<p>The rapid expansion of internet-connected digital systems has intensified cybersecurity risks, with malicious applications increasingly exploiting vulnerabilities to steal sensitive user data. Conventional malware detection systems often fail to recognize novel threats, as attackers continually evolve their tactics using sophisticated obfuscation and delivery mechanisms. To address this challenge, we propose&#xa0;an&#xa0;Explainable Machine Learning-based Android Malware Detection&#xa0;(EML-AMD) framework leveraging the&#xa0;Red Deer Algorithm (RDA)&#xa0;for optimized feature selection and&#xa0;SMOTE (Synthetic Minority Over-sampling Technique)&#xa0;to mitigate class imbalance and reduce false negatives. The RDA enhances robustness against known and zero-day malware by identifying the most discriminative features. At the same time, an ensemble of heterogeneous classifiers, including&#xa0;support vector machine (SVM), Decision Tree (DT), Random Forest (RF), K-Nearest Neighbour (KNN), Gradient Boosting (GB), and Extreme Gradient Boosting (XGB), ensures high detection accuracy. The proposed framework is evaluated on the&#xa0;CICMalDroid2020&#xa0;dataset. Our framework achieves state-of-the-art performance, with&#xa0;XGB attaining 98.78% accuracy, 98.74% precision, 98.76% recall, and a 98.76% F1-score. These results demonstrate&#xa0;EML-AMD superiority in detecting evolving Android malware while maintaining interpretability through explainable artificial intelligence principles. The results of the proposed method demonstrate its effectiveness for Android malware detection.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

EML-AMD: an explainable machine learning framework for adaptive android malware detection

  • Aakansha Patel,
  • Samarendra Mohan Ghosh

摘要

The rapid expansion of internet-connected digital systems has intensified cybersecurity risks, with malicious applications increasingly exploiting vulnerabilities to steal sensitive user data. Conventional malware detection systems often fail to recognize novel threats, as attackers continually evolve their tactics using sophisticated obfuscation and delivery mechanisms. To address this challenge, we propose an Explainable Machine Learning-based Android Malware Detection (EML-AMD) framework leveraging the Red Deer Algorithm (RDA) for optimized feature selection and SMOTE (Synthetic Minority Over-sampling Technique) to mitigate class imbalance and reduce false negatives. The RDA enhances robustness against known and zero-day malware by identifying the most discriminative features. At the same time, an ensemble of heterogeneous classifiers, including support vector machine (SVM), Decision Tree (DT), Random Forest (RF), K-Nearest Neighbour (KNN), Gradient Boosting (GB), and Extreme Gradient Boosting (XGB), ensures high detection accuracy. The proposed framework is evaluated on the CICMalDroid2020 dataset. Our framework achieves state-of-the-art performance, with XGB attaining 98.78% accuracy, 98.74% precision, 98.76% recall, and a 98.76% F1-score. These results demonstrate EML-AMD superiority in detecting evolving Android malware while maintaining interpretability through explainable artificial intelligence principles. The results of the proposed method demonstrate its effectiveness for Android malware detection.