ARCHIVES
Original Article
Android Malware Detection Using LightGBM with Intelligent Threat Attribution
Murapala Pavitra1
Dr. L. Sumalatha2
1 PG Scholar, Department of Computer Science and Engineering, University College of Engineering Kakinada, JNTUK, Kakinada, Andhra Pradesh, India. 2 Professor, Department of Computer Science and Engineering, University College of Engineering Kakinada, JNTUK, Kakinada, Andhra Pradesh, India.
Published Online: July-August 2026
Pages: 92-101
Cite this article
↗ https://www.doi.org/10.59256/ijire.20260704013References
1. J. Senanayake, H. Kalutarage and M. O. Al-Kadri, “Android mobile malware detection using machine learning: A systematic review,”
Electronics, vol. 10, no. 13, art. 1606, 2021. doi: 10.3390/electronics10131606
2. A. Qamar, A. Karim and V. Chang, “Mobile malware attacks: Review, taxonomy and future directions,” Future Generation Computer
Systems, vol. 97, pp. 887-909, 2019. doi: 10.1016/j.future.2019.03.007
3. Q. Wu, X. Zhu and B. Liu, “A survey of Android malware static detection technology based on machine learning,” Mobile Information
Systems, vol. 2021, art. 8896013, 2021. doi: 10.1155/2021/8896013
4. J. Li, L. Sun, Q. Yan, Z. Li, W. Srisa-an and H. Ye, “Significant permission identification for machine-learning-based Android malware
detection,” IEEE Transactions on Industrial Informatics, vol. 14, no. 7, pp. 3216-3225, 2018. doi: 10.1109/TII.2017.2789219
5. N. Peiravian and X. Zhu, “Machine learning for Android malware detection using permission and API calls,” in Proc. IEEE 25th Int.
Conf. on Tools with Artificial Intelligence (ICTAI), 2013, pp. 300-305. doi: 10.1109/ICTAI.2013.53
6. W. Wang, Z. Gao, M. Zhao, Y. Li, J. Liu and X. Zhang, “DroidEnsemble: Detecting Android malicious applications with ensemble of
string and structural static features,” IEEE Access, vol. 6, pp. 31798-31807, 2018. doi: 10.1109/ACCESS.2018.2835654
7. A. T. Kabakus, “What static analysis can utmost offer for Android malware detection,” Information Technology and Control, vol. 48,
no. 2, pp. 235-249, 2019. doi: 10.5755/j01.itc.48.2.21457
8. D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon and K. Rieck, “DREBIN: Effective and explainable detection of Android malware
in your pocket,” in Proc. Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 2014. doi:
10.14722/ndss.2014.23247
9. S. Arshad, M. A. Shah, A. Wahid, A. Mehmood, H. Song and H. Yu, “SAMADroid: A novel 3-level hybrid malware detection model
for Android operating system,” IEEE Access, vol. 6, pp. 4321-4339, 2018. doi: 10.1109/ACCESS.2018.2792941
10. [10] O. E. Saied and K. H. Thanoon, “Static analysis-based detection of Android malware using machine learning algorithms,”
Sistemasi: Jurnal Sistem Informasi, vol. 14, no. 5, pp. 2540-2551, 2025. doi: 10.32520/stmsi.v14i5.7536
11. P. A. Museeb et al., “Android malware detection using API calls and permissions with Random Forest classifier,” IEEE Access, vol.
