IJMECS Vol. 18, No. 5, 8 Oct. 2026
Cover page and Table of Contents: PDF (size: 2284KB)
PDF (2284KB), PP.37-67
Views: 0 Downloads: 0
Explainable AI, Android Malware Detection, Deepfake Detection, Adversarial Robustness, SHAP, Metaheuristic Optimization, Educational Simulator.
We present SECURE-XED, a unified, explainable, and adversarial-aware learning system for two traditionally disjoint domains: Android malware classification and deepfake detection. The system uses a shared convolutional neural network backbone with domain-specific input adaptation and two task-specific heads. It integrates SHapley Additive exPlanations for explanation, the Fast Gradient Sign Method and Projected Gradient Descent for adversarial evaluation under Structural Similarity Index Measure guardrails, and a selective-activation controller that enables behavioral malware features when confidence is low or evasion is suspected. A hybrid Seagull Optimization Algorithm–Imperialist Competitive Algorithm procedure jointly tunes clean accuracy, robustness under projected-gradient attacks, expected calibration error, parameter count, and inference latency. SECURE-XED is evaluated on standard Android malware corpora and the FaceForensics++, Celeb-DF, and Deepfake Detection Challenge benchmarks. Under Projected Gradient Descent, Android malware accuracy decreases by approximately 19–21% with a perturbation budget of 0.1 over 40 steps, while deepfake accuracy decreases by 16.6–17.6% with a perturbation budget of 0.03 over 10 steps, demonstrating domain-dependent adversarial sensitivity. Under clean deepfake inference conditions, excluding post-prediction explanation generation and adversarial processing, the unified configuration reduces average inference latency from 34.1 to 26.9 milliseconds per frame and approximately halves the parameter requirement relative to maintaining separate model instances, while retaining equal or slightly better clean accuracy. A classroom-oriented simulator exposes explanation overlays and adversarial controls on real frames. A six-participant human-grounded pilot descriptively showed a 22-percentage-point change in Region Identification Accuracy, a 12-second reduction in decision time, and a 0.9-point Likert change in perceived clarity and trust; these pilot outcomes are descriptive and not inferential. The resulting framework combines shared cross-domain representation, multi-objective optimization, adversarial evaluation, explainability, and model-in-the-loop educational interaction within a single modular architecture.
Mohammad Othman Nassar, "SECURE-XED: A Unified Explainable CNN Framework with Hybrid Metaheuristic Optimization for Cross-Domain Malware and Deepfake Detection", International Journal of Modern Education and Computer Science(IJMECS), Vol.18, No.5, pp. 37-67, 2026. DOI:10.5815/ijmecs.2026.05.03
[1]P. Agrawal and B. Trivedi, “A Survey on Android Malware and their Detection Techniques,” in Proc. 2019 IEEE Int. Conf. Electrical, Computer and Communication Technologies (ICECCT), Coimbatore, India, 2019, pp. 1–6, doi:10.1109/ICECCT.2019.8868951.
[2]C. Gilbert and M. A. Gilbert, “Leveraging Artificial Intelligence (AI) by a Strategic Defense against Deepfakes and Digital Misinformation,” International Journal of Scientific Research and Modern Technology, vol. 3, no. 11, pp. 62–78, Nov. 2024, doi:10.38124/ijsrmt.v3i11.76.
[3]R. Mubarak et al., “A Survey on the Detection and Impacts of Deepfakes in Visual, Audio, and Textual Formats,” IEEE Access, vol. 11, pp. 144497–144529, 2023, doi:10.1109/ACCESS.2023.3344653.
[4]L. Shu, S. Dong, H. Su, and J. Huang, “Android Malware Detection Methods Based on Convolutional Neural Network: A Survey,” IEEE Transactions on Emerging Topics in Computational Intelligence, vol. 7, no. 5, pp. 1330–1350, Oct. 2023, doi:10.1109/TETCI.2023.3281833.
[5]S. Hosseini and A. Al Khaled, “A Survey on the Imperialist Competitive Algorithm Metaheuristic: Implementation in Engineering Domain and Directions for Future Research,” Applied Soft Computing, vol. 24, pp. 1078–1094, Nov. 2014, doi:10.1016/j.asoc.2014.08.024.
