An Explainable Deep Learning Pipeline for Malware Family Classification: GAF Image Encoding and API-Grounded LLM Interpretation
Signature-based malware detection is undermined by obfuscation and packing, motivating dynamic analysis of Application Programming Interface (API) call sequences. Existing image-based classifiers reach high accuracy but rarely explain why a sample belongs to a given family. In this paper, our goal is not to maximize cl...