The invention relates to a malicious
software detection method based on multi-
feature fusion and
interpretability analysis. According to the technical scheme, static features are extracted through'macroscopic-microscopic 'double paths, and a dynamic behavior
knowledge graph is constructed in combination with sandbox monitoring,
stain analysis and semantic abstraction and converted into feature vectors through
graph embedding; multi-
modal feature deep interaction and accurate classification are realized through a double-end cross attention-triple fusion-deep classification architecture; a hierarchical interpretable framework is constructed based on cross-
modal causal alignment, case reasoning and anti-fact analysis, and a complete decision evidence chain is generated. The method has the advantages that comprehensive representation of the form,
semantics and intention of malicious
software is achieved, the detection precision and robustness are remarkably improved, meanwhile, the'
black box 'dilemma of the model is solved, credible explanation is provided for
security analysis, the method is suitable for
complex network threat detection scenes, and it is verified through experiments that the method has good application prospects. According to the method, the
detection rate of the Windows malicious
software is remarkably increased, and the
false alarm rate is effectively reduced.