Abstract
Android malware attributes to the increasing usage of code obfuscation, polymorphism, and dynamic execution. In this study, we propose XEnDroid (Xplainable Ensemble Droid), an advanced stacking ensemble approach for detecting malware on Android phones by combining random forest, convolution neural network, and transformer models under a logistic regression model. Dynamic behavioral features such as API, system call, and network activities are used for extracting features that are later reduced using PCA and processed through SMOTE. Model transparency is ensured by incorporating SHAP and LIME, which helps in understanding both global feature significance and prediction explanation locally. An experimental analysis using the CICMalDroid2020 dataset proves the effectiveness of the proposed method, as it results in 94.6% accuracy, 94.1% precision, 94.2% recall, 94.1% F1-score, and 0.986 AUC score.References
- Aslan, Ömer Aslan, and Refik Samet. "A Comprehensive Review on Malware Detection Approaches." IEEE Access 2020, vol. 8, 6249-6271.
- Ijaz, Muhammad, Muhammad Hanif Durad, and Maliha Ismail. "Static and Dynamic Malware Analysis using Machine Learning." In 2019 16th International Bhurban Conference on Applied Sciences and Technology (IBCAST), IEEE, 2019, 687-691
- Rieck, Konrad, Philipp Trinius, Carsten Willems, and Thorsten Holz. "Automatic Analysis of Malware Behavior using Machine Learning." Journal of Computer Security 2011, vol. 19, no. 4, 639-668.
- Alzaylaee, Mohammed K., Suleiman Y. Yerima, and Sakir Sezer. "DL-Droid: Deep Learning based Android Malware Detection using Real Devices." Computers & Security 2020, vol. 89, 101663.
- Arshad, Saba, Munam A. Shah, Abdul Wahid, Amjad Mehmood, Houbing Song, and Hongnian Yu. "SAMADroid: a novel 3-level hybrid Malware Detection Model for android operating system." IEEE Access 2018, vol. 6, 4321-4339.
- Wu, Yueming, Xiaodi Li, Deqing Zou, Wei Yang, Xin Zhang, and Hai Jin. "Malscan: Fast Market-Wide Mobile Malware Scanning by Social-Network Centrality Analysis." 34th IEEE/ACM International Conference on Automated Software Engineering (ASE), IEEE, 2019, 139-150.
- Gibert, Daniel, Carles Mateu, and Jordi Planes. "HYDRA: A Multimodal Deep Learning Framework for Malware Classification." Computers & Security 2020, vol. 95, 101873.
- Kim, Hyunjoo, Jonghyun Kim, Youngsoo Kim, Ikkyun Kim, Kuinam J. Kim, and Hyuncheol Kim. "Improvement of Malware Detection and Classification using API Call Sequence Alignment and Visualization." Cluster Computing 2019, vol. 22, no. Suppl 1, 921-929.
- Owoh, Nsikak, John Adejoh, Salaheddin Hosseinzadeh, Moses Ashawa, Jude Osamor, and Ayyaz Qureshi. "Malware Detection based on API Call Sequence Analysis: A gated Recurrent unit–Generative Adversarial Network Model Approach." Future Internet 2024, vol. 16, no. 10, 369.
- Das, Swagatam, Sankha Subhra Mullick, and Ivan Zelinka. "On supervised class-imbalanced learning: An Updated Perspective and Some Key Challenges." IEEE Transactions on Artificial Intelligence 2022, vol. 3, no. 6, 973-993.
- Zhang, Zhibo, Hussam Al Hamadi, Ernesto Damiani, Chan Yeob Yeun, and Fatma Taher. "Explainable Artificial Intelligence Applications in Cyber Security: State-of-the-art in research." IEEE Access 2022, vol. 10, 93104-93139.
- Lashkari, Arash Habibi, Andi Fitriah A. Kadir, Hugo Gonzalez, Kenneth Fon Mbah, and Ali A. Ghorbani. "Towards a Network-based Framework for Android Malware Detection and Characterization." 15th Annual Conference on Privacy, Security and Trust (PST), IEEE, 2017, 233-23309.
- Samaneh Mahdavifar, Andi Fitriah Abdul Kadir, Rasool Fatemi, Dima Alhadidi, Ali A. Ghorbani "Dynamic Android Malware Category Classification using Semi-Supervised Deep Learning. ", The 18th IEEE International Conference on Dependable, Autonomic, and Secure Computing (DASC), 2020, 515-522.

Journal of ISMAC