14, pp. 6464-6470, 2026. doi: 10.1109/ACCESS.2026.3651861
12. A. Feizollah, N. B. Anuar, R. Salleh, G. Suarez-Tangil and S. Furnell, “AndroDialysis: Analysis of Android intent effectiveness in
malware detection,” Computers & Security, vol. 65, pp. 121-134, 2017. doi: 10.1016/j.cose.2016.11.007
13. K. A. Prasad et al., “AndroMD: An Android malware detection framework based on source code analysis and permission scanning,”
Results in Engineering, 2025. doi: 10.1016/j.rineng.2025.107050
14. S. Zhou, H. Li, X. Fu, D. Han and X. He, “Novel multi-classification dynamic detection model for Android malware based on improved
Zebra Optimization Algorithm and LightGBM,” Sensors, vol. 24, no. 18, art. 5975, 2024. doi: 10.3390/s24185975
15. S. Y. Yerima and S. Sezer, “DroidFusion: A novel multilevel classifier fusion approach for Android malware detection,” IEEE
Transactions on Cybernetics, vol. 49, no. 2, pp. 453-466, 2019. doi: 10.1109/TCYB.2017.277796016. N. McLaughlin et al., “Deep Android malware detection,” in Proc. 7th ACM Conf. on Data and Application Security and Privacy
(CODASPY), 2017, pp. 301-308. doi: 10.1145/3029806.3029823
17. R. Ma et al., “A lightweight deep learning-based Android malware detection system,” Expert Systems with Applications, 2024. doi:
10.1016/j.eswa.2024.124633
18. T. Sun et al., “DetectBERT: Full app-level representation learning to detect Android malware,” arXiv preprint arXiv:2408.16353,
2024. doi: 10.48550/arXiv.2408.16353
19. H. H. R. Manzil and S. M. Naik, “Android malware category detection using a novel feature vector-based machine learning model,”
Cybersecurity, vol. 6, art. 6, 2023. doi: 10.1186/s42400-023-00139-y
20. S. M. Lundberg and S.-I. Lee, “A unified approach to interpreting model predictions,” in Advances in Neural Information Processing
Systems (NeurIPS), vol. 30, 2017, pp. 4765-4774. doi: 10.48550/arXiv.1705.07874
21. M. Ghourabi, “An attention-based approach to enhance the detection and classification of Android malware,” Computers, Materials &
Continua, vol. 80, no. 2, 2024. doi: 10.32604/cmc.2024.053163
22. A. Mahindru, H. Arora, A. Kumar et al., “PermDroid: A framework developed using proposed feature selection approach and machine
learning techniques for Android malware detection,” Scientific Reports, vol. 14, art. 10724, 2024. doi: 10.1038/s41598-024-60982-y
23. X. Tanha and M. Kafaie, “Explainable AI techniques for Android malware detection,” ACM Computing Surveys, vol. 57, no. 2, 2025.
doi: 10.1145/3631234
24. T. Lan and F. Nait-Abdesselam, “LLM-driven feature-level adversarial attacks on Android malware detectors,” arXiv preprint, 2025.
doi: 10.48550/arXiv.2512.21404
25. Y. Odat and Q. Yaseen, “A novel machine learning approach for Android malware detection based on the co-existence of features,”
IEEE Access, vol. 11, pp. 15471-15484, 2023. doi: 10.1109/ACCESS.2023.3244656
26. N. Zhang, J. Xue, Y. Ma, R. Zhang, T. Liang and Y. Tan, “Hybrid sequence-based Android malware detection using natural language
processing,” International Journal of Intelligent Systems, vol. 36, no. 10, pp. 5770-5784, 2021. doi: 10.1002/int.22529
27. G. Ke et al., “LightGBM: A highly efficient gradient boosting decision tree,” in Advances in Neural Information Processing Systems
(NeurIPS), vol. 30, 2017, pp. 3146-3154.
28. T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proc. 22nd ACM SIGKDD Int. Conf. on Knowledge
Discovery and Data Mining, 2016, pp. 785-794. doi: 10.1145/2939672.2939785
29. B. E. Strom, A. Applebaum, D. P. Miller, K. C. Nickels, A. G. Pennington and C. B. Thomas, “MITRE ATT&CK: Design and
philosophy,” MITRE Corporation, Technical Report MP180360R1, 2020.
30. L. Breiman, “Random forests,” Machine Learning, vol. 45, no. 1, pp. 5-32, 2001. doi: 10.1023/A:1010933404324
31. L. Prokhorenkova, G. Gusev, A. Vorobev, A. V. Dorogush and A. Gulin, “CatBoost: Unbiased boosting with categorical features,” in
Advances in Neural Information Processing Systems (NeurIPS), vol. 31, 2018, pp. 6638-6648. doi: 10.48550/arXiv.1706.09516.
