DeepGuard: Explainable Behavioral Malware Detection Using Hybrid CNN-BiLSTM-Attention Deep Learning on Dynamic API Call Sequences
Abstract
Recent rapid increases in sophisticated malware have severely challenged traditional signature-based security systems, particularly in their ability to recognize zero-day and polymorphic threats. This paper introduces “DeepGuard,” an AI/Machine-Learning-powered behavioral malware detection framework built around the analysis of dynamic API call sequences using a hybrid deep learning architecture. Specifically, DeepGuard combines Convolutional Neural Networks (CNN), Bidirectional Long Short-Term Memory (BiLSTM), and an Attention mechanism to jointly capture local behavioral patterns of malware and the long-term sequential dependencies present in execution behavior. DeepGuard is trained on dynamic API call sequence data covering both malware and benign samples, providing the basis for robust behavioral analysis and realtime threat detection. The Synthetic Minority Oversampling Technique (SMOTE) is applied during preprocessing to address class imbalance, and SHAP (SHapley Additive exPlanations) is integrated into the design to make the model interpretable and to identify the specific API behaviors that drive a malicious prediction. On the evaluated dataset, DeepGuard achieves an accuracy of 98.88%, precision of 99.39%, recall of 99.46%, F1-score of 99.43%, and an AUC of 96.29%, outperforming conventional CNN, LSTM, and BiLSTM baselines trained under the same protocol. Overall, DeepGuard is presented as an efficient, scalable, and explainable framework for modern behavioral anti-malware systems, and this revised version explicitly documents its current validation scope, reproducibility details, and the empirical analyses (cross-validation, ablation, and SHAP visualizations) planned to further substantiate these results.