Document Type
Article
Source of Publication
Array
Publication Date
9-1-2026
Abstract
The convergence of media analytics, Cyber threat Intelligence (CTI) and trustworthy artificial intelligence has become essential for modern cybersecurity systems operating over large-scale, heterogenous data sources. In particular, Social Media Intelligence (SOCMINT) and Open Source Intelligence (OSINT) provide high-volume, real-time signals that complement structured CTI frameworks for early-stage malware and adversarial threat detection. However, integrating these unstructured and dynamic sources with Structured Threat Information Expression (STIX) remains challenging due to its hierarchical complexity, semantic redundancy, and computational overhead in resource-constrained environments. This paper proposes an explainable and optimized intelligence pipeline (BERT-STIX) that unifies SOCMINT, OSINT, and STIX-based CTI using deep contextual language models, including BERT, SecBERT, and ELMo. To ensure efficiency and adaptability, nature-inspired optimization techniques – Genetic Algorithms (GA), Particle Swarm Optimization (PSO), and Ant Colony Optimization (ACO) – are employed to tune model representations while preserving semantic relationships between malware entities and MITRE ATT&CK techniques. Experimental results demonstrate that SecBERT achieves superior baseline performance compared to BERT and ELMO (accuracy: 89.4% vs. 87.2% and 85.7%), while PSO enhanced optimization further improved classification accuracy, reaching up to 97.9%. Beyond performance, the proposed framework emphasizes explainability and trustworthiness through SHAP-based analysis. Global, local, and drift-based explanations reveal how SOCMINT-driven signals and structured CTI indicators jointly influence model predictions, while uncertainty analysis highlights confidence variations under ambiguous threat conditions. Overall, the proposed approach bridges media-driven intelligence with structured CTI, enabling interpretable and efficient malware detection suitable for deployment in next-generation intelligent security systems.
DOI Link
ISSN
Publisher
Elsevier BV
Volume
31
Disciplines
Computer Sciences
Keywords
Malware analysis, Nature inspired, Optimization, Social media analytics, Threat intelligence, XAI
Scopus ID
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 International License.
Recommended Citation
Al-Obeidat, Feras; Rashad, Muhammad Saad; Amin, Muhammad; Ali, Waqas; Khan, Bilal; and Anwar, Sajid, "Trustworthy and explainable malware threat intelligence through social media analytics and nature-inspired optimization" (2026). All Works. 8071.
https://zuscholars.zu.ac.ae/works/8071
Indexed in Scopus
yes
Open Access
yes
Open Access Type
Gold: This publication is openly available in an open access journal/series