A ROBUST AND EFFICIENT MACHINE LEARNING FRAMEWORK FOR ENHANCING EARLY DETECTION OF ANDROID MALWARE
DOI:
https://doi.org/10.62643/Abstract
The rapid growth of Android smartphones and mobile applications has significantly enhanced digital connectivity while simultaneously increasing the exposure of users to sophisticated malware attacks. Conventional malware detection techniques primarily rely on signature-based mechanisms, which are ineffective against zero-day attacks, polymorphic malware, and obfuscated malicious applications. These limitations necessitate the development of intelligent and adaptive malware detection frameworks capable of identifying previously unseen threats with high accuracy. This paper proposes a robust and efficient machine learning framework for enhancing the early detection of Android malware by integrating multiple supervised learning algorithms with Explainable Artificial Intelligence (XAI). The proposed framework utilizes static analysis to extract significant application features, including system calls, binder interactions, and API invocation frequencies, which are subsequently preprocessed to eliminate redundancy and improve data quality. Three machine learning algorithms, namely Random Forest, XGBoost, and Decision Tree, are employed to classify Android applications into benign and malicious categories. Comparative performance evaluation is performed using standard metrics such as accuracy, precision, recall, F1-score, and ROC-AUC to determine the most effective classifier. To improve model transparency and facilitate cybersecurity investigations, SHapley Additive exPlanations (SHAP) are incorporated to explain feature contributions influencing prediction outcomes. The framework further integrates a FastAPIbased backend, secure user authentication, interactive dashboard, automated report generation, prediction history management, and visualization modules, thereby providing a comprehensive malware analysis environment. Experimental evaluation demonstrates that the ensemble learning models, particularly XGBoost and Random Forest, achieve superior detection performance while maintaining high interpretability through SHAP-based explanations. The proposed framework effectively reduces false positives, enhances early malware detection capability, and supports informed cybersecurity decision-making. Consequently, the developed system provides a scalable, reliable, and intelligent solution for strengthening Android application security and mitigating emerging mobile cyber threats through explainable machine learning techniques.
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.













