arrow
Return

Regression-Aware Continual Learning for Android Malware Detection

delete2026-07-16
delete0
delete
OA
AI
D
Daniele Ghiani
D
Daniele Angioni
G
Giorgio Piras
A
Angelo Sotgiu
L
Luca Minnei
S
Srishti Gupta
M
Maura Pintor
F
Fabio Roli
B
Battista Biggio
DOI:10.1109/tifs.2026.3714132delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Malware evolves rapidly, forcing machine learning-based detectors to be continuously updated. With antivirus vendors processing hundreds of thousands of new samples daily, datasets can grow to billions of examples, making full retraining impractical. Continual learning (CL) has emerged as a scalable alternative, enabling incremental updates without full data access while mitigating catastrophic forgetting. In this work, we analyze a critical yet overlooked issue in this context: security regression. Unlike forgetting, which manifests as a drop in average performance on previously seen data, security regression captures harmful sample-level prediction changes, e.g., malware samples that were correctly detected before an update but evade detection afterward. This poses serious risks in security-critical applications, as the silent reintroduction of previously detected threats may undermine users’ trust in the update process, leading them to perceive a regression in security even if the average model performance has actually improved. We first formalize and quantify security regression in CL-based malware detectors, revealing that up to 3-6% of malware experience it after model updates. We then address this issue by introducing a regression-aware framework to the CL setting. Specifically, we instantiate it via Positive Congruent Training (PCT), showing seamless integration with any prior CL strategy. Experiments on the ELSA, Tesseract, and AZ-Class datasets show that our method effectively halves regression across different CL scenarios while maintaining strong detection performance over time.
Keywords:
Android malware
continual learning
negative flips
regression testing

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.3K
Citations:
2.3W

Organization

U
University of Cagliari
Scholars:
1.5K
Papers: 580
Citations: 9.1K
Cited Papers

Cited Papers

errShare
errSave
Deep Android Malware Detection
err2017-03-22
err0
errOAAI
errNiall McLaughlin; Jesus Martinez del Rincon; BooJoong Kang; Suleiman Yerima; Paul Miller; Sakir Sezer; Yeganeh Safaei; Erik Trickel; Ziming Zhao; Adam Doupé; Gail Joon Ahn
errShare
errSave
Unraveling the Key of Machine Learning-based Android Malware Detection
err
err0
PREAI
errLiu,Jiahao; Zeng,Jun; Pierazzi,Fabio; Yang,Ziqi; Cavallaro,Lorenzo; Liang,Zhenkai
errShare
errSave
A continual learning survey: Defying forgetting in classification tasks
err2021-01-01
err0
errOAAI
errMatthias Delange; Rahaf Aljundi; Marc Masana; Sarah Parisot; Xu Jia; Ales Leonardis; Greg Slabaugh; Tinne Tuytelaars
errShare
errSave
Positive-Congruent Training: Towards Regression-Free Model Updates
err2021-06-01
err0
errOAAI
errSijie Yan; Yuanjun Xiong; Kaustav Kundu; Shuo Yang; Siqi Deng; Meng Wang; Wei Xia; Stefano Soatto
errShare
errSave
Elodi: Ensemble Logit Difference Inhibition for Positive-Congruent Training
err
IF0
err2024-12-01
err0
PREAI
errYue Zhao; Yantao Shen; Yuanjun Xiong; Shuo Yang; Wei Xia; Zhuowen Tu; Bernt Schiele; Stefano Soatto
errShare
errSave
Android Security: A Survey of Issues, Malware Penetration, and Defenses
err2015-01-01
err294
errOAAI
errFaruki, Parvez; Bharmal, Ammar; Laxmi, Vijay; Ganmoor, Vijay; Gaur, Manoj Singh; Conti, Mauro; Rajarajan, Muttukrishnan
errShare
errSave
researcher View more