SHAP-Guided Opcode Feature Selection for Lightweight and Explainable IoT Malware Detection — and What the Explanations Revealed About the Dataset

Authors

DOI:

https://doi.org/10.71229/t8m7gd33

Keywords:

IoT malware , Opcode analysis, SHAP, Feature selection , Explainable AI, Dataset artifacts, Lightweight models

Abstract

Opcode-frequency models detect IoT malware with near-perfect accuracy, yet typically with thousands of n-gram features and no account of which instructions drive a verdict. We propose a framework in which SHAP values are not a post-hoc report but the feature-selection criterion itself: a reference LightGBM model is explained fold-by-fold, opcodes are ranked by mean absolute SHAP contribution, and the smallest top-k set that preserves performance becomes the deployed model's input space. On the public CyberScienceLab ARM-32 opcode corpus (268 benign, 244 malicious samples), five selected features out of roughly 4,700 retain an F1 of 0.9939 ± 0.0035, statistically indistinguishable from the strongest of six baselines (Wilcoxon p = 0.121) under repeated stratified 10-fold cross-validation with selection performed inside each fold. The explanations also exposed a problem the accuracy tables hide. The single most influential token, an uppercase RET that is not an ARM-32 mnemonic, appears in 243 of 244 malware files and in no benign file — a collection artifact that may inflate reported accuracies on this dataset. We therefore introduce an artifact-resistant protocol that restricts the vocabulary to opcodes present in at least 5% of training files of each class, computed within each fold. Under this stricter regime the five-feature model reaches an F1 of 0.9913 ± 0.0051, trading 0.6 points of F1 against the best baseline (p = 0.046) for a 4x smaller feature set and explanations built into the pipeline. Interpretability is not an accessory: it is the mechanism that compressed the model and audited the data.

Author Biography

  • Suad Shatti Azeez, Department of Information Technology, Ministry of Education, Baghdad, Iraq

    Department of Information Technology, Ministry of Education, Baghdad, Iraq

References

[1] B. T. Ahmed, N. G. M. Jameel, and B. I. Saeed, "A Novel Hybrid Opcode Feature Selection Framework for Efficient and Effective IoT Malware Detection," IoT, vol. 7, no. 1, art. 24, 2026, doi: 10.3390/iot7010024. DOI: https://doi.org/10.3390/iot7010024

[2] A. Alfahaid, E. Alalwany, A. M. Almars, F. Alharbi, E. Atlam, and I. Mahgoub, "Machine Learning-Based Security Solutions for IoT Networks: A Comprehensive Survey," Sensors, vol. 25, no. 11, art. 3341, 2025, doi: 10.3390/s25113341. DOI: https://doi.org/10.3390/s25113341

[3] H. Manthena, S. Shajarian, J. Kimmell, M. Abdelsalam, S. Khorsandroo, and M. Gupta, "Explainable Artificial Intelligence (XAI) for Malware Analysis: A Survey of Techniques, Applications, and Open Challenges," IEEE Access, 2025, doi: 10.1109/ACCESS.2025.3555926. DOI: https://doi.org/10.1109/ACCESS.2025.3555926

[4] S. M. Lundberg and S.-I. Lee, "A Unified Approach to Interpreting Model Predictions," in Advances in Neural Information Processing Systems 30 (NIPS), 2017.

[5] S. M. Lundberg, G. Erion, H. Chen, A. DeGrave, J. M. Prutkin, B. Nair, R. Katz, J. Himmelfarb, N. Bansal, and S.-I. Lee, "From Local Explanations to Global Understanding with Explainable AI for Trees," Nature Machine Intelligence, vol. 2, pp. 56–67, 2020, doi: 10.1038/s42256-019-0138-9. DOI: https://doi.org/10.1038/s42256-019-0138-9

[6] G. Ke, Q. Meng, T. Finley, T. Wang, W. Chen, W. Ma, Q. Ye, and T.-Y. Liu, "LightGBM: A Highly Efficient Gradient Boosting Decision Tree," in Advances in Neural Information Processing Systems 30 (NIPS), 2017.

