Leveraging Interpretable Tsetlin Machine for PDF Malware Detection Rahul Jaiswal The Centre for Artificial Intelligence Research (CAIR)
arXiv:2607.09290v1 [cs.CR] 10 Jul 2026
Department of ICT, University of Agder, Norway [email protected]
Abstract—In the digital era, Portable Document Format (PDF) is one of the most widely used file formats for storing and exchanging digital documents due to its platform independence and rich functionality. However, these same capabilities have also made PDF files an attractive attack vector for cyberattackers, who embed malicious code within seemingly legitimate documents to compromise target systems. This paper presents a novel interpretable Tsetlin Machine (TM)-based framework for PDF malware detection. The proposed framework extracts salient features from PDF documents through static analysis without executing the files and employs rule-based learning to accurately classify benign and malicious PDF documents. Numerical evaluation on the RIT-PDFMal-2026 dataset demonstrates that the proposed framework achieves competitive performance, attaining an accuracy of 98.02% compared with several ML classifiers and existing methods. Moreover, the proposed framework provides intrinsic interpretability by transparently explaining its classification decisions. The combination of competitive detection performance, computational efficiency, and intrinsic interpretability makes the proposed framework a promising solution for practical PDF malware detection. Index Terms—Cybersecurity, Malware Detection, Portable Document Format, and Tsetlin Machine.
I. I NTRODUCTION In today’s digital world, the Portable Document Format (PDF) has become one of the most widely used document formats for sharing and exchanging information due to its portability, platform independence, and consistent rendering across different operating systems and software environments. The PDF files contain a complex internal structure consisting of both binary and ASCII elements and support advanced features such as embedded objects, JavaScript, and interactive actions, as shown in Fig. 1. Consequently, they can execute complex instructions when opened, extending their functionality beyond that of conventional static documents. The CloudFiles Report 2025 [1] states that approximately 15 trillion digital files were generated worldwide across various formats, including PDF, doc, images, videos, and graphic designs. Among these, PDF documents account for nearly 2.5 trillion files, representing around 17% of the total. The PDF files are widely used to store and share various types of documents, such as invoices, payslips, certificates, contracts, and reports. This widespread adoption across both personal and organizational applications has made PDF files one of the most prevalent formats for digital document exchange. 979-8-3315-1276-8/26/$31.00 ©2026 IEEE
Fig. 1: The PDF internal architecture. The widespread adoption of PDF documents and their advanced functionalities have made them an attractive target for cyberattackers. Features such as embedded objects and JavaScript can be exploited to deliver malicious payloads, making PDF files a common attack vector for malware distribution. Malicious PDFs can facilitate cyberattacks such as credential theft, spyware installation, unauthorized system access, browser exploitation, data exfiltration, phishing, and financial fraud [2]. Moreover, the rapid evolution of different attack techniques makes PDF malware detection a significant challenge for modern cybersecurity systems. The Reis Informatica Report 2026 [3] highlights that 74% of cyberattacks against Microsoft Windows systems in Canada were carried out via malicious PDF documents. To protect PDF documents, a variety of malware detection techniques are used. For example, signature-based methods [2] identify malware by matching files against known signatures, such as code patterns, hashes, or predefined behavioral characteristics. However, they struggle to identify newly emerging malware. Anomaly-based methods [4] learn the characteristics of normal files or system behavior and detect deviations. By relying on behavioral anomalies, these methods can identify unknown and evolving malware. Recently, machine learning (ML) techniques, such as decision trees, random forest, support vector machine, and gradient boosting, have been explored for PDF malware detection [5], [6]. Transfer learning [7]–[9] has also been used for detecting malware [10]. Some of these studies have employed post-hoc explainability techniques, such as Shapley Additive Explana-
