International Journal of Scientific Engineering and Research (IJSER)
Call for Papers | Fully Refereed | Open Access | Double Blind Peer Reviewed | ISSN: 2347-3878


Downloads: 2

India | Computer Science | Volume 14 Issue 9, September 2026 | Pages: 13 - 17


Comparative Evaluation of Tree-Based Ensembles on Memory-Resident Malware Datasets

Dr. Channakeshava RN

Abstract: The rapid proliferation of fileless and memory-resident malware presents critical challenges for traditional disk-based security mechanisms, necessitating advanced volatile memory forensics. This study presents a comprehensive evaluation of four tree-based ensemble algorithms- Random Forest, Extra Trees, XGBoost, and LightGBM- applied to the benchmark CIC-MalMem-2022 dataset containing approximately 58,600 memory artifact samples. Both binary classification and granular multi-class evaluation across 16 distinct malware families and benign states were conducted. Experimental results demonstrate that while binary classification yields near-linear separability across all ensembles, LightGBM achieves the leading multi-class classification performance with a weighted F1-score of 0.7674. Computational efficiency profiling on a resource-constrained Intel Core i3 local architecture confirms an ultra-low inference latency of 0.0064 milliseconds per sample and a minimal model memory footprint of 0.05 KB, highlighting operational viability for endpoint security sensors. Additionally, post-hoc interpretability via TreeSHAP and Gini impurity analysis identifies critical kernel-level features- such as service scan properties and DLL distributions- providing transparent attribution for automated threat detection systems.

Keywords: Volatile memory forensics, malware detection, tree-based ensembles, LightGBM, SHAP interpretability, CIC-MalMem-2022


View Article PDF


Rate This Article


Top