[6]S. Ma et al., “Improved Seagull Optimization Algorithm to Optimize Neural Networks with Gated Recurrent Units for Network Intrusion Detection,” in Proc. 2021 11th IEEE Int. Conf. Intelligent Data Acquisition and Advanced Computing Systems: Technology and Applications (IDAACS), Cracow, Poland, 2021, pp. 100–104, doi:10.1109/IDAACS53288.2021.9660898.
[7]S. Dasgupta, K. Badal, S. Chittam, M. T. Alam, and K. Roy, “Attention-Enhanced CNN for High-Performance Deepfake Detection: A Multi-Dataset Study,” IEEE Access, vol. 13, pp. 101980–101993, 2025, doi:10.1109/ACCESS.2025.3578343.
[8]Z. Tan and Y. Tian, “Robust Explanation for Free or at the Cost of Faithfulness,” in Proc. 40th Int. Conf. Machine Learning (ICML), Proc. Machine Learning Research, vol. 202, pp. 33534–33562, 2023.
[9]H. She, Y. Hu, B. Liu, J. Li, and C.-T. Li, “Using Graph Neural Networks to Improve Generalization Capability of the Models for Deepfake Detection,” IEEE Transactions on Information Forensics and Security, vol. 19, pp. 8414–8427, 2024, doi:10.1109/TIFS.2024.3451356.
[10]A. Anitha, L. M. Saju, and B. Kamaraj, “Deepfake Detection Using XAI Based Deep Fusion Models,” in Proc. 2025 2nd Int. Conf. Computational Intelligence, Communication Technology and Networking (CICTN), Ghaziabad, India, 2025, pp. 526–531, doi:10.1109/CICTN64563.2025.10932587.
[11]B. Gowrisankar and V. L. L. Thing, “An Adversarial Attack Approach for eXplainable AI Evaluation on Deepfake Detection Models,” Computers & Security, vol. 139, Art. no. 103684, Apr. 2024, doi:10.1016/j.cose.2023.103684.
[12]G. Makridis et al., “Towards a Unified Multidimensional Explainability Metric: Evaluating Trustworthiness in AI Models,” in Proc. 2023 19th Int. Conf. Distributed Computing in Smart Systems and the Internet of Things (DCOSS-IoT), Pafos, Cyprus, 2023, pp. 504–511, doi:10.1109/DCOSS-IoT58021.2023.00084.
[13]T. Oorloff et al., “AVFF: Audio-Visual Feature Fusion for Video Deepfake Detection,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition (CVPR), pp. 27092–27102, 2024, doi:10.1109/CVPR52733.2024.02559.
[14]B. Akay, D. Karaboga, and R. Akay, “A Comprehensive Survey on Optimizing Deep Learning Models by Metaheuristics,” Artificial Intelligence Review, vol. 55, no. 2, pp. 829–894, Feb. 2022, doi:10.1007/s10462-021-09992-0.
[15]J. Singh, S. Rani, and G. Srilakshmi, “Towards Explainable AI: Interpretable Models for Complex Decision-Making,” in Proc. 2024 Int. Conf. Knowledge Engineering and Communication Systems (ICKECS), Chikkaballapur, India, 2024, pp. 1–5, doi:10.1109/ICKECS61492.2024.10616500.
[16]F. Bourebaa and M. Benmohammed, “Android Malware Detection Using Convolutional Deep Neural Networks,” in Proc. 2020 Int. Conf. Advanced Aspects of Software Engineering (ICAASE), Constantine, Algeria, 2020, pp. 1–7, doi:10.1109/ICAASE51408.2020.9380104.
[17]S. Mahdavifar, A. F. Abdul Kadir, R. Fatemi, D. Alhadidi, and A. A. Ghorbani, “Dynamic Android Malware Category Classification Using Semi-Supervised Deep Learning,” in Proc. 2020 IEEE DASC/PiCom/CBDCom/CyberSciTech, Calgary, AB, Canada, 2020, pp. 515–522, doi:10.1109/DASC-PICom-CBDCom-CyberSciTech49142.2020.00094.