tions (SHAP) and Local Interpretable Model-agnostic Explanations (LIME) [11], to interpret the predictions of blackbox ML classifiers. However, these techniques provide only approximate explanations rather than revealing the classifiers’ underlying decision-making process. This paper proposes a novel approach for PDF malware detection using an interpretable ML model based on the Tsetlin Machine (TM) [12], [13]. The proposed framework extracts salient features directly from PDF files without executing them and uses these features to classify documents as benign (normal) or malicious. Furthermore, unlike conventional black-box ML classifiers, the framework provides intrinsic interpretability by learning human-readable propositional clauses. Its classification decisions are directly explained through clause activation heatmaps, class-vote analysis, and feature-level contribution analysis, providing transparent and faithful insights that enhance the trustworthiness of PDF malware detection. The key contributions of this paper are: • Design of an effective TM framework for PDF malware detection using the RIT-PDFMal-2026 dataset. • Numerical evaluation showing comparable performance of the proposed framework over existing ML classifiers. • Interpretability analysis of the proposed TM framework through learned clauses and feature contributions, explaining its decision-making for PDF malware detection. The rest of this paper is structured as follows. Section II describes different classifiers employed. Section III describes the proposed TM framework. Section IV introduces the exper-
imental dataset. Section V presents and discusses the results. Finally, Section VI concludes the paper with future work. II. BACKGROUND This section describes the Tsetlin Machine and the machine learning classifiers used in this study. A. Tsetlin Machine The Tsetlin Machine (TM) is an interpretable, rule-based machine learning model that learns human-readable logical clauses using propositional logic [13]. By representing malicious cyberattack patterns as logical expressions, the TM enables transparent and explainable malware detection. The TM represents knowledge using a collection of conjunctive clauses (see Fig. 2) formed from binary input features. Each clause Cj consists of a conjunction of selected literals and their negations, and is defined as [13]: ^ ^ ¬xl , (1) xk ∧ Cj = k∈Ij
l∈I¯j
where xk ∈ {0, 1} denotes a binary feature, while Ij and I¯j represent the sets of included and negated literals, respectively. Each clause contributes either a positive or a negative vote toward a class, and the final class score is obtained by aggregating the votes from all clauses as: f (x) =
m X
wj Cj (x),
j=1
Fig. 2: Proposed TM framework for PDF malware detection.
|f (x)| ≤ T,
(2)
TABLE I: Features present in the RIT-PDFMal-2026 dataset. S.No. Feature name S.No. Feature name S.No. Feature name S.No. Feature name S.No. Feature name 1. pdfsize 2. metadata size 3. pages 4. xref length 5. title length 6. isEncrypted 7. embedded files 8. images 9. contains_text 10. pdf_ver 11. obj 12. endobj 13. stream 14. endstream 15. trailer 16. xref 17. startxref 18. page_command 19. Encrypt 20. ObjStm 21. JS 22. JavaScript 23. AA 24. OpenAction 25. Acroform 26. JBIG2Decode 27. RichMedia 28. Launch 29. EmbeddedFile 30. XFA 31. Colors 32. URI 33. BaseEncoding 34. Encoding 35. ProcSet 36. Registry 37. Resources 38. www 39. server 40. Root 41. BitsPerComponent 42. Label Total number of features = 42
where wj ∈ {+1, −1} denotes the polarity of clause j, and T is the voting threshold that constrains the accumulated clause votes to promote stable learning. The specificity parameter s > 1 controls the granularity of the learned clauses by regulating the probability of including literals during training. B. Machine Learning Classifiers In this study, seven ML classifiers are considered for performance comparison with the proposed TM framework. These classifiers include Decision Tree (DT), which constructs a hierarchical tree by recursively splitting the feature space based on decision rules [14]; Random Forest (RF), an ensemble learning method that combines the predictions of multiple decision trees through majority voting [15]; K-Nearest Neighbours (KNN), which classifies a sample according to the labels of its nearest neighbours in the feature space [15]; Naive Bayes (NB), a probabilistic classifier derived from Bayes’ theorem under the assumption of conditional feature independence [15], Logistic Regression (LR), which models class membership probabilities using a logistic function [16]; XGBoost, a gradient-boosting algorithm that incrementally builds decision trees to improve predictive accuracy [17]; and LightGBM (LGBM), a histogram-based gradient-boosting framework that adopts a leaf-wise tree growth strategy to achieve efficient training and high predictive performance [18]. III. P ROPOSED TM F RAMEWORK The proposed TM framework aims to distinguish malicious PDF documents from benign ones accurately. As illustrated in Fig. 2, the framework consists of several sequential stages, including