Threshold Tuning Explorer

A malware classifier outputs a probability, not a verdict. The decision thresholdconverts that score into “malware” or “benign” — and where you place it decides the trade-off between catching threats and raising false alarms. Drag the threshold below and watch the confusion matrix respond. Distributions mirror a balanced CIC-MalMem-2022 split (58,596 samples); the model is the ANN baseline from my MSc dissertation.

Classifier score distribution
BenignMalwareFalse positiveFalse negative
0.000.250.500.751.00Predicted probability of malware →0.50
Decision threshold0.50
Confusion matrixthreshold 0.50
Pred. malware
Pred. benign
Actual malware
26,720
2,578
Actual benign
1,126
28,172
91.2%
3.8%
96.0%
93.5%
93.7%
ROC curveAUC 0.985
False-positive rateTrue-positive rate

The dot is your current operating point. Sliding the threshold walks it along the curve — up-left means fewer false alarms, down-left means missed malware.

© 2026 Isuru Panditharatne · Threshold Tuning Explorer← The Lab