arrow
Return

Graph-augmented multi-modal learning framework for robust android malware detection

delete2025-11-03
delete0
delete
OA
AI
M
Muhammad Usama Tanveer
K
Kashif Munir
H
Hasan J. Alyamani
S
Syed Rizwan Hassan *
M
Muhammad Sheraz
T
Teong Chee Chuah *
DOI:10.1038/s41598-025-22169-xdelete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
The widespread adoption of Android has made it a primary target for increasingly sophisticated malware, posing a significant challenge to mobile security. Traditional static or behavioural approaches often struggle with obfuscation and lack contextual integration across multiple feature domains. In this work, we propose GIT-GuardNet, a novel Graph-Informed Transformer Network that leverages multi-modal learning to detect Android malware with high precision and robustness. GIT-GuardNet fuses three complementary perspectives: (i) static code attributes captured through a Transformer encoder, (ii) call graph structures modelled via a Graph Attention Network (GAT), and (iii) temporal behaviour traces learned using a Temporal Transformer. These encoders are integrated using a cross-attention fusion mechanism that dynamically weighs inter-modal dependencies, enabling more informed decision-making under both benign and adversarial conditions. We conducted comprehensive experiments on a large-scale dataset comprising 15,036 Android applications, including 5,560 malware samples from the Drebin project. GIT-GuardNet achieves state-of-the-art performance, reaching 99.85% accuracy, 99.89% precision, and 99.94 AUC, outperforming traditional machine learning models, single-view deep networks, and recent hybrid approaches like DroidFusion. Ablation studies confirm the complementary impact of each modality and the effectiveness of the cross-attention design. Our results demonstrate the strong generalization of GIT-GuardNet in obfuscated and stealthy threats, low inference overhead, and practical applicability for real-world mobile threat detection. This study provides a powerful and extensible framework for future research in secure mobile computing and intelligent malware defence.
Keywords:
Android malware detection
Multi-modal learning
Static code analysis
Call graph modelling
Temporal behavior analysis
Deep learning
Cross-attention fusion
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Scientific Reports cover
Scientific Reports
IF:
3.9
Papers:
27.1W
Citations:
83.5W

Organization

D
department of computer engineering
Scholars:
473
Papers: 306
Citations: 0
F
faculty of artificial intelligence and engineering
Scholars:
24
Papers: 21
Citations: 0
I
Institute of Information Technology
Scholars:
39
Papers: 25
Citations: 0
researcher View more organizations