feature extraction, preprocessing, classification, and interpretability analysis. In the first stage, salient features are extracted directly from PDF documents through static analysis without executing the files. The extracted features are then preprocessed by removing duplicate samples, handling missing values, performing data splitting, addressing class imbalance through random undersampling [19], applying feature normalization, and converting the features into a binary representation using feature binarization. The processed data are subsequently used to train the TM model, where appropriate hyperparameters are selected, and logical clauses are learned to capture discriminative patterns for malware detection. To improve the robustness and generalization of the model, k-fold cross-validation [20] is employed during training. Finally, the trained TM model classifies an unseen PDF document as either benign or
TABLE II: Samples in the RIT-PDFMal-2026 dataset. Samples Benign Malicious Total samples
Collected Corrupted Final 13,242 7 13,235 11,243 141 11,102 13,235 + 11,102 = 24,337
malicious by aggregating the votes of the learned positive and negative clauses. IV. E XPERIMENTAL DATASET The RIT-PDFMal-2026 dataset1 [21] is used to detect PDF malware. The dataset contains real-world malicious PDF samples collected between 2017 and 2025 from VirusTotal [22]. The Benign PDF files were gathered using a dedicated internet crawler that automatically downloaded PDF documents from different websites. The PDF file sizes range from 25 kB to 1.5 MB. The dataset is imbalanced and comprises 24,337 PDF samples described by 42 extracted numerical features, as presented in Table I and Table II, respectively. V. R ESULTS AND D ISCUSSIONS This section outlines the experimental setup, performance evaluation and discusses the classification results. A. Experimental Setup All algorithms are implemented in Python 3.13.6. The ML models are developed using Keras built on TensorFlow 2.20.0, while NumPy 2.3.2, Pandas 2.3.1, scikitlearn 1.7.2, imbalanced-learn 0.14.0, XGBoost 3.2.0, and LightGBM 4.6.0 are used for data preprocessing and performance evaluation. All experiments are conducted on a MacBook powered by an Apple M4 chip with 16 GB of RAM. B. Performance Evaluation The classification performance is evaluated using accuracy, macro-averaged precision, recall, and F1-score, which assign equal importance to each class and are therefore well suited for imbalanced datasets. Accuracy quantifies the overall proportion of correctly classified samples. Precision measures the proportion of correctly identified malicious PDF files, recall evaluates the ability to detect actual malicious PDF files, and the F1-score provides a balanced assessment by combining precision and recall into a single metric. In addition, class-wise precision, recall, and F1-score are reported for the proposed TM framework. The dataset is divided into 80% training 1 Dataset link: https://github.com/Mo-Alani/RIT-PDFMal-2026 (accessed on July 05, 2026).
TP + TN , Accuracy = TP + TN + FP + FN
13149
Number of Samples
12000
10000
8000
6000
4000
2222
2000
0
Benign (0)
Malicious (1)
Class
Fig. 3: Class imbalance in the dataset. 10519
Before Undersampling After Undersampling
10000
Number of Samples
and 20% testing subsets using stratified random sampling with a fixed random seed of 42. The training data are subsequently balanced through random undersampling, normalized, and binarized before applying five-fold stratified crossvalidation [20] for hyperparameter selection. The final TM model is then trained on the complete preprocessed training set and evaluated on the independent test set. Furthermore, a confusion matrix is used to examine class-wise prediction performance. The proposed TM framework is benchmarked against the ML classifiers described in Section II-B. Finally, the inference time, defined as the average time required to classify a single input sample, is measured to evaluate computational efficiency. To demonstrate the interpretability of the proposed TM framework, class-wise vote scores and clause activation heatmaps explain the underlying classification decisions. A larger vote score for a particular class indicates stronger evidence supporting the assignment of an input PDF to that class, reflecting greater confidence in the prediction. Furthermore, feature-level contribution analysis is performed to identify the most influential features driving the classification outcome. The performance metrics are defined as follows [23], [24]:
8000
6000
4000
2000
1777
0
1777
Benign (0)
1777
Malicious (1)
Class
Fig. 4: Balanced training classes.
(3)
0.98
F1-score =
2 × (Precision × Recall) , Precision + Recall
(4)
(5)
where T P , T N , F P , and F N denote the true positive, true negative, false positive, and false negative, respectively.
