Document Type

Article

Source of Publication

Array

Publication Date

9-1-2026

Abstract

The convergence of media analytics, Cyber threat Intelligence (CTI) and trustworthy artificial intelligence has become essential for modern cybersecurity systems operating over large-scale, heterogenous data sources. In particular, Social Media Intelligence (SOCMINT) and Open Source Intelligence (OSINT) provide high-volume, real-time signals that complement structured CTI frameworks for early-stage malware and adversarial threat detection. However, integrating these unstructured and dynamic sources with Structured Threat Information Expression (STIX) remains challenging due to its hierarchical complexity, semantic redundancy, and computational overhead in resource-constrained environments. This paper proposes an explainable and optimized intelligence pipeline (BERT-STIX) that unifies SOCMINT, OSINT, and STIX-based CTI using deep contextual language models, including BERT, SecBERT, and ELMo. To ensure efficiency and adaptability, nature-inspired optimization techniques – Genetic Algorithms (GA), Particle Swarm Optimization (PSO), and Ant Colony Optimization (ACO) – are employed to tune model representations while preserving semantic relationships between malware entities and MITRE ATT&CK techniques. Experimental results demonstrate that SecBERT achieves superior baseline performance compared to BERT and ELMO (accuracy: 89.4% vs. 87.2% and 85.7%), while PSO enhanced optimization further improved classification accuracy, reaching up to 97.9%. Beyond performance, the proposed framework emphasizes explainability and trustworthiness through SHAP-based analysis. Global, local, and drift-based explanations reveal how SOCMINT-driven signals and structured CTI indicators jointly influence model predictions, while uncertainty analysis highlights confidence variations under ambiguous threat conditions. Overall, the proposed approach bridges media-driven intelligence with structured CTI, enabling interpretable and efficient malware detection suitable for deployment in next-generation intelligent security systems.

ISSN

2590-0056

Publisher

Elsevier BV

Volume

31

Disciplines

Computer Sciences

Keywords

Malware analysis, Nature inspired, Optimization, Social media analytics, Threat intelligence, XAI

Scopus ID

105048059297

Creative Commons License

Creative Commons Attribution 4.0 International License
This work is licensed under a Creative Commons Attribution 4.0 International License.

Indexed in Scopus

yes

Open Access

yes

Open Access Type

Gold: This publication is openly available in an open access journal/series

Share

COinS