Repeated memory snapshots carrying the same
dataset-provided malware identifier can cross record-level splits.
A high score may then measure recurring-identifier triage
rather than behavioral generalization to an unseen identifier.
We audit this dependence in CIC-MalMem-2022 and present
Evidence-Aware Malware XAI (EAM-XAI), a routed behavioral–
retrieval system: unseen or unavailable identifiers use a behavioral
LightGBM model, known pure identifiers use label-count retrieval,
and mixed-label identifiers use a local Extra-Trees specialist. The
filename-derived token is not treated as a verified executable hash.
Snapshot-stratified five-fold evaluation reaches 99.85% ± 0.06%
accuracy, whereas malware-identifier-disjoint evaluation reaches
85.49% ± 1.06%. A retrospective multi-snapshot extension that
requires joint access to an unseen identifier’s available captures improves a reproduced single-snapshot baseline from 85.50%±0.98%
to 89.93% ± 1.30%.