Accuracy
0.97
TP TP Precision = , Recall = , TP + FP TP + FN
0.96
0.95
0.94
0.93
Training Accuracy Testing Accuracy 0.92 0
10
20
30
40
50
Epoch
Fig. 5: Training and testing accuracy across epochs. C. Classification Performance 1) Data Pre-processing: The dataset is imbalanced, as summarized in Table II. During data preprocessing, 8,966 duplicate samples (36.84% of the dataset) are identified and removed, resulting in 15,371 unique samples comprising 13,149 benign and 2,222 malicious PDF files. No missing values are observed in the dataset. The class labels are encoded numerically, where 0 denotes benign PDFs, and 1 denotes malicious PDFs. Furthermore, the features Acroform, Colors, and BaseEncoding are excluded because they contain only zero values and therefore do not contribute to the classification process. After preprocessing, the dataset remains highly imbalanced, as illustrated in Fig. 3. Such imbalance can bias the learning process toward the majority class and adversely affect detection performance. To address this issue, the dataset is divided into training (80%) and testing (20%) subsets using stratified random sampling with a fixed random seed of 42. Random undersampling is then applied exclusively to the training set to balance the class distribution, as shown in Fig. 4, while preserving the original distribution of the test set for unbiased performance evaluation.
2) Classifier Training: The numerical features are normalized using min-max scaling, where the scaler is fitted on the training set and subsequently applied to the test set to ensure consistent feature scaling and stable model training. Since the TM requires binary-valued inputs for logical rule learning, the normalized features are discretized into intervals using the KBinsDiscretizer [20] and then converted into a binary representation suitable for clause construction. For a fair comparison, the same normalized data, without the binarization step, are used to train the ML classifiers described in Section II-B. All model parameters are selected empirically, and a fixed random seed of 42 is maintained throughout the experiments to ensure reproducibility. The parameter configurations and classification results of the TM and ML models are presented in Tables III and IV, respectively. Additionally, Fig. 5 illustrates the training and testing accuracy of the TM model across the training epochs, demonstrating stable convergence and consistent learning behavior. Table IV shows that the proposed TM achieves an accuracy of 98.02%, which is comparable to the slightly better-
TABLE III: Model parameters.
True Label: Benign (0) | Predicted Label: Benign (0) | Decision: Correct 10
Parameters Binarizer: KBinsDiscretizer, n bins=15, encode=onehot-dense, strategy=quantile number of clauses=250, T =15, s=5, weighted clauses=False, Epochs=50 criterion=gini n estimators=100, criterion=gini n neighbors=4, algorithm=brute, leaf size=10 var smoothing=1e-07 solver=liblinear, max iter=300 objective=binary:logistic, eval metric=logloss, tree method=hist, learning rate=0.2, max depth=10, n estimators=100 objective=binary, learning rate=0.2, n estimators=200, num leaves=20
LGBM
10
6 4 2
4
DT RF KNN NB LR XGBoost
8 Total Class Votes
Model TM
0
Benign (0)
Malicious (1) Classes
Fig. 7: Class-wise votes of a Benign sample. True Label: Benign (0) | Predicted Label: Benign (0) | Decision: Correct
1.0
0.8
Benign (0)
TABLE IV: Model performance. Accuracy Precision Recall F1-score Inference time (in %) (in %) (in %) (in %) (in µs) TM 98.02 96.03 95.95 95.99 2.853 DT 94.41 86.45 94.77 89.89 0.044 RF 98.28 96.02 97.13 96.56 3.901 KNN 94.31 86.77 92.75 89.39 3.659 NB 86.57 73.92 59.76 62.37 0.115 LR 79.74 66.06 74.43 68.13 0.032 XGBoost 97.37 93.06 97.06 94.92 0.319 LGBM 97.30 92.88 97.02 94.80 15.274
0.6
Classes
Model
0.4
Malicious (1)
0.2
0
25
50
75
100
125 150 Clause Index
175
200
0.0
225
Fig. 8: Clause activation heatmap of the same Benign sample. isEncrypted Encrypt
TABLE V: TM performance by class.
