PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 19, 2026ACM Transactions on Software Engineering and Methodology0 citations

Unraveling the Key of Machine Learning-based Android Malware Detection

View Full Paper
JLJiahao LiuJZJun ZengFPFabio Pierazzi

Key Points

  • The aim is to systematically analyze existing machine learning-based Android malware detection approaches and identify their limitations.
  • Organized prior research into a unified taxonomy based on app representations and the ML modeling pipeline.
  • Designed a general-purpose framework for ML-based malware detection.
  • Re-implemented 12 detection approaches from software engineering, security, and machine learning communities.
  • Conducted large-scale evaluations on detection effectiveness, robustness, and efficiency.
  • Existing detectors struggle with malware evolution and adversarial attacks.
  • Limitations are linked to their ability to capture malware semantics derived from APK features.
  • Key insights and recommendations for future research were summarized.

Abstract

With the rapid advancement of machine learning (ML), ML-based Android malware detection has gained significant popularity due to its ability to automatically learn malicious patterns from Android apps. However, the lack of an in-depth and systematic analysis of existing research makes it difficult to obtain a holistic understanding of the state of the art in this field. In this work, we present the most comprehensive investigation to date of ML-based Android malware detection systems, combining both empirical and quantitative analyses. We first organize prior work into a unified taxonomy based on Android app representations and the ML modeling pipeline. Building on this taxonomy, we design a general-purpose framework for ML-based Android malware detection and re-implement 12 representative approaches from three research communities—software engineering, security, and machine learning. Using this framework, we conduct a large-scale evaluation across three key dimensions: detection effectiveness, robustness to real-world challenges, and efficiency. Despite extensive research efforts and encouraging results, our findings reveal that existing learning-based Android malware detectors still face significant challenges, including vulnerability to malware evolution and susceptibility to adversarial attacks. We attribute these limitations to the detectors’ ability to capture and leverage malware semantics, defined as semantic information that characterizes malicious behaviors derived from APK features. Finally, we summarize our key insights and provide actionable recommendations to guide future research in this domain.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Liu et al. (2026) studied this question.

synapsesocial.com/papers/69e4741c010ef96374d8fe61https://doi.org/10.1145/3809491
Ask AI
Helpful
Bookmark
Share
View Full Paper