ISSN: 2245-4578 (Online Version) ISSN:2245-1439 (Print Version)
Feature-Driven Framework for Interpretable Detection and Analysis of Android Malware Through Network and Application Behaviors
PDF
HTML

Keywords

cybersecurity analytics
DELTA-XAI sensitivity
network traffic analysis
metaheuristic algorithms
Android malware detection

How to Cite

[1]
C. . Tan and X. . Li, “Feature-Driven Framework for Interpretable Detection and Analysis of Android Malware Through Network and Application Behaviors”, JCSANDM, vol. 15, no. 05, pp. 1311–1336, Oct. 2026.

Abstract

This paper presents a complete framework for feature-driven Android malware detection that combines predictive modeling with explainable artificial intelligence to improve classification accuracy, interpretability, and operational dependability. The system initiates by examining network-flow metrics, including Source Port (SP), Initial Window Bytes Forward (IW), packet rates, and user activity indicators, derived from a publicly accessible dataset including 355,630 cases across four classifications: Adware, Scareware, SMS malware, and benign. Feature preprocessing utilizes the Variance Inflation Factor (VIF) analysis to eliminate multicollinearity to discern the most important variables, hence assuring a non-redundant and highly relevant feature collection. Subsequently, Gradient Boosting Classifier (XGBC) and Decision Tree Classifier (DTC) are augmented with metaheuristic optimization algorithms, Tailor Optimization Algorithm (TOA) and Spotted Deer Optimization Algorithm (SDOA), to boost convergence, stability, and generalization. Model interpretability is attained by Delta-XAI, which identifies SP, IW, and User Interaction/Write operations as the principal features, collectively representing approximately 80% of the explanatory power of the top features. Assessment by five-fold cross-validation indicates that the XGBC+TOA (XGTO) configuration attains an overall accuracy of 98.0%, exhibiting excellent precision and Matthews Correlation Coefficient (MCC), surpassing all other models. This framework combines feature-centric selection, enhanced learning, and explainable AI to deliver a dependable, interpretable, and pragmatic approach for identifying Android malware, thereby connecting data-driven analysis with practical cybersecurity implementations.

https://doi.org/10.13052/jcsm2245-1439.1557
PDF
HTML

References

M. Chau and R. Reith, Smartphone market share, IDC Corp., USA, 2020, 444.

L. Eze, U. B. Chaudhry, and H. Jahankhani, Quantum-Enhanced Machine Learning for Cybersecurity: Evaluating Malicious URL Detection, Electronics, 2025, 14(9): 1827.

J. Ylitalo, The Interface Between Technology and People in Cybersecurity: Technological Solutions Supporting Humans in Organizational Protection, 2025.

H. Rathod and S. Agal, A study and overview on current trends and technology in mobile applications and its development, International Conference on ICT for Sustainable Development, 2023, pp. 383–395.

A. Karim, S. A. Ali Shah, R. Bin Salleh, M. Arif, R. M. Noor, and S. Shamshirband, Mobile botnet attacks-An emerging threat: Classification, review and open issues, KSII Transactions on Internet and Information Systems, 2015, 9(4): 1471–1492.

S. Aonzo, G. C. Georgiu, L. Verderame, and A. Merlo, Obfuscapk: An open-source black-box obfuscation tool for Android apps, SoftwareX, 2020, 11: 100403.

D. J. Edwards, Malware Defenses, in Critical Security Controls for Effective Cyber Defense: A Comprehensive Guide to CIS 18 Controls, Springer, 2024.

M. Suleman, T. R. Soomro, T. M. Ghazal, and M. Alshurideh, Combating against potentially harmful mobile apps, International Conference on Artificial Intelligence and Computer Vision, 2021, 1377: 154–173.

F. A. Aboaoja, A. Zainal, F. A. Ghaleb, B. A. S. Al-Rimy, T. A. E. Eisa, and A. A. H. Elnour, Malware detection issues, challenges, and future directions: A survey, Applied Sciences, 2022, 12(17): 8482.

H. A. Abdulbaqi, A. M. Ghandour, and T. A. Jawad, Develop secure software specifications for Android app concealing the information and safeguarding data, Iraqi Journal of Computer Science and Mathematics, 2024, 5(4): 243–257.

