Skip to main navigation Skip to search Skip to main content

A Comparative Study of Machine Learning Models for Two-Tier Android Malware Classification with Dynamic Behavioral Analysis

  • Jorge Torres
  • , Felipe Grijalva
  • , David Chushig-Muzo
  • , Luis Bote Curiel
  • , Malena Loza*
  • *Corresponding author for this work
  • Universidad San Francisco de Quito
  • Universidad Rey Juan Carlos

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The rapid proliferation of android malware has emerged as a critical threat to global cybersecurity. This study comparatively evaluates five supervised classification algorithms, including Random Forest (RF), Support Vector Machines (SVM) with RBF kernel, Artificial Neural Networks (ANNs), Naive Bayes and the novel TabNet model. The CCCS-CIC-AndMal-2020 dataset is used that comprises 200,000 malware samples categorized into 14 classes and 191 families, with features dynamically extracted during application execution in emulated environments. The predictive performance was assessed at two hierarchical classification approaches, distinguishing between broad malware categories and family-level attribution. To address class imbalance, oversampling techniques were considered. Precision, recall, and F1-score metrics, complemented by confusion matrices and ROC curves, were utilized for comprehensive evaluation. Statistical significance of differences among classifiers was determined using Friedman and Nemenyi post-hoc tests. Experimental results showed that RF, SVM, and ANNs consistently outperform other models across most metrics. This research provides a robust analytical framework for developing intelligent malware detection systems, contributing significantly to enhanced mobile cybersecurity.

Original languageEnglish
Title of host publicationIntelligent Data Engineering and Automated Learning, IDEAL 2025 - 26th International Conference, Proceedings
EditorsLuis Martínez, David Camacho, Hujun Yin, Bapi Dutta, Raciel Yera, Rosa M. Rodríguez Domínguez, Antonio Tallón-Ballesteros
PublisherSpringer Science and Business Media Deutschland GmbH
Pages445-456
Number of pages12
ISBN (Print)9783032104854
DOIs
StatePublished - 2026
Event26th International Conference on Intelligent Data Engineering and Automated Learning, IDEAL 2025 - Jaén, Spain
Duration: 13 Nov 202515 Nov 2025

Publication series

NameLecture Notes in Computer Science
Volume16238 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference26th International Conference on Intelligent Data Engineering and Automated Learning, IDEAL 2025
Country/TerritorySpain
CityJaén
Period13/11/2515/11/25

Keywords

  • CCCS-CIC-AndMal-2020
  • Malware
  • Naive Bayes
  • Neural Networks
  • Random Forest
  • SVM
  • Supervised classification
  • TabNet

Fingerprint

Dive into the research topics of 'A Comparative Study of Machine Learning Models for Two-Tier Android Malware Classification with Dynamic Behavioral Analysis'. Together they form a unique fingerprint.

Cite this