server
Class Benign Malicious
Precision (in %) 98.82 93.24
Recall (in %) 98.86 93.03
F1-score (in %) 98.84 93.14
Features
JBIG2Decode JS XFA Registry EmbeddedFile Launch
Benign (0)
JavaScript
0.8 0.989
0.011
Malicious (1)
True Label
0.6
0.4 0.070
0.930
0.2
Benign (0)
Malicious (1) Predicted Label
Fig. 6: TM confusion matrix. performing RF classifier (98.28%) and higher than those of XGBoost (97.37%) and LightGBM (97.30%). Moreover, the TM attains macro-averaged precision, recall, and F1-score of 96.03%, 95.95%, and 95.99%, respectively, demonstrating balanced classification performance across both benign and malicious PDF classes. Although RF achieves marginally higher accuracy and F1-score, it requires a longer inference time of 3.901 µs per sample, whereas the TM requires only 2.853 µs, making it approximately 26.9% faster during inference. Furthermore, the TM offers the additional advantage of intrinsic interpretability. Overall, the proposed TM framework delivers classification performance comparable to that of ML classifiers while enabling efficient inference.
0
2
4
6
8
10
12
14
Contribution Score
Fig. 9: Top ten features of the same Benign sample. Table V shows that the high evaluation metrics achieved for both benign and malicious PDF classes demonstrate the effectiveness of the TM model in accurately detecting PDF malware while maintaining balanced classification performance. Next, Fig. 6 presents the confusion matrix of the proposed TM model. The model correctly classifies 98.9% of benign PDF documents and 93.0% of malicious PDF documents. This corresponds to a false positive rate (FPR) of only 1.1%, indicating that very few benign PDFs are incorrectly misclassified as malicious, and a false negative rate (FNR) of 7.0%, showing that only a small proportion of malicious PDFs are misclassified as benign. These results demonstrate the strong classification capability of the TM model, with high detection accuracy and low misclassification rates for both classes. 3) TM Interpretability: To illustrate the interpretability of the proposed TM framework, Figs. 7, 8, 9, and 10 present the class-wise vote scores, clause activation heatmap, top ten contributing features, and feature-level contributions for a benign test sample, respectively. Figure 7 shows that the benign class receives the highest class vote (10), resulting in the correct classification of the input PDF as benign. As illustrated in Fig. 8, each cell
0 −10 −20 −30 −40 −50
www
OpenAction
AA
pdf_ver
contains_text
trailer
JavaScript
Launch
xref
BitsPerComponent
images
Registry
EmbeddedFile
JS
XFA
JBIG2Decode
server
startxref
Encrypt
URI
isEncrypted
pages
Encoding
ObjStm
ProcSet
page_command
Root
title length
Resources
metadata size
stream
xref length
pdfsize
endstream
obj
endobj
embedded files
Supports Sample Suppresses Sample Zero Reference
−60
RichMedia
Signed Contribution Score
10
Features (Sorted by Absolute Contribution)
Fig. 10: Feature-level contribution of the same Benign sample as in Fig. 7. Supports Sample Suppresses Sample Zero Reference
Signed Contribution Score
120 100 80 60 40 20 0
AA
Registry
OpenAction
contains_text
trailer
xref
embedded files
ObjStm
server
JBIG2Decode
EmbeddedFile
JavaScript
RichMedia
Launch
Encrypt
isEncrypted
JS
XFA
www
images
startxref
Root
BitsPerComponent
pdf_ver
title length
Resources
URI
ProcSet
pages
Encoding
xref length
page_command
stream
metadata size
obj
endstream
endobj
pdfsize
−20
Features (Sorted by Absolute Contribution)
Fig. 11: Feature-level contribution of the same Malicious sample as in Fig. 12. True Label: Malicious (1) | Predicted Label: Malicious (1) | Decision: Correct
True Label: Malicious (1) | Predicted Label: Malicious (1) | Decision: Correct
1.0
8
2
0.6
Classes
8
4
0.4
Malicious (1)
0.2
0 -2
0
-3
Total Class Votes
0.8
Benign (0)
6
Benign (0)
Malicious (1) Classes
Fig. 12: Class-wise votes of a Malicious sample. represents the activation state of a clause for the selected test sample, where yellow (1) denotes an active clause and dark purple (0) indicates an inactive clause. The benign class exhibits a larger number of activated clauses than the malicious class, leading to a higher accumulated class vote and, consequently, the correct prediction. Figure 9 presents the ten most influential features contributing to the classification, with isEncrypted emerging as the most significant feature for the selected benign PDF sample. Finally, Fig. 10 illustrates the feature-level contributions, where positive contribution values (green) support the benign sample prediction, whereas negative contribution values (orange) suppress evidence for the benign class. These results demonstrate the transparent and interpretable decision-making capability of the TM model. Similarly, Fig. 12 shows that the malicious class receives the
25
50
75
100
125 150 Clause Index
175
200
225
0.0
Fig. 13: Clause activation heatmap of same Malicious sample. highest class vote (8), resulting in the correct classification of the input PDF as malicious. Figure 13 also shows that the malicious class has more activated clauses than the benign class, yielding a higher cumulative vote and correct prediction. This observation is further supported by the feature-level contributions shown in Fig. 11, highlighting the transparent and interpretable decision-making capability of the TM model. In contrast, Fig. 14 shows a misclassification case in which a benign sample is incorrectly classified as malicious. The malicious class attains the highest class vote (2), whereas the correct benign class receives a vote of -9. This misclassification is likely caused by overlapping feature characteristics between benign and malicious samples, leading the TM model to assign a higher confidence to the malicious class. This behavior is further supported by the clause activation heatmap shown in Fig. 15, where the malicious class exhibits a larger number of activated clauses than the benign class.
