恶意软件
计算机科学
Android(操作系统)
Android恶意软件
隐病毒学
人气
计算机安全
恶意软件分析
杠杆(统计)
实证研究
稳健性(进化)
人工智能
静态分析
Android应用程序
仿人机器人
移动恶意软件
机器学习
数据科学
移动设备
脆弱性(计算)
对抗制
作者
Jiahao Liu,Jun Zeng,Fabio Pierazzi,Ziqi Yang,Lorenzo Cavallaro,Zhenkai Liang
摘要
With the rapid advancement of machine learning (ML), ML-based Android malware detection has gained significant popularity due to its ability to automatically learn malicious patterns from Android apps. However, the lack of an in-depth and systematic analysis of existing research makes it difficult to obtain a holistic understanding of the state of the art in this field. In this work, we present the most comprehensive investigation to date of ML-based Android malware detection systems, combining both empirical and quantitative analyses. We first organize prior work into a unified taxonomy based on Android app representations and the ML modeling pipeline. Building on this taxonomy, we design a general-purpose framework for ML-based Android malware detection and re-implement 12 representative approaches from three research communities—software engineering, security, and machine learning. Using this framework, we conduct a large-scale evaluation across three key dimensions: detection effectiveness, robustness to real-world challenges, and efficiency. Despite extensive research efforts and encouraging results, our findings reveal that existing learning-based Android malware detectors still face significant challenges, including vulnerability to malware evolution and susceptibility to adversarial attacks. We attribute these limitations to the detectors’ ability to capture and leverage malware semantics, defined as semantic information that characterizes malicious behaviors derived from APK features. Finally, we summarize our key insights and provide actionable recommendations to guide future research in this domain.
科研通智能强力驱动
Strongly Powered by AbleSci AI