Context-aware, Adaptive and Scalable Android Malware Detection through Online Learning (extended version)

It is well known that Android malware constantly evolves so as to evade detection. This causes the entire malware population to be nonstationary. Contrary to this fact, most of the prior works on machine learning based android malware detection have assumed that the distribution of the observed malware characteristics (i.e., features) does not change over time. In this paper, we address the problem of <italic>malware population drift</italic> and propose a novel online learning based framework to detect malware, named <sc>Casandra</sc> (<underline>C</underline> ontext-aware, <underline>A</underline>daptive and <underline>S</underline>calable <underline>ANDR</underline>oid m <underline>A</underline>lware detector). In order to perform accurate detection, a novel graph kernel that facilitates capturing apps security-sensitive behaviors along with their context information from dependence graphs is proposed. Besides being accurate and scalable, <sc>Casandra</sc> has specific advantages: first, being adaptive to the evolution in malware features over time; second, explaining the significant features that led to an apps classification as being malicious or benign. In a large-scale comparative analysis, <sc>Casandra</sc> outperforms two state-of-the-art techniques on a benchmark dataset achieving 99.23% F-measure. When evaluated with more than 87 000 apps collected in-the-wild, <sc>Casandra</sc> achieves 89.92% accuracy, outperforming existing techniques by more than 25% in their typical batch learning setting and more than <inline-formula><tex-math notation="LaTeX"> $\text{7}$</tex-math></inline-formula>% when they are continuously retained, while maintaining comparable efficiency.

Paper

References (74)

Scroll for more · 38 remaining

Similar papers

© 2026 NYSGPT2525 LLC