[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-119151-en":3,"doc-seo-119151-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},119151,8796095462418,"Noah","https://ap-avatar.wpscdn.com/avatar/80000253c1241d02b47?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778826106357471780",8,"Research & Report","Android Malware Detection Using Machine Learning Techniques","Android’s continued popularity makes it an attractive target for malware attacks, and sensitive smartphone data makes detection and prevention critical. Traditional signature-based approaches are limited by signature databases and struggle with the growth of users and applications, especially for zero-day threats. Machine learning can detect similarities to previously unknown vulnerabilities, but faces challenges such as limited up-to-date Android datasets and concerns about practical deployability. This thesis presents a contemporary dataset and DroidDissector tool, compares feature/model spaces, improves accuracy via ensembling, and proposes an active learning online learning framework to handle real-world labeling delays.","Android Malware Detection Using Machine Learning Techniques  \nAli Muzaffar  \nSubmitted for the degree of  \nDoctor of Philosophy  \nHeriot-Watt University  \nSchool of Mathematical and Computer Sciences.  \nDecember, 2023  \nThe copyright in this thesis is owned by the author. Any quotation from the thesis or use of any of the information contained in it must acknowledge this thesis as the source of the quotation or information.  \nAbstract  \nAndroid’s sustained and continued popularity makes it an attractive target for many malware attacks. Due to the sensitive data on smartphones, detecting and preventing such attacks is crucial. Traditional signature-based detection techniques are limited to spotting signatures in their signature databases, making them inadequate in dealing with the significant increase in users and applications.  \nMachine learning does not depend on rigid signature databases and can effectively detect new threats, known as zero-day attacks, by exploiting their similarities to previously unknown vulnerabilities. Despite the efficacy of machine learning systems, they face challenges. One of the main challenges researchers face is the limited availability of contemporary Android application datasets. This raises a big question about the models built using outdated datasets and how they would fare with modern malware. Furthermore, a notable issue observed in the literature is the lack of consideration given to the practicality of deploying such systems.  \nThis thesis starts with a critical review of previous work and highlights the lack of up-to-date analysis tools and a reliance on outdated datasets. We present our contemporary dataset and our automated feature extraction tool, DroidDissector. We then comprehensively analyze the Android feature space to identify the best machine learning models and feature sets for Android malware detection. Notably, our research findings indicated that using the costlier dynamic and individual hybrid feature models does not provide significant benefits compared to using static features alone, and some historically significant feature sets perform poorly with our contemporary dataset. Significantly, we found that accuracy could be improved by ensembling models trained on static and dynamic features. Finally, we propose a novel active learning-based online learning framework for Android malware detection. Our framework aims to bridge the gap between theoretical systems and practical deployment and show how it compensates for the loss of accuracy caused by real-world labeling delays. We introduce active learning for the first time in the context of Android malware detection. Active learning enables the training of online learning models without relying on the true label of each application instance.  \nI dedicate this  \nthesis to my Mom and Dad, for their never-ending support, guidance, and prayers. May God bless them abundantly and grant them everlasting happiness.  \nAcknowledgements  \nI am extremely grateful for the continuous support and guidance provided by my supervisors, Dr. Hani Ragab Hassen, Dr. Michael A. Lones, and Dr. Hind Zantout. Without their unwavering support, I wouldn’t have been able to finish my thesis. Their expertise, insightful feedback, and encouragement have been instrumental in shaping my research and academic growth. I would also like to thank Dr. HansWolfgang Loidl for his invaluable insights throughout.  \nI want to express my heartfelt thanks to my parents, for always being there forme and believing in me. Their constant support, prayers, and confidence have been crucial in helping me complete this thesis.  \nI would like to extend my heartfelt appreciation to my sisters, brother, and wife, for their unwavering presence and continuous encouragement. They have been a constant source of motivation throughout this journey. I am truly grateful for their support. I would also like to acknowledge my nieces and nephews, whose joyful presence has brought immense hap","cbCailKWatyCSxv1","https://ap.wps.com/l/cbCailKWatyCSxv1","pdf",5541577,1,178,"English","en",105,"# 1 Introduction\n## 1.1 Motiv\n## 1.2\n# 2 Related Work\n## 2.1\n# 3 Dataset and Tooling\n## 3.1 Contemporary dataset\n## 3.2 DroidDissector\n# 4 Feature Space and Model Analysis\n## 4.1 Static vs dynamic features\n## 4.2 Hybrid feature models\n# 5 Online Learning with Active Learning\n## 5.1 Framework overview\n## 5.2 Labeling delay handling","[{\"question\":\"Why are traditional signature-based Android malware detectors inadequate?\",\"answer\":\"They rely on fixed signature databases, so they cannot effectively respond to the rapid growth of apps and users or detect zero-day threats that lack known signatures.\"},{\"question\":\"What key resources does the thesis introduce for Android malware detection?\",\"answer\":\"It provides a contemporary Android dataset and an automated feature extraction tool called DroidDissector to support up-to-date analysis.\"},{\"question\":\"How does the thesis improve detection performance and address deployment practicality?\",\"answer\":\"It finds that ensembling models trained on static and dynamic features boosts accuracy, and it proposes an active learning-based online learning framework that compensates for real-world labeling delays without needing true labels for every instance.\"}]","Android Malware Detection Using Machine Learning Techniques | PDF",1785722754,449,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"android-malware-detection-using-machine-learning-techniques","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/android-malware-detection-using-machine-learning-techniques/119151/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why are traditional signature-based Android malware detectors inadequate?","Question",{"text":75,"@type":76},"They rely on fixed signature databases, so they cannot effectively respond to the rapid growth of apps and users or detect zero-day threats that lack known signatures.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"What key resources does the thesis introduce for Android malware detection?",{"text":80,"@type":76},"It provides a contemporary Android dataset and an automated feature extraction tool called DroidDissector to support up-to-date analysis.",{"name":82,"@type":73,"acceptedAnswer":83},"How does the thesis improve detection performance and address deployment practicality?",{"text":84,"@type":76},"It finds that ensembling models trained on static and dynamic features boosts accuracy, and it proposes an active learning-based online learning framework that compensates for real-world labeling delays without needing true labels for every instance.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]