arrow
Return

Android malware detection by using graph optimization of static features based on pre-trained language models

delete2026-01-06
delete0
PRE
AI
N
Nghi Hoang Khoa
D
Doan Minh Trung
D
Duong The Dat
P
Phan The Duy
V
Van-Hau Pham
N
Nguyen Tan Cam *
DOI:10.1016/j.infsof.2026.108012delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
• This study proposed APSDroid, a novel method for detecting and classifying Android malware by integrating permissions-intents (PIs) and API call graphs (ACGs) with pre-trained language models (PLMs). • Forensic analysis was conducted by extracting and analyzing critical PIs and ACGs to effectively uncover normal and malicious behaviors. • APSDroid incorporates graph optimization techniques such as community detection and centrality measures to reduce graph complexity while maintaining the contextual flow of application behavior. • The approach addresses challenges in processing large-scale graph data for PLMs, including token length constraints and computational demands. • Experiments conducted on the CICMalDroid2020 dataset demonstrated the effectiveness of APSDroid, achieving an accuracy of 97.40% for malware detection and 94.23% for malware category classification. It also maintains strong resilience under obfuscation techniques, with F1-scores of 98.69% (binary) and 83.98% (multi-class), outperforming several SOTA approaches.

Journal

Information and Software Technology cover
Information and Software Technology
IF:
4.3
Papers:
3.7K
Citations:
7.7K

Organization

No organization information available