<p>The dominance of the Android operating system in the global mobile market has led to a rapidly expanding application ecosystem, which simultaneously intensifies security challenges posed by the proliferation of sophisticated malware, threatening user privacy and financial assets. Traditional detection methods often suffer from limited effectiveness caused by data redundancy and obfuscation techniques. To overcome this issue, we introduce SI-Droid, a novel inversion framework for Android malware detection based on software imaging. Our approach innovates by first applying a feature inversion process to chaotic observational data, which quantitatively assesses the importance of API calls, permissions, and intent actions through statistical divergence metrics. This process extracts discriminative features, which are then fused into RGB images for visualization and classified using a Convolutional Neural Network. Extensive experiments on real-world datasets (i.e., Andro-Dumpsys and CICDataset) demonstrate that SI-Droid achieves high detection accuracy, significantly reducing false positives and enhancing robustness compared to baseline methods. The results validate that our inversion-driven framework not only improves detection capability and generalization but also provides a reliable, interpretable solution for Android security by reframing malware detection as an inverse problem. This work highlights the importance of feature refinement prior to imaging for future security analytics.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A software imaging-based inversion framework for Android malware detection

  • Shen-shen Bai,
  • Yin-hui Li,
  • Ming-wei Leng

摘要

The dominance of the Android operating system in the global mobile market has led to a rapidly expanding application ecosystem, which simultaneously intensifies security challenges posed by the proliferation of sophisticated malware, threatening user privacy and financial assets. Traditional detection methods often suffer from limited effectiveness caused by data redundancy and obfuscation techniques. To overcome this issue, we introduce SI-Droid, a novel inversion framework for Android malware detection based on software imaging. Our approach innovates by first applying a feature inversion process to chaotic observational data, which quantitatively assesses the importance of API calls, permissions, and intent actions through statistical divergence metrics. This process extracts discriminative features, which are then fused into RGB images for visualization and classified using a Convolutional Neural Network. Extensive experiments on real-world datasets (i.e., Andro-Dumpsys and CICDataset) demonstrate that SI-Droid achieves high detection accuracy, significantly reducing false positives and enhancing robustness compared to baseline methods. The results validate that our inversion-driven framework not only improves detection capability and generalization but also provides a reliable, interpretable solution for Android security by reframing malware detection as an inverse problem. This work highlights the importance of feature refinement prior to imaging for future security analytics.