<p>Android operating system, renowned for its open-source nature and flexibility, holds the largest global market share, yet faces significant security challenges, particularly from malware threats. Existing studies often rely on complex feature engineering for malware detection, leading to cumbersome methods prone to noise and lacking effective feature selection mechanisms. Some deep learning approaches also suffer from low efficiency. This paper introduces a lightweight and interpretable Android malware detection system called “FEdroid.” By focusing on code segments that utilize sensitive APIs, the system simplifies the analysis process and extracts key information, employing XGBoost for cross-feature selection to concentrate on a minimal yet crucial feature set. This approach enhances detection accuracy while reducing device resource usage. Experimental results demonstrate that the system achieved an accuracy of 98.26% and a false negative rate of only 1.86% across 18,653 APK samples, significantly improving detection efficiency and accuracy while minimizing deployment resource dependency. Furthermore, the application of Shapley values for interpretive analysis greatly enhances the transparency and understandability of the classifier model, thereby improving the overall interpretability of the system.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

FEdroid: a lightweight and interpretable machine learning-based android malware detection system

  • Hong Huang,
  • Weitao Huang,
  • Yinghang Zhou,
  • Wengang Luo,
  • Yunfei Wang

摘要

Android operating system, renowned for its open-source nature and flexibility, holds the largest global market share, yet faces significant security challenges, particularly from malware threats. Existing studies often rely on complex feature engineering for malware detection, leading to cumbersome methods prone to noise and lacking effective feature selection mechanisms. Some deep learning approaches also suffer from low efficiency. This paper introduces a lightweight and interpretable Android malware detection system called “FEdroid.” By focusing on code segments that utilize sensitive APIs, the system simplifies the analysis process and extracts key information, employing XGBoost for cross-feature selection to concentrate on a minimal yet crucial feature set. This approach enhances detection accuracy while reducing device resource usage. Experimental results demonstrate that the system achieved an accuracy of 98.26% and a false negative rate of only 1.86% across 18,653 APK samples, significantly improving detection efficiency and accuracy while minimizing deployment resource dependency. Furthermore, the application of Shapley values for interpretive analysis greatly enhances the transparency and understandability of the classifier model, thereby improving the overall interpretability of the system.