Conventional Machine Learning-Based Android Malware Detectors

Daoudi N., Allix K., Bissyandé T.F., Klein J.

Advances in Information Security, vol. 91, pp. 175-196, 2025

Abstract

Android operating system provides various services to users. However, its widespread use has also attracted individuals developing malicious software to exploit vulnerabilities. Indeed, malware developers target Android markets to distribute harmful apps, leading to drastic consequences such as financially exploiting Android users. In tackling the challenges posed by Android malware, machine learning has emerged as a promising tool for automatic detection. The literature on Android malware detection is rich with a variety of ML-based approaches designed to distinguish malware from legitimate samples. In this chapter, we overview five state-of-the-art Android malware detectors that rely on machine learning. Specifically, we present the dataset used in their performance evaluation. We delve into the feature set adopted by the different approaches and describe how they are embedded in vector spaces. Furthermore, we conduct an in-depth exploration of the classification process, including the ML algorithms used, their hyper-parameters, and the methodology employed in the evaluation. Additionally, we provide examples showcasing the performance effectiveness of the studied approaches. Lastly, we discuss the limitations and challenges of ML-based malware detectors that need to be overcome to advance the research field.

People

DAOUDI Nadia

DAOUDI Nadia

Software Engineering

Send an email

How can we help you?

By content type (optional)