CyberXAI: Explainable Multi-Modal Threat Detection & Classification
CyberXAI is an industrial-grade threat intelligence and cyber-defense framework combining:
- Module A (Malware Analysis):
- Static Analysis: PE header, entropy, section analysis on BODMAS dataset (57 PE features).
- Dynamic Analysis: Memory dump inspection on Obfuscated-MalMem2022 (55 volatility memory features, Ransomware vs Spyware vs Trojan).
- API Call Sequence Analysis: Behavioral sequence mining on MalAPI 2019 (n-gram TF-IDF on API traces).
- Module B (URL Threat Analysis):
- HybridURLNet (Deep Learning): Character-level 1D-CNN + Bidirectional GRU with residual lexical fusion trained on Kaggle cloud GPUs (88.61% accuracy, 0.95 Malware F1).
- URLInfraGNN (Graph Attention Network): Heterogeneous bipartite infrastructure graph linking URLs, Domains, IPs, and Autonomous System Numbers (ASNs) with Layer-2 Attention explainability.
- Soft Voting Ensemble: CatBoost + LightGBM + XGBoost + Random Forest on 79 hybrid lexical, host, and domain features.
- Sub-Second Explainability: Neural gradient saliency, Layer-2 GAT attention weights, and Tree SHAP surrogate attribution.
Model Zoo & Repository Contents
| File | Module / Architecture | Parameters / Size | Key Metric |
|---|---|---|---|
url_dl_model.pt |
HybridURLNet (1D-CNN + BiGRU + Residual Lexical MLP) | 52,060 params (208 KB) | 88.61% Test Accuracy (0.95 Malware F1) |
url_gnn_model.pt |
URLInfraGNN (2-Layer Pure PyTorch Graph Attention Network) | 15,588 params (70 KB) | 83.33% Graph Test Accuracy (0.94 Malware F1) |
url_voting_classifier.joblib |
Soft Voting Ensemble (CatBoost, LightGBM, XGBoost, RF) | 13.9 GB | Comprehensive ensemble on hybrid URL features |
url_shap_surrogate_rf.joblib |
Fast Tree SHAP surrogate explainer | 3.01 MB | Sub-second local feature attributions (<35ms) |
malware_dynamic_rf_multiclass_family.joblib |
Random Forest dynamic memory family classifier | 286 MB | Multi-class malware family classification |
malware_dynamic_xgb_multiclass_family.joblib |
XGBoost dynamic memory family classifier | 5.84 MB | Multi-class malware family classification |
malware_static_rf.joblib |
Random Forest PE static classifier | 531 MB | Static executable triage |
malware_static_xgb.joblib |
XGBoost PE static classifier | 2.75 MB | Static executable triage |
malware_api_sequence_rf.joblib |
Random Forest behavioral API sequence classifier | 110 MB | Multi-class behavioral classifier |
malware_api_sequence_xgb.joblib |
XGBoost behavioral API sequence classifier | 6.80 MB | Multi-class behavioral classifier |
Quickstart: Running Inference with Deep Learning & GNN
1. HybridURLNet Deep Learning Inference
import torch
import joblib
from huggingface_hub import hf_hub_download
from src.url_pipeline.dl_model import HybridURLNet
repo = "siddudavant/cyberxai-models"
model_path = hf_hub_download(repo_id=repo, filename="url_dl_model.pt")
scaler_path = hf_hub_download(repo_id=repo, filename="url_dl_scaler.joblib")
encoder_path = hf_hub_download(repo_id=repo, filename="url_dl_label_encoder.joblib")
model = HybridURLNet(lexical_dim=15, num_classes=4)
model.load_state_dict(torch.load(model_path, map_location="cpu"))
model.eval()
2. URLInfraGNN Graph Attention Network Inference
import torch
from huggingface_hub import hf_hub_download
from src.url_pipeline.gnn_model import URLInfraGNN
repo = "siddudavant/cyberxai-models"
gnn_path = hf_hub_download(repo_id=repo, filename="url_gnn_model.pt")
model = URLInfraGNN(in_dim=15, hidden_dim=64, num_classes=4, heads=2)
model.load_state_dict(torch.load(gnn_path, map_location="cpu"))
model.eval()
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support