Electronics, vol. 10, no. 13, art. 1606, 2021. doi: 10.3390/electronics10131606
2. A. Qamar, A. Karim and V. Chang, “Mobile malware attacks: Review, taxonomy and future directions,” Future Generation Computer
Systems, vol. 97, pp. 887-909, 2019. doi: 10.1016/j.future.2019.03.007
3. Q. Wu, X. Zhu and B. Liu, “A survey of Android malware static detection technology based on machine learning,” Mobile Information
Systems, vol. 2021, art. 8896013, 2021. doi: 10.1155/2021/8896013
4. J. Li, L. Sun, Q. Yan, Z. Li, W. Srisa-an and H. Ye, “Significant permission identification for machine-learning-based Android malware
detection,” IEEE Transactions on Industrial Informatics, vol. 14, no. 7, pp. 3216-3225, 2018. doi: 10.1109/TII.2017.2789219
5. N. Peiravian and X. Zhu, “Machine learning for Android malware detection using permission and API calls,” in Proc. IEEE 25th Int.
Conf. on Tools with Artificial Intelligence (ICTAI), 2013, pp. 300-305. doi: 10.1109/ICTAI.2013.53
6. W. Wang, Z. Gao, M. Zhao, Y. Li, J. Liu and X. Zhang, “DroidEnsemble: Detecting Android malicious applications with ensemble of
string and structural static features,” IEEE Access, vol. 6, pp. 31798-31807, 2018. doi: 10.1109/ACCESS.2018.2835654
7. A. T. Kabakus, “What static analysis can utmost offer for Android malware detection,” Information Technology and Control, vol. 48,
no. 2, pp. 235-249, 2019. doi: 10.5755/j01.itc.48.2.21457
8. D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon and K. Rieck, “DREBIN: Effective and explainable detection of Android malware
in your pocket,” in Proc. Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA, 2014. doi:
10.14722/ndss.2014.23247
9. S. Arshad, M. A. Shah, A. Wahid, A. Mehmood, H. Song and H. Yu, “SAMADroid: A novel 3-level hybrid malware detection model
for Android operating system,” IEEE Access, vol. 6, pp. 4321-4339, 2018. doi: 10.1109/ACCESS.2018.2792941
10. [10] O. E. Saied and K. H. Thanoon, “Static analysis-based detection of Android malware using machine learning algorithms,”
Sistemasi: Jurnal Sistem Informasi, vol. 14, no. 5, pp. 2540-2551, 2025. doi: 10.32520/stmsi.v14i5.7536
11. P. A. Museeb et al., “Android malware detection using API calls and permissions with Random Forest classifier,” IEEE Access, vol.
14, pp. 6464-6470, 2026. doi: 10.1109/ACCESS.2026.3651861
12. A. Feizollah, N. B. Anuar, R. Salleh, G. Suarez-Tangil and S. Furnell, “AndroDialysis: Analysis of Android intent effectiveness in
malware detection,” Computers & Security, vol. 65, pp. 121-134, 2017. doi: 10.1016/j.cose.2016.11.007
13. K. A. Prasad et al., “AndroMD: An Android malware detection framework based on source code analysis and permission scanning,”
Results in Engineering, 2025. doi: 10.1016/j.rineng.2025.107050
14. S. Zhou, H. Li, X. Fu, D. Han and X. He, “Novel multi-classification dynamic detection model for Android malware based on improved
Zebra Optimization Algorithm and LightGBM,” Sensors, vol. 24, no. 18, art. 5975, 2024. doi: 10.3390/s24185975
15. S. Y. Yerima and S. Sezer, “DroidFusion: A novel multilevel classifier fusion approach for Android malware detection,” IEEE
Transactions on Cybernetics, vol. 49, no. 2, pp. 453-466, 2019. doi: 10.1109/TCYB.2017.277796016. N. McLaughlin et al., “Deep Android malware detection,” in Proc. 7th ACM Conf. on Data and Application Security and Privacy
(CODASPY), 2017, pp. 301-308. doi: 10.1145/3029806.3029823
