Disclosed herein are devices, systems, and methods for detecting, understanding, and classifying malicious actions and / or behaviors in
software (e.g.,
malware), including hidden malicious actions. Specifically, disclosed embodiments use
natural language approaches to understand malicious
software and provide explanations for classification results. At least one embodiment constructs a
knowledge graph that includes textual explanations from source materials (e.g., articles), collecting one or more sets of dynamic program traces from one or more instances of
malware, and constructing and training a model (also referred to herein as Trace-BERT) using the one or more sets of dynamic program traces. Forced execution of sample segments of computer code can also be used to identify hidden or novel malicious actions.