JOURNAL ARTICLE

Adaptive and scalable Android malware detection through online learning

Abstract

It is well-known that malware constantly evolves so as to evade detection and this causes the entire malware population to be non-stationary. Contrary to this fact, prior works on machine learning based Android malware detection have assumed that the distribution of the observed malware characteristics (i.e., features) do not change over time. In this work, we address the problem of malware population drift and propose a novel online machine learning based framework, named DroidOL to handle it and effectively detect malware. In order to perform accurate detection, security-sensitive behavior are captured from apps in form of inter-procedural control-flow sub-graph features using a state-of-the-art graph kernel. In order to perform scalable detection and to adapt to the drift and evolution in malware population, an online passive-aggressive classifier is used. In a large-scale comparative analysis with more than 87,000 apps, DroidOL achieves 84.29% accuracy outperforming two state-of-the-art malware techniques by more than 20% in their typical batch learning setting and more than 3% when they are continuously re-trained. Our experimental findings strongly indicate that online learning based approaches are highly suitable for real-world malware detection.

Keywords:
Malware Computer science Scalability Machine learning Artificial intelligence Population Android malware Android (operating system) Concept drift Online learning Classifier (UML) Computer security Operating system World Wide Web Data stream mining

Metrics

67
Cited By
7.14
FWCI (Field Weighted Citation Impact)
24
Refs
0.98
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Advanced Malware Detection Techniques
Physical Sciences →  Computer Science →  Signal Processing
Network Security and Intrusion Detection
Physical Sciences →  Computer Science →  Computer Networks and Communications
Software Testing and Debugging Techniques
Physical Sciences →  Computer Science →  Software

Related Documents

JOURNAL ARTICLE

Context-Aware, Adaptive, and Scalable Android Malware Detection Through Online Learning

A. Sankara NarayananMahinthan ChandramohanLihui ChenYang Liu

Journal:   IEEE Transactions on Emerging Topics in Computational Intelligence Year: 2017 Vol: 1 (3)Pages: 157-175
BOOK-CHAPTER

PetaDroid: Adaptive Android Malware Detection Using Deep Learning

ElMouatez Billah KarbabMourad Debbabi

Lecture notes in computer science Year: 2021 Pages: 319-340
JOURNAL ARTICLE

Advanced Android Malware Detection through Deep Learning Optimization

Ahmed Alhussen

Journal:   Engineering Technology & Applied Science Research Year: 2024 Vol: 14 (3)Pages: 14552-14557
© 2026 ScienceGate Book Chapters — All rights reserved.