A. El Hami, Methods and Applications of Artificial Intelligence: Dynamic Response, Learning, Random Forest, Linear Regression, Interoperability, Additive Manufacturing and Mechatronics, John Wiley & Sons, 2025, 2: 1–225.

U. Baldangombo, Z. Kherlenchimeg, and U. Naidansuren, Android malware detection using machine learning, Journal of Institute of Mathematics and Digital Technology, 2024, 6(1): 130–145.

A. Anand, J. P. Singh, and V. Dhoundiyal, Android malware detection using HexCode features, 2024, pp. 1–26.

S. Y. Yerima, S. Sezer, and I. Muttik, Android malware detection using parallel machine learning classifiers, International Conference on Next Generation Mobile Apps, Services and Technologies, 2014, pp. 37–42.

R. M. Hamad et al., COVID-19 Pandemic and its Impact on Sustainable Development Goals: An Observation of South Asian Perspective, 2020.

S. Kotha, S. Hariharasitaraman, D. Saravanan, and S. Ahmed, Android malware detection using deep learning, International Conference on Advancements in Smart, Secure and Intelligent Computing (ASSIC), 2025, pp. 1–4.

V. Bansal, N. Baliyan, and M. Ghosh, Dynamic Android malware detection using Light Gradient Boosting Machine, International Conference on Artificial Intelligence and Speech Technology (AIST), 2022, pp. 1–6.

H. H. R. Manzil and S. M. Naik, Detection approaches for Android malware: Taxonomy and review analysis, Expert Systems with Applications, 2024, 238: 122255.

H. A. Al-Kaaf, Integrated Information Gain with Extra Tree Algorithm for Feature Permission Analysis in Android Malware Classification, Universiti Teknologi Malaysia, 2022.

M. P. Singh and H. K. Khan, Malware detection in Android applications using machine learning, International Conference on Advances in Electronics, Communication, Computing and Intelligent Information Systems (ICAECIS), 2023, pp. 105–110.

X. Y. Liew, N. Hameed, and J. Clos, An investigation of XGBoost-based algorithm for breast cancer classification, Machine Learning with Applications, 2021, 6: 100154.

T. Chen and C. Guestrin, XGBoost: A scalable tree boosting system, ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2016, pp. 785–794.

A. Beucher, A. B. Møller, and M. H. Greve, Artificial neural networks and decision tree classification for predicting soil drainage classes in Denmark, Geoderma, 2019, 352: 351–359.

T. Hamadneh et al., On the application of Tailor Optimization Algorithm for solving real-world optimization application, International Journal of Intelligent Engineering Systems, 2025, 18(1): 1–12.

J. Zhang, Spotted Deer Optimization Algorithm, HAL, 2026, pp. 1–13.

R. M. O’Brien, A caution regarding rules of thumb for variance inflation factors, Quality & Quantity, 2007, 41(5): 673–690.

N. Kapure, H. Joshi, P. Kumari, R. Mistri, and M. Mali, FRAME: Forward Recursive Adaptive Model Extraction-A technique for advance feature selection, arXiv preprint arXiv:2501.11972, 2025. https://doi.org/10.48550/arXiv.2501.11972.

S. Bates, T. Hastie, and R. Tibshirani, Cross-validation: What does it estimate and how well does it do it? Journal of the American Statistical Association, 2024, 119(546): 1434–1445.

A. De Carlo, E. Parimbelli, N. Melillo, and G. Nicora, Introducing δ-XAI: A novel sensitivity-based method for local AI explanations, arXiv preprint arXiv:2407.18343, 2024. https://doi.org/10.48550/arXiv.2407.18343.

M. S. Islam, I. Hussain, M. M. Rahman, S. J. Park, and M. A. Hossain, Explainable artificial intelligence model for stroke prediction using EEG signal, Sensors, 2022, 22(24): 9859.

S. Chakraborty, Android Malware Detection, Kaggle, 2023.

Creative Commons License

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.

Copyright (c) 2026 Journal of Cyber Security and Mobility

Downloads

Download data is not yet available.