arrow
Return

ActDroid: An active learning framework for Android malware detection

delete2025-10-24
delete0
delete
OA
AI
A
Ali Muzaffar
H
Hani Ragab Hassen
H
Hind Zantout
M
Michael A. Lones
DOI:10.1016/j.cose.2025.104724delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
The growing popularity of Android requires malware detection systems that can keep up with the pace of new software being released. According to a recent study, a new piece of malware appears online every 12 seconds. To address this, we treat Android malware detection as a streaming data problem and explore the use of active online learning as a means of mitigating the problem of labelling applications in a timely and cost-effective manner. Specifically, we develop a semi-supervised active learning framework that incrementally trains online learning models using only samples with low prediction confidence, while detecting concept drift and retraining the models when drift is observed. Our resulting framework achieves accuracies of up to 96% on a balanced dataset, requires as little as 24% of the training data to be labelled, and compensates for concept drift that occurs between the release and labelling of an application. We also consider the broader practicalities of online learning within Android malware detection, and systematically explore the trade-offs between using different static, dynamic and hybrid feature sets to classify malware. We find that features derived from static API calls lead to the best performing models, though models based around lower-dimensional permission and opcode feature sets provide a potentially more practical basis for deployment, with only a marginal deficit in accuracy. Dynamic and hybrid feature sets are found to significantly increase feature extraction costs with no net benefit to predictive performance.
Keywords:
Malware detection
Android security
Machine learning
Online learning
Active learning
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

H
heriot-watt university
Scholars:
619
Papers: 402
Citations: 0