[7] CyberScienceLab, "IoT OpCode Dataset," GitHub repository. [Online]. Available: https://github.com/CyberScienceLab/Our-Datasets (accessed Jul. 18, 2026).

[8] E. Cozzi, M. Graziano, Y. Fratantonio, and D. Balzarotti, "Understanding Linux Malware," in Proc. IEEE Symposium on Security and Privacy (SP), 2018. DOI: https://doi.org/10.1109/SP.2018.00054

[9] M. Antonakakis et al., "Understanding the Mirai Botnet," in Proc. USENIX Security Symposium, 2017.

[10] A. D. Raju, I. Abualhaol, R. S. Giagone, Y. Zhou, and S. Huang, "A Survey on Cross-Architectural IoT Malware Threat Hunting," IEEE Access, 2021, doi: 10.1109/ACCESS.2021.3091427. DOI: https://doi.org/10.1109/ACCESS.2021.3091427

[11] Z. Qian, H. Miao, C. Zhang, Q. Hu, Y. Jiang, J. Huang, and F. Zhong, "Feature-Oriented IoT Malware Analysis: Extraction, Classification, and Future Directions," arXiv:2509.03442, Sep. 2025. [Online]. Available: https://arxiv.org/abs/2509.03442

[12] J. Ramamoorthy, K. Gupta, N. K. Shashidhar, and C. Varol, "Linux IoT Malware Variant Classification Using Binary Lifting and Opcode Entropy," Electronics, vol. 13, no. 12, art. 2381, 2024, doi: 10.3390/electronics13122381. DOI: https://doi.org/10.3390/electronics13122381

[13] S. Heydari and Q. H. Mahmoud, "Tiny Machine Learning and On-Device Inference: A Survey of Applications, Challenges, and Future Directions," Sensors, vol. 25, no. 10, art. 3191, 2025, doi: 10.3390/s25103191. DOI: https://doi.org/10.3390/s25103191

[14] C. Rondanini, B. Carminati, E. Ferrari, A. Gaudiano, and A. Kundu, "Malware Detection at the Edge with Lightweight LLMs: A Performance Evaluation," arXiv:2503.04302, Mar. 2025. [Online]. Available: https://arxiv.org/abs/2503.04302

[15] R. Darwish, M. Abdelsalam, S. Khorsandroo, and K. Roy, "FedP3E: Privacy-Preserving Prototype Exchange for Non-IID IoT Malware Detection in Cross-Silo Federated Learning," arXiv:2507.07258, Jul. 2025. [Online]. Available: https://arxiv.org/abs/2507.07258

[16] CrySyS Lab, "CUBE-MALIoT-2021 Dataset," GitHub repository. [Online]. Available: https://github.com/CrySyS/cube-maliot-2021 (accessed Jul. 18, 2026).

[17] F. Pedregosa et al., "Scikit-learn: Machine Learning in Python," Journal of Machine Learning Research, vol. 12, pp. 2825–2830, 2011.

[18] J. Demšar, "Statistical Comparisons of Classifiers over Multiple Data Sets," Journal of Machine Learning Research, vol. 7, pp. 1–30, 2006.

[19] P. Virtanen et al., "SciPy 1.0: Fundamental Algorithms for Scientific Computing in Python," Nature Methods, vol. 17, pp. 261–272, 2020, doi: 10.1038/s41592-019-0686-2. DOI: https://doi.org/10.1038/s41592-019-0686-2

fig 4

Downloads

Published

2026-09-06

Issue

Section

Original Articles

How to Cite

SHAP-Guided Opcode Feature Selection for Lightweight and Explainable IoT Malware Detection — and What the Explanations Revealed About the Dataset. (2026). Al-Noor Journal of Engineering Management and Computer Science, 2(4), 185-195. https://doi.org/10.71229/t8m7gd33

Similar Articles

21-30 of 87

You may also start an advanced similarity search for this article.