True Label: Benign (0) | Predicted Label: Malicious (1) | Decision: Incorrect
ACKNOWLEDGEMENT This publication has emanated from the research project SecureIoTM: Ultra-low-energy IoT Intrusion Detection Systems using Logic-based Tsetlin Machines, under Grant Number 342167, funded by the Research Council of Norway.
2
2
-2 -4
-9
Total Class Votes
0
-6
R EFERENCES
-8
[1] CloudFiles, “Digital files presence in the world, 2025,” Accessed on July 05, 2026. [Online]. Available: https://www.cloudfiles.io/blog/how -many-files-are-there-in-the-world [2] P. Singh, S. Tapaswi, and S. Gupta, “Malware Detection in PDF and Office Documents: A Survey,” Information Security Journal: A Global Perspective, vol. 29, no. 3, pp. 134–153, 2020. [3] R. Informatica, “Malicious PDF Attacks on Microsoft Windows, 2026,” Accessed on July 05, 2026. [Online]. Available: https: //reisinformatica.com/malicious-pdf-attacks-on-microsoft-windows-202 6-protection-guide-for-canadian-businesses/ [4] S. Liu, J. Ming, Y. Zhou, J. Fu, and G. Peng, “VAPD: An Anomaly Detection Model for PDF Malware Forensics with Adversarial Robustness,” in 34th USENIX Security Symposium, 2025, pp. 4759–4778. [5] Q. Abu Al-Haija and H. Qattous, “PDF Malware Detection Based on Optimizable Decision Trees,” Electronics, vol. 11, no. 19, p. 3142, 2022. [6] F. Chbib and R. Khatoun, “Leveraging Machine Learning-Based PDF Malware Detection in Snort,” in Int. Conference on Electrical, Computer, Communications and Mechatronics Engineering. IEEE, 2024, pp. 1–6. [7] R. K. Jaiswal, M. Elnourani, S. Deshmukh, and B. Beferull-Lozano, “Leveraging Transfer learning for Radio Map Estimation via Mixture of Experts,” IEEE TCCN, vol. 12, pp. 846–863, 2025. [8] R. Jaiswal, M. Elnourani, S. Deshmukh, and B. Beferull-Lozano, “Location-free Indoor Radio Map Estimation using Transfer learning,” in 97th Vehicular Technology Conference. IEEE, 2023, pp. 1–7. [9] R. K. Jaiswal, M. Elnourani, S. Deshmukh, and B. Beferull-Lozano, “A Data-driven Transfer Learning Method for Indoor Radio Map Estimation,” IEEE TVT, vol. 75, no. 3, pp. 4261–4277, 2026. [10] C. Rong, G. Gou, M. Cui, Z. Li, and L. Guo, “TransNet: Unseen Malware Variants Detection using Deep Transfer Learning,” in Int. Conf. on Security and Privacy in Communication Systems, 2020, pp. 84–101. [11] S. M. Lundberg and S.-I. Lee, “A Unified Approach to Interpreting Model Predictions,” in NIPS, 2017, pp. 1–10. [12] S. Kundu, S. M. Mishra, G. Trivedi, and F. Merchant, “A Comprehensive Review of Tsetlin Machines: Concepts, Applications, Analysis, and the Future,” IEEE IoT Journal, vol. 13, no. 10, pp. 20 105–20 127, 2026. [13] O.-C. Granmo, “The Tsetlin Machine–A Game Theoretic Bandit Driven Approach to Optimal Pattern Recognition with Propositional Logic,” arXiv preprint arXiv:1804.01508, pp. 1–42, 2018. [14] L. Breiman, J. Friedman, R. A. Olshen, and C. J. Stone, Classification and Regression Trees. Chapman and Hall/CRC, 2017. [15] E. Alpaydin, Introduction to Machine Learning. MIT press, 2020. [16] D. W. Hosmer Jr, S. Lemeshow, and R. X. Sturdivant, Applied Logistic Regression. John Wiley & Sons, 2013. [17] T. Chen and C. Guestrin, “Xgboost: A Scalable Tree Boosting System,” in 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2016, pp. 