[18]M. S. Khan et al., “Metaheuristic Algorithms in Optimizing Deep Neural Network Model for Software Effort Estimation,” IEEE Access, vol. 9, pp. 60309–60327, 2021, doi:10.1109/ACCESS.2021.3072380.
[19]S. Rakesh and S. Mahesh, “A Comprehensive Overview on Variants of Cuckoo Search Algorithm and Applications,” in Proc. 2017 Int. Conf. Electrical, Electronics, Communication, Computer, and Optimization Techniques (ICEECCOT), Mysuru, India, 2017, pp. 1–5, doi:10.1109/ICEECCOT.2017.8284569.
[20]M. O. Nassar and F. F. Al-Mashagba, “Optimal Ensemble Learning with Meta-Heuristics for Multiclass Classification of Syscall-Binder Interactions in Mobile Applications,” Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications, vol. 16, no. 1, pp. 26–48, 2025, doi:10.58346/jowua.2025.i1.002.
[21]M. O. Nassar and F. F. Al-Mashagba, “Novel Hybrid LOA-VCS Metaheuristic Approach with Adaptive Parameter Tuning for Network Intrusion Detection,” International Journal of Computer Network and Information Security, vol. 17, no. 5, pp. 31–44, 2025, doi:10.5815/ijcnis.2025.05.03.
[22]M. O. Nassar, “A Robust and Energy-Efficient Federated IDS for IIoT Using Spiking Neural Networks and Differential Evolution with Adversarial Resilience,” Iraqi Journal for Computer Science and Mathematics, vol. 6, no. 4, 2025, doi:10.52866/2788-7421.1328.
[23]Y. Li, X. Yang, P. Sun, H. Qi, and S. Lyu, “Celeb-DF: A Large-Scale Challenging Dataset for DeepFake Forensics,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition (CVPR), Seattle, WA, USA, 2020, pp. 3204–3213, doi:10.1109/CVPR42600.2020.00327.
[24]A. Rossler et al., “FaceForensics++: Learning to Detect Manipulated Facial Images,” in Proc. IEEE/CVF Int. Conf. Computer Vision (ICCV), Seoul, South Korea, 2019, pp. 1–11, doi:10.1109/ICCV.2019.00009.
[25]B. C. Soundarya and H. L. Gururaj, “A Novel Dense-Swish-CNN With Bi-LSTM Framework for Image Deepfake Detection,” IEEE Access, vol. 13, pp. 89641–89653, 2025, doi:10.1109/ACCESS.2025.3570761.
[26]R. Alenezi and S. A. Ludwig, “Explainability of Cybersecurity Threats Data Using SHAP,” in Proc. 2021 IEEE Symposium Series on Computational Intelligence (SSCI), Orlando, FL, USA, 2021, pp. 1–10, doi:10.1109/SSCI50451.2021.9659888.
[27]S. M. Lundberg and S.-I. Lee, “A Unified Approach to Interpreting Model Predictions,” in Advances in Neural Information Processing Systems, vol. 30, pp. 4768–4777, 2017, doi:10.5555/3295222.3295230.
[28]P. C. S. Mahesh and S. Hemalatha, “An Efficient Android Malware Detection Using Adaptive Red Fox Optimization Based CNN,” Wireless Personal Communications, vol. 126, no. 1, pp. 679–700, Sep. 2022, doi:10.1007/s11277-022-09765-0.
[29]MIT RAISE, “Day of AI,” 2025. [Online]. Available: https://dayofai.org/. [Accessed: Feb. 10, 2025].
[30]MIT, “Media Literacy in the Age of Deepfakes,” 2025. [Online]. Available: https://deepfakes.virtuality.mit.edu/. [Accessed: Feb. 10, 2025].
[31]C. P. Dai and F. Ke, “Educational Applications of Artificial Intelligence in Simulation-Based Learning: A Systematic Mapping Review,” Computers and Education: Artificial Intelligence, vol. 3, Art. no. 100087, 2022, doi:10.1016/j.caeai.2022.100087.
