journal, vol. 11, no. 19, pp. 30725-30741, 1 Oct.1, 2024.
Z. Zhang, H. A. Hamadi, E. Damiani, C. Y. Yeun and F. Taher, "Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-Art in Research," in IEEE Access, vol. 10, pp. 93104-93139, 2022.
P. Hermosilla, S. Berríos, and H. Allende-Cid, "Explainable AI for forensic analysis: A comparative study of SHAP and LIME in intrusion detection models," Applied Sciences, vol. 15, no. 13, p. 7329, Jun. 2025.
O. Oladejo and A. A. Ahmed, “Leveraging Cross-Domain Transfer Learning for Enhanced Multi-Protocol Network Intrusion Detection,” Computers, vol. 15, no. 6, p. 376, Jun. 2026.
M. Rehan, M. S. I. Malik and M. M. Jamjoom, "Fine-Tuning Transformer Models Using Transfer Learning for Multilingual Threatening Text Identification," in IEEE Access, vol. 11, pp. 106503-106515, 2023.
K. Furumoto, T. Morikawa, A. Kolehmainen, B. Silverajan, T. Takahashi, and D. Inoue, “A Comprehensive Survey of Threat Intelligence Research: A Measurement-Based Study,” ACM Computing Surveys, vol. 58, no. 6, pp. 1–35, Dec. 2025.
R. Kant, R. Rao Thallada, B. Pandey and P. Srivastava, "AI-Based Cybersecurity in Healthcare: A Data-Driven, Governance-Aware Framework for Secure Clinical Systems," 2026 IEEE 5th International Conference on AI in Cybersecurity (ICAIC), Houston, TX, USA, 2026, pp. 1-5.
S. M. Lundberg and S.-I. Lee, "A unified approach to interpreting model predictions," in Proceedings Advances in Neural Information Processing Systems (NIPS), Long Beach, CA, USA, 2017, pp. 4765-4774.
U. U. Izuazu, C. I. Nwakanma, D. Kim, and J. M. Lee, "Explainable and perturbation-resilient model for cyber-threat detection in industrial control systems networks," Discover Internet of Things, vol. 5, no. 1, pp. 1-23, Feb. 2025.
R. V. S. S. B. R, Y. M. M. John, M. B. B. G, B. Karim and G. Saritha, "Multi-Domain Cyber Threat Classification Using Enhanced Genetic Algorithm and Deep Neural Networks," 2025 Third International Conference on Networks, Multimedia and Information Technology (NMITCON), BENGALURU, India, 2025, pp. 1-6.
R. Sommer and V. Paxson, "Outside the closed world: On using machine learning for network intrusion detection," IEEE Symposium on Security and Privacy, Oakland, CA, USA, 2025, pp. 305-319.
Z. Shou, Y. Di, X. Ma, R. Xu, H. Chai, and L. Yin, "The APT family classification system based on APT call sequences and attention mechanism," International Journal of Information and Computer Security, vol. 26, no. 1, pp. 22-40, Jan. 2025.
C. Kılıç and G. Şengül, "SHAP-Guided Feature Selection for Cross-Dataset Generalization in Network Intrusion Detection Systems," in IEEE Access, vol. 14, pp. 90926-90936, 2026.
A. A. Abualhassan, Y. Fadol, M. S. M. Gismalla, and M. Hamdan, "IIoT-TinyDNN: A lightweight intrusion detection system for edge-based IIoT security," 2025 IEEE Conference on Standards for Communications and Networking (CSCN), Bologna, Italy, 2025, pp. 1-6.
N. Raghavendran, "Dataset and code for IoT-based WISNE-SDN detection and DDOS attack mitigation using machine learning techniques," Mendeley Data, V4, Aug. 2025.
S. T. Hasson, M. S. Balasim, and M. S. Mohmood, “Detection and Classification of Malicious Software in the IoT Environment Using Feature Selection by Deep Learning Methods,” 2025 XXVIII International Conference on Soft Computing and Measurements (SCM), pp. 1–7, May 2025.
M. Ahmed, A. Mahmood, and J. Hu, "A survey of network anomaly detection techniques," Journal of Network and Computer Applications, vol. 60, pp. 19-31, Jan. 2024.
S. Benabderrahmane and A. Lenca, "From one attack domain to another: Contrastive transfer learning with Siamese networks for APT detection," arXiv preprint, Nov. 2025.
B. Romaric de Judicael, D. D. Jerome, B. N. Gerard, and K. Tiemoman, "Towards explicable cybersecurity: Integrating explicability into BERT and GPT models for incident detection and analysis," Journal of Information Systems Engineering and Management, vol. 10, no. 60s, pp. 162-172, Feb. 2025.
M. Rajesh and V. Nirmalrani, "Interpretable intrusion detection for IoT environments using a self-attention-based explainable AI framework," IEEE Access, vol. 13, pp. 45678-45695, 2025.