arrow
Return

Explainable Ensemble Learning for Robust Android Malware Detection

delete2026-02-11
delete0
PRE
AI
G
Gopalakrishnan Venkatesh
J
Jasin David Jaya Singh
S
S. Loganand
K
K. Jivesh
A
Ayman Altameem
A
Ateeq Ur Rehman *
S
Seada Hussen *
A
Ahmad Almogren
DOI:10.1002/spy2.70206delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
The primary cybersecurity threat addressed in this work arises from Android malware that bypasses conventional fingerprint-based defenses by exploiting permission misuse, intent filters, and code obfuscation techniques. To address this challenge, this paper proposes an interpretable and rational malware detection framework based on ensemble learning. Five machine learning classifiers-Logistic Regression, Random Forest, Gradient Boosting, XGBoost, and Neural Networks-were evaluated using three Android malware datasets, namely CHIMERA, Mendeley, and NaticusDroid. The proposed methodology employs a strict preprocessing pipeline, a hybrid interactive feature selection and elimination strategy, five-fold cross-validation, and hyperparameter optimization. Experimental results show that ensemble models, particularly XGBoost and Random Forest, achieve predictive accuracies exceeding 97% even on limited or noisy datasets such as Mendeley and NaticusDroid. Interpretability analysis using SHAP reveals that critical Android permissions, including READ_PHONE_STATE, SEND_SMS, and RECEIVE_BOOT_COMPLETED, strongly influence model decisions and are closely associated with real-world malicious behaviors such as data exfiltration and persistence. Duplicate sample filtering improves computational efficiency and slightly mitigates overfitting, while adversarial evaluation provides insights into model robustness against evasion attacks. Overall, the findings demonstrate that ensemble learning combined with explainable AI yields malware detection models that are both highly accurate and transparent, providing a practical foundation for interpretable and adversarially resilient Android malware detection. Future work will focus on real-world deployment.
Keywords:
android malware detection
CHIMERA
cybersecurity
hybrid feature selection
machine learning
NaticusDroid and Mendeley datasets
SHAP
XGBoost

Journal

S
Security and Privacy
IF:
2.1
Papers:
125
Citations:
717

Organization

A
amrita vishwa vidyapeetham coimbatore
Scholars:
741
Papers: 752
Citations: 1
A
adama science & technology university
Scholars:
135
Papers: 69
Citations: 0
A
Amrita Vishwa Vidyapeetham
Scholars:
6.8K
Papers: 4.2K
Citations: 3.3K
G
gachon university
Scholars:
1.9K
Papers: 1.2K
Citations: 0
K
king saud university
Scholars:
5.4K
Papers: 2.9K
Citations: 1
researcher View more organizations