Fig. 17

LIME explanations for misclassified samples from KronoDroid dataset. (a) False negative: a malware sample misclassified as benign, showing atypically low discriminative features (fcntl64, dup) that push the prediction toward benign. (b) False positive: a benign sample misclassified as malware, showing unusually high fsync and getdents64 activity. Red bars indicate features supporting malware classification; blue bars indicate features supporting benign classification.