785–794. [18] G. Ke, Q. Meng, and T. Finley, “Lightgbm: A Highly Efficient Gradient Boosting Decision Tree,” in NIPS, 2017, pp. 1–9. [19] S. Mishra, “Handling Imbalanced Data: SMOTE vs Random Undersampling,” International Research Journal of Engineering and Technology, vol. 4, no. 8, pp. 317–320, 2017. [20] R. Bhagwat, M. Abdolahnejad, and M. Moocarme, Applied Deep Learning with Keras: Solve Complex Real-life Problems with the Simplicity of Keras. Packt Publishing Ltd, 2019. [21] M. M. Alani and E. Damiani, “RIT-PDFMal-2026: A Comprehensive Benchmark Dataset for PDF Malware Detection,” IEEE Access, vol. 14, pp. 97 841–97 855, 2026. [22] VirusTotal, “Malicious Sample,” Accessed on July 05, 2026. [Online]. Available: https://www.virustotal.com/gui/home/upload [23] R. Jaiswal, “Performance Analysis of Voice Activity Detector in Presence of Non-stationary Noise,” in 11th International Conf. on Robotics, Vision, Signal Processing and Power Applications, 2022, pp. 59–65. [24] R. K. Jaiswal and R. K. Dubey, “Non-intrusive Speech Quality Assessment using Context-aware Neural Networks,” International Journal of Speech Technology, vol. 25, no. 4, pp. 947–965, 2022.
Benign (0)
Malicious (1) Classes
Fig. 14: Class-wise votes of another Benign sample. True Label: Benign (0) | Predicted Label: Malicious (1) | Decision: Incorrect
1.0
0.8
Benign (0) Classes
0.6
0.4
Malicious (1)
0.2
0
25
50
75
100
125 150 Clause Index
175
200
225
0.0
Fig. 15: Clause activation heatmap of the sample as in Fig. 14. TABLE VI: Comparison with related works. Reference Dataset Method Accuracy Inference Time Interpretable Paper [4] Contagio VAPD 99.54% No Paper [5] Evasive-2022 Optimized DT 98.84% 2.174 µs No Paper [6] Contagio ML Ensemble 93.00% Yes Proposed RIT-PDFMal TM 98.02% 2.853 µs Yes
D. State-of-the-Art Comparison Table VI shows that, although the compared methods are evaluated on different datasets, the proposed TM framework achieves competitive accuracy while providing intrinsic interpretability and low inference time. This enables a balanced trade-off between performance, efficiency, and transparency, making it a practical solution for PDF malware detection. VI. C ONCLUSIONS AND F UTURE W ORK This paper presents an interpretable Tsetlin Machine (TM)based framework for PDF malware detection. The proposed framework extracts salient features directly from PDF documents through static analysis without executing the files and employs rule-based learning to accurately classify benign and malicious PDF files. Experimental results on the RITPDFMal-2026 dataset demonstrate that the proposed framework achieves competitive performance compared with several ML classifiers and existing methods while providing intrinsic interpretability. This enhances the transparency and trustworthiness of the classification process, making the proposed framework a promising solution for practical PDF malware detection. Nevertheless, the study is limited to a single public dataset, and the interpretability analysis is demonstrated using representative case studies rather than a formal user-based evaluation. Future work will focus on extending the evaluation to diverse PDF malware datasets encompassing a wider range of malware families and validating its interpretability through user studies.