AuthProtect: An Incremental Learning Framework for Android Malware Detection via Permission-Exploitation Mapping
Автор: Maksim Iavich, Razvan Bocu
Журнал: International Journal of Engineering and Manufacturing @ijem
Статья в выпуске: 4 vol.16, 2026 года.
Бесплатный доступ
Android's widespread adoption and open ecosystem make it a primary target for malware, a challenge exacerbated by internet fragmentation resulting in non-stationary data distributions across regions. This work presents AuthProtect, a scalable malware detection framework based on incremental learning and a novel permission-to-exploitation mapping approach that links 135 permissions to 25 malware development techniques. The system is validated on a balanced dataset of 82,704 benign and 82,704 malicious applications, partitioned into three geographic regions to assess robustness to distribution shifts. A similarity-based selective training strategy improves computational efficiency by training only on novel samples (cosine similarity < threshold τ), while a test-then-train mechanism enhances robustness by sequentially processing samples to avoid data exposure bias. Evaluation on four benchmark datasets (Naticusdroid, Malgenome, CICMalDroid 2020, Android Malware Dataset) demonstrates accuracy ranging from 0.9573 to 0.9992, with a maximum accuracy of 0.9982 on real-world data. We provide a comparative analysis against state-of-the-art methods and ablation studies quantifying the contribution of each component. Limitations include dependency on the completeness of permission-technique mapping and computational overhead for real-time deployment on resource-constrained devices.
Malware Detection, Android, Machine Learning, Permission-to-Exploitation Associations, Android APK Decompilation, Internet Fragmentation
Короткий адрес: https://sciup.org/15020595
IDR: 15020595 | DOI: 10.5815/ijem.2026.04.23