17. R. Ma et al., “A lightweight deep learning-based Android malware detection system,” Expert Systems with Applications, 2024. doi:
10.1016/j.eswa.2024.124633
18. T. Sun et al., “DetectBERT: Full app-level representation learning to detect Android malware,” arXiv preprint arXiv:2408.16353,
2024. doi: 10.48550/arXiv.2408.16353
19. H. H. R. Manzil and S. M. Naik, “Android malware category detection using a novel feature vector-based machine learning model,”
Cybersecurity, vol. 6, art. 6, 2023. doi: 10.1186/s42400-023-00139-y
20. S. M. Lundberg and S.-I. Lee, “A unified approach to interpreting model predictions,” in Advances in Neural Information Processing
Systems (NeurIPS), vol. 30, 2017, pp. 4765-4774. doi: 10.48550/arXiv.1705.07874
21. M. Ghourabi, “An attention-based approach to enhance the detection and classification of Android malware,” Computers, Materials &
Continua, vol. 80, no. 2, 2024. doi: 10.32604/cmc.2024.053163
22. A. Mahindru, H. Arora, A. Kumar et al., “PermDroid: A framework developed using proposed feature selection approach and machine
learning techniques for Android malware detection,” Scientific Reports, vol. 14, art. 10724, 2024. doi: 10.1038/s41598-024-60982-y
23. X. Tanha and M. Kafaie, “Explainable AI techniques for Android malware detection,” ACM Computing Surveys, vol. 57, no. 2, 2025.
doi: 10.1145/3631234
24. T. Lan and F. Nait-Abdesselam, “LLM-driven feature-level adversarial attacks on Android malware detectors,” arXiv preprint, 2025.
doi: 10.48550/arXiv.2512.21404
25. Y. Odat and Q. Yaseen, “A novel machine learning approach for Android malware detection based on the co-existence of features,”
IEEE Access, vol. 11, pp. 15471-15484, 2023. doi: 10.1109/ACCESS.2023.3244656
26. N. Zhang, J. Xue, Y. Ma, R. Zhang, T. Liang and Y. Tan, “Hybrid sequence-based Android malware detection using natural language
processing,” International Journal of Intelligent Systems, vol. 36, no. 10, pp. 5770-5784, 2021. doi: 10.1002/int.22529
27. G. Ke et al., “LightGBM: A highly efficient gradient boosting decision tree,” in Advances in Neural Information Processing Systems
(NeurIPS), vol. 30, 2017, pp. 3146-3154.
28. T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proc. 22nd ACM SIGKDD Int. Conf. on Knowledge
Discovery and Data Mining, 2016, pp. 785-794. doi: 10.1145/2939672.2939785
29. B. E. Strom, A. Applebaum, D. P. Miller, K. C. Nickels, A. G. Pennington and C. B. Thomas, “MITRE ATT&CK: Design and
philosophy,” MITRE Corporation, Technical Report MP180360R1, 2020.
30. L. Breiman, “Random forests,” Machine Learning, vol. 45, no. 1, pp. 5-32, 2001. doi: 10.1023/A:1010933404324
31. L. Prokhorenkova, G. Gusev, A. Vorobev, A. V. Dorogush and A. Gulin, “CatBoost: Unbiased boosting with categorical features,” in
Advances in Neural Information Processing Systems (NeurIPS), vol. 31, 2018, pp. 6638-6648. doi: 10.48550/arXiv.1706.09516.
Related Articles
2026
AI-Based Stomach Cancer Detection Using Biomarkers, Medical Images, and Voice Analysis
2026
Hydrogen-Efficient Eco-Driving and Route Planning for Fuel-Cell Electric Vehicles Using Multi-Objective Optimization Under Traffic and Terrain Uncertainty
2026
A Data-Driven Machine Learning Framework for Assessing Patent Commercial Value and Technological Significance
2026
Evaluating Student Academic Performance Through a Benchmark of Fuzzy Reasoning Models
2026
A Hybrid Soft Computing Approach for Managing Uncertainty in Data Analytics
2026