[32]A. Firdaus, N. B. Anuar, A. Karim, and M. F. A. Razak, “Discovering Optimal Features Using Static Analysis and a Genetic Search Based Method for Android Malware Detection,” Frontiers of Information Technology & Electronic Engineering, vol. 19, no. 6, pp. 712–736, Jun. 2018, doi:10.1631/FITEE.1601491.
[33]A. Mohanraj and K. Sivasankari, “Android Traffic Malware Analysis and Detection Using Ensemble Classifier,” Ain Shams Engineering Journal, vol. 15, no. 12, Art. no. 103134, Dec. 2024, doi:10.1016/j.asej.2024.103134.
[34]I. Goodfellow, J. Shlens, and C. Szegedy, “Explaining and Harnessing Adversarial Examples,” in Proc. Int. Conf. Learning Representations (ICLR), 2015.
[35]D. Arp, M. Spreitzenbarth, M. Hübner, H. Gascon, and K. Rieck, “Drebin: Effective and Explainable Detection of Android Malware in Your Pocket,” in Proc. 2014 Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 2014, doi:10.14722/ndss.2014.23247.
[36]A. H. Lashkari, A. F. A. Kadir, L. Taheri, and A. A. Ghorbani, “Toward Developing a Systematic Approach to Generate Benchmark Android Malware Datasets and Classification,” in Proc. 2018 Int. Carnahan Conf. Security Technology (ICCST), Montreal, QC, Canada, 2018, pp. 1–7, doi:10.1109/CCST.2018.8585560.
[37]F. Wei, Y. Li, S. Roy, X. Ou, and W. Zhou, “Deep ground truth analysis of current android malware,” in Proc. Int. Conf. on Cyber Security and Data Mining (CIDM)/Lecture Notes in Computer Science, 2017, pp. 252–276. doi: 10.1007/978-3-319-60876-1_12.
[38]M. Pinski and A. Benlian, “AI Literacy for Users – A Comprehensive Review and Future Research Directions of Learning Methods, Components, and Effects,” Computers in Human Behavior: Artificial Humans, vol. 2, no. 1, Art. no. 100062, Jan. 2024, doi:10.1016/j.chbah.2024.100062.
[39]Y. Walter, “Embracing the Future of Artificial Intelligence in the Classroom: The Relevance of AI Literacy, Prompt Engineering, and Critical Thinking in Modern Education,” International Journal of Educational Technology in Higher Education, vol. 21, no. 1, Art. no. 15, Feb. 2024, doi:10.1186/s41239-024-00448-3.
[40]S. Wang et al., “Artificial Intelligence in Education: A Systematic Literature Review,” Expert Systems with Applications, vol. 252, Art. no. 124167, Oct. 2024, doi:10.1016/j.eswa.2024.124167.
[41]M. Brundage et al., “The Malicious Use of Artificial Intelligence: Forecasting, Prevention, and Mitigation,” arXiv:1802.07228, 2018, doi:10.48550/arXiv.1802.07228.
[42]R. Clarke, “Principles for the Responsible Application of Generative AI,” Computer Law & Security Review, vol. 57, Art. no. 106131, Jul. 2025, doi:10.1016/j.clsr.2025.106131.
[43]A. Alzubaidi, “Detecting Android Malware Using Deep Learning Algorithms: A Survey,” Computers & Electrical Engineering, vol. 119, Art. no. 109544, Oct. 2024, doi:10.1016/j.compeleceng.2024.109544.
[44]R. Srinivasan and A. Chander, “Biases in AI Systems,” Communications of the ACM, vol. 64, no. 8, pp. 44–49, Aug. 2021, doi:10.1145/3464903.
[45]M. K. Das, M. Kumar, I. K. Kapil, and R. K. Yadav, “Deepfake Creation Using GANs and Autoencoder and Deepfake Detection,” in Proc. 2023 2nd Int. Conf. Vision Towards Emerging Trends in Communication and Networking Technologies (ViTECoN), Vellore, India, 2023, pp. 1–6, doi:10.1109/ViTECoN58111.2023.10157962.
