Contacts

GUO Yuejun

Send an email

TANG Qiang

Send an email
Financial supports

ANANSI

Android Malware Defense: Localization-Facilitated Evasive Behavior Analysis and Countermeasures

Inspiration

Android powers over 3.9 billion devices worldwide, and its openness has made it a prime target for cybercriminals — malware samples now exceed 35 million and continue to grow. Traditional detection methods struggle to keep up: rule-based systems miss new threats, and even machine learning models often can't explain why they flag something as malicious or pinpoint exactly where in the code the danger lies. This "black-box" problem makes it hard for security analysts to trust, validate, or improve detection systems — leaving organizations exposed to increasingly evasive malware that adapts faster than defenses can respond.

Innovation

ANANSI is a fundamental research project that builds a fine-grained, explainable pipeline for detecting and defending against Android malware. The project will:

  • Develop an LLM-powered framework to pinpoint malicious code down to the method (and potentially line) level within app bytecode.
  • Build a dynamic analysis framework that simulates real-world conditions to expose evasive malware behaviors invisible to static analysis.
  • Design a robustness testing framework that uses explainable AI to uncover why detection models fail and generate targeted countermeasures.
  • Integrate all of this into a continuous learning pipeline that keeps detection models adaptive as malware evolves.

Rather than just flagging malware, ANANSI traces exactly which code causes it, why it evades detection, and how models can be hardened against it. This connects three research areas — localization, dynamic behavior analysis, and adversarial robustness — that are normally studied in isolation.

Impact

The project's main deliverables include:

  • A fine-grained localization framework and benchmark dataset for identifying malicious payloads in Android code.
  • A dynamic execution analysis framework that uncovers hidden, condition-triggered malware behavior.
  • A robustness testing and enhancement framework, with countermeasures against adversarial evasion tactics.
  • A unified, continuously improving malware analysis pipeline integrating all of the above.

By making Android malware detection more precise, explainable, and resilient, ANANSI will help security teams move from reactive patching to proactive, adaptive defense. Its outputs have real-world applications in enterprise mobile security, threat intelligence platforms, and app-store vetting — helping safeguard billions of Android users and strengthening Luxembourg's role in cybersecurity research and standards.

Project Profile

Start date
 
1.3.2026
End date
 
28.2.2029
Duration
 
36 Months
Keywords
 
mobile apps; Android applications; malware; app analysis

Funding

Funding Framework
 
FNR CORE
Call
 
2025 CORE Call
 
This project has received funding from the Luxembourg National Research Fund (FNR) through CORE project ANANSI (C25/IS/19577554/ANANSI).

Partners

People

How can we help you?

By content type (optional)