IJEM Vol. 16, No. 4, 8 Aug. 2026
Cover page and Table of Contents: PDF (size: 507KB)
PDF (507KB), PP.344-355
Views: 0 Downloads: 0
Malware Detection, Android, Machine Learning, Permission-to-Exploitation Associations, Android APK Decompilation, Internet Fragmentation
Android's widespread adoption and open ecosystem make it a primary target for malware, a challenge exacerbated by internet fragmentation resulting in non-stationary data distributions across regions. This work presents AuthProtect, a scalable malware detection framework based on incremental learning and a novel permission-to-exploitation mapping approach that links 135 permissions to 25 malware development techniques. The system is validated on a balanced dataset of 82,704 benign and 82,704 malicious applications, partitioned into three geographic regions to assess robustness to distribution shifts. A similarity-based selective training strategy improves computational efficiency by training only on novel samples (cosine similarity < threshold τ), while a test-then-train mechanism enhances robustness by sequentially processing samples to avoid data exposure bias. Evaluation on four benchmark datasets (Naticusdroid, Malgenome, CICMalDroid 2020, Android Malware Dataset) demonstrates accuracy ranging from 0.9573 to 0.9992, with a maximum accuracy of 0.9982 on real-world data. We provide a comparative analysis against state-of-the-art methods and ablation studies quantifying the contribution of each component. Limitations include dependency on the completeness of permission-technique mapping and computational overhead for real-time deployment on resource-constrained devices.
Maksim Iavich, Razvan Bocu, "AuthProtect: An Incremental Learning Framework for Android Malware Detection via Permission-Exploitation Mapping", International Journal of Engineering and Manufacturing (IJEM), Vol.16, No.4, pp.344-355, 2026. DOI:10.5815/ijem.2026.04.23
[1]StatCounter, "Mobile Operating System Market Share Worldwide”. Accessed: Sep. 25, 2025. [Online]. Available: https://gs.statcounter.com/os-market-share/mobile/worldwide.
[2]Kaspersky, "Turkey, Russia, Southeast Asia and Latin America hit by Android threats, Kaspersky identifies". Accessed: Sep. 26, 2024. [Online]. Available: https://www.kaspersky.com/about/press-releases/turkey-russia-southeast-asia-and-latin-america-hit-by-android-threats-kaspersky-identifies .
[3]S. Fadilpašic. "Dangerous new Android malware infects 11 million devices — here’s what we know", TechRadar. Accessed: Sep. 20, 2025. [Online]. Available: https://www.techradar.com/pro/security/dangerous-new-android-malware-infects-11-million-devices-here-s-what-we-know.
[4]ST. Sutter, T. Kehrer, M. Rennhard, B. Tellenbach, and J. Klein, “Dynamic Security Analysis on Android: A systematic literature review”, IEEE Access, vol. 12, pp. 57261–57287, 2024. doi: https://doi.org/10.1109/ACCESS.2024.3390612.
[5]H. Zhu, H. Wei, L. Wang, Z. Xu, and V. S. Sheng, “An effective end-to-end android malware detection method”, Expert Systems With Applications, vol. 218, p. 119593, Jan. 2023 doi: https://doi.org/10.1016/j.eswa.2023.119593.
[6]C. E. Rubio-Medrano et al., “DyPolDroid: Protecting against permission-abuse attacks in Android”, Information Systems Frontiers, Oct. 2022. doi: https://doi.org/10.1007/s10796-022-10328-8 .
[7]P. Arntz, "New variant of Android SpyJoker malware removed from Play Store after 3 million installs", Malwarebytes Labs. Accessed: Dec. 26, 2024. [Online]. Available: https://www.malwarebytes.com/blog/news/2022/07/new-variant-of-android-spyjoker-malware-removed-from-play-store-after-3-million-installs . Accessed: Jun. 22, 2024.
[8]Ferdous, Jannatul, et al. "A survey on ml techniques for multi-platform malware detection: Securing pc, mobile devices, iot, and cloud environments." Sensors 25.4 (2025): 1153.
[9]Wajahat, J. He, N. Zhu, T. Mahmood, A. Nazir, F. Ullah, et al., "Securing Android IoT devices with GuardDroid transparent and lightweight malware detection", Ain Shams Eng. J., vol. 15, no. 5, May 2024. doi: https://doi.org/10.1016/j.asej.2024.102642.
[10]R. Gupta, K. Sharma, and R. K. Garg, “Innovative Approach to Android Malware Detection: Prioritizing Critical Features Using Rough Set Theory”, Electronics, vol. 13, no. 3, p. 482, Jan. 2024. doi: https://doi.org/10.3390/electronics13030482.
[11]X. Li, L. Liu, Y. Liu, and H. Liu, “Detecting Android malware: A multimodal fusion method with fine-grained feature”, Information Fusion, vol. 114, pp. 102662–102662, Sep. 2024. doi: https://doi.org/10.1016/j.inffus.2024.102662.
[12]Wang, Xusheng, et al. "MFDroid: A stacking ensemble learning framework for Android malware detection." Sensors 22.7 (2022): 2597.
[13]Almomani, T. Almashat, and W. El-Shafai, “Maloid-DS: Labeled Dataset for Android Malware Forensics”, IEEE Access, vol. 12, pp. 73481–73546, 2024. doi: https://doi.org/10.1109/access.2024.3400211.
[14]Prasad, S. Chandra, Ibrahim Atoum, N. Ahmad, and Yazeed Alqahhas, “A collaborative prediction approach to defend against amplified reflection and exploitation attacks”, Electronic Research Archive, vol. 31, no. 10, pp. 6045–6070, Jan. 2023. doi: https://doi.org/10.3934/era.2023308.
[15]R. Verma and S. Chandra, “RepuTE: A soft voting ensemble learning framework for reputation-based attack detection in fog-IoT milieu”, Engineering Applications of Artificial Intelligence, vol. 118, p. 105670, Feb. 2023. doi: https://doi.org/10.1016/j.engappai.2022.105670.
[16]A. Daniel, R. Deebalakshmi, R. Thilagavathy, T. Kohilakanagalakshmi, S. Janakiraman, and Balamurugan Balusamy, “Optimal feature selection for malware detection in cyber physical systems using graph convolutional network”, Computers & Electrical Engineering, vol. 108, pp. 108689–108689, Apr. 2023. doi: https://doi.org/10.1016/j.compeleceng.2023.108689.