[46]A. Hooda and M. Kumar, “Combatting Disinformation and Deepfake: Interdisciplinary Insights and Global Strategies,” in Proc. TENCON 2024 - 2024 IEEE Region 10 Conf., Singapore, 2024, pp. 1729–1732, doi:10.1109/TENCON61640.2024.10902954.
[47]I. D. Raji et al., “Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing,” in Proc. 2020 Conf. Fairness, Accountability, and Transparency, Barcelona, Spain, 2020, pp. 33–44, doi:10.1145/3351095.3372873.
[48]Y. Ou, Y. Feng, and Y. Sun, “Towards Accurate and Robust Architectures via Neural Architecture Search,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition (CVPR), pp. 5967–5976, 2024, doi:10.1109/CVPR52733.2024.00570.
[49]Y.-M. Zhang et al., “MOTE-NAS: Multi-Objective Training-Based Estimate for Efficient Neural Architecture Search,” Advances in Neural Information Processing Systems, vol. 37, pp. 100845–100869, 2024, doi:10.52202/079017-3198.
[50]J. Crabbé and M. van der Schaar, “Evaluating the Robustness of Interpretability Methods Through Explanation Invariance and Equivariance,” Advances in Neural Information Processing Systems, vol. 36, pp. 71393–71429, 2023, doi:10.52202/075280-3127.
[51]G. Liang, S. Michielssen, and S. Fattahi, “Enhancing Performance of Explainable AI Models with Constrained Concept Refinement,” in Proc. 42nd Int. Conf. Machine Learning (ICML), Proc. Machine Learning Research, vol. 267, pp. 37299–37338, 2025.
[52]A. Hooda et al., “D4: Detection of Adversarial Diffusion Deepfakes Using Disjoint Ensembles,” in Proc. IEEE/CVF Winter Conf. Applications of Computer Vision (WACV), pp. 3800–3810, 2024, doi:10.1109/WACV57701.2024.00377.
[53]Y. Xu et al., “TALL: Thumbnail Layout for Deepfake Video Detection,” in Proc. IEEE/CVF Int. Conf. Computer Vision (ICCV), pp. 22601–22611, 2023, doi:10.1109/ICCV51070.2023.02071.
[54]Z. Yan, Y. Luo, S. Lyu, Q. Liu, and B. Wu, “Transcending Forgery Specificity with Latent Space Augmentation for Generalizable Deepfake Detection,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition (CVPR), pp. 8984–8994, 2024, doi:10.1109/CVPR52733.2024.00858.
[55]J. Cheng et al., “Can We Leave Deepfake Data Behind in Training Deepfake Detector?” Advances in Neural Information Processing Systems, vol. 37, pp. 21979–21998, 2024, doi:10.52202/079017-0691.
[56]X. Cui, Y. Li, A. Luo, J. Zhou, and J. Dong, “Forensics Adapter: Adapting CLIP for Generalizable Face Forgery Detection,” in Proc. IEEE/CVF Conf. Computer Vision and Pattern Recognition (CVPR), pp. 19207–19217, 2025, doi:10.1109/CVPR52734.2025.01789.
[57]M. Naseer et al., “Obfuscated Malware Detection and Classification in Network Traffic Leveraging Hybrid Large Language Models and Synthetic Data,” Sensors, vol. 25, no. 1, Art. no. 202, 2025, doi:10.3390/s25010202.
[58]S. Poornima and R. Mahalakshmi, “Automated Malware Detection Using Machine Learning and Deep Learning Approaches for Android Applications,” Measurement: Sensors, vol. 32, Art. no. 100955, 2024, doi:10.1016/j.measen.2023.100955.
[59]Z. Wang, K. Zeng, J. Wang, and D. Li, “FAGnet: Family-Aware-Based Android Malware Analysis Using Graph Neural Network,” Knowledge-Based Systems, vol. 289, Art. no. 111531, 2024, doi:10.1016/j.knosys.2024.111531.
[60]A. Joshi et al., “Malware Analysis Using Transformer Based Models: An Empirical Study,” in Proc. 21st Int. Conf. Security and Cryptography (SECRYPT), pp. 858–865, 2024, doi:10.5220/0012855100003767.