Um Modelo Baseado em Redes Neurais Profundas e Redes Neurais Recorrentes para Análise Sequencial de Binários Android
Resumo
Este trabalho propõe um framework que particiona o código binário de aplicações Android em sequências de imagens de tamanho fixo, preservando sua estrutura espacial original. O modelo combina uma Rede Neural Profunda (DNN) para extração de características espaciais com uma Rede Neural Recorrente (RNN), responsável por capturar dependências temporais entre sequências. A abordagem utiliza uma estratégia de classificação many-to-one, permitindo lidar com aplicações de tamanhos variáveis sem perda significativa de informação. O método foi avaliado em um conjunto de mais de 13 mil amostras do AndroZoo coletadas ao longo de quatro anos. Os resultados mostram que a proposta supera abordagens tradicionais baseadas em redimensionamento, alcançando um F1-Score de até 0,93, uma melhoria de até 0,03 no AUC e maior capacidade de generalização entre diferentes famílias de malware.Referências
Anton Kivva (2026). Mobile malware evolution in 2025.
de Oliveira, V. M., de Oliveira, H. M., Santos, G. M., Geremias, J., and Viegas, E. K. (2025). A big data framework for scalable and cross-dataset capable machine learning in network intrusion detection systems. IEEE Access, 13:129419–129431.
Espindola, A. d. S., Casimiro, A., Santin, A. O., Ferreira, P. M., and Viegas, E. K. (2026a). Enhancing intrusion detection generalization via diversity-driven multi-view ensemble learning in industrial systems. Future Generation Computer Systems, 182:108458.
Espindola, A. d. S., Santin, A. O., Casimiro, A., Ferreira, P. M., and Viegas, E. K. (2026b). Understanding the adversary: A survey of adversarial machine learning in network intrusion detection. Computer Science Review, 62:100995.
Geremias, J., Viegas, E. K., Santin, A. O., Britto, A., and Horchulhack, P. (2023). Towards a reliable hierarchical android malware detection through image-based cnn. In 2023 IEEE 20th Consumer Communications & Networking Conference (CCNC), page 242–247. IEEE.
Horchulhack, P., Viegas, E. K., and Santin, A. O. (2022). Detection of service provider hardware over-commitment in container orchestration environments. In GLOBECOM 2022 - 2022 IEEE Global Communications Conference, page 6354–6359. IEEE.
Lan, T., Darwaish, A., Nait-Abdesselam, F., and Gu, P. (2023). Defensive randomization against adversarial attacks in image-based android malware detection. In ICC 2023 - IEEE International Conference on Communications. IEEE.
Maniriho, P., Mahmood, A. N., and Chowdhury, M. J. M. (2024). A survey of recent advances in deep learning models for detecting malware in desktop and mobile platforms. ACM Comput. Surv., 56(6):1–41.
Rodrigues, M. G., Viegas, E. K., Santin, A. O., and Enembreck, F. (2025). A mlops architecture for near real-time distributed stream learning operation deployment. Journal of Network and Computer Applications, 238:104169.
Sharma, T. and Rattan, D. (2025). Characterization of android malwares and their families. ACM Comput. Surv., 57(5):1–31.
Shen, L., Feng, J., Chen, Z., Sun, Z., Liang, D., Li, H., and Wang, Y. (2023). Self-attention based convolutional-LSTM for android malware detection using network traffics grayscale image. Appl. Intell., 53(1):683–705.
Shu, L., Dong, S., Su, H., and Huang, J. (2023). Android malware detection methods based on convolutional neural network: A survey. IEEE Trans. Emerg. Top. Comput. Intell., pages 1–21.
StatCounter (2026). Mobile operating system market share worldwide.
Tang, J., Xu, W., Peng, T., Zhou, S., Pi, Q., He, R., and Hu, X. (2024). Android malware detection based on a novel mixed bytecode image combined with attention mechanism. Journal of Information Security and Applications, 82:103721.
Usama Tanveer, M., Munir, K., Alabdulatif, A., Najdawi, A. R., and Jhaveri, R. H. (2025). Malware-seqguard: An approach utilizing lstm and gru for effective detection of evolving malware in android environments. IEEE Access, 13:117355–117373.
Viegas, E. K., Santin, A. O., Cogo, V. V., and Abreu, V. (2020). Facing the Unknown: A Stream Learning Intrusion Detection System for Reliable Model Updates, page 898–909. Springer International Publishing.
Xiao, X., Zhang, S., Mercaldo, F., Hu, G., and Sangaiah, A. K. (2017). Android malware detection based on system call sequences and lstm. Multimedia Tools and Applications, 78(4):3979–3999.
Yadav, P., Menon, N., Ravi, V., Vishvanathan, S., and Pham, T. D. (2022). Efficient-Net convolutional neural networks-based android malware detection. Comput. Secur., 115(102622):102622.
Yapici, M. M. (2025). 3dmaldroid: A novel 3d image based approach for android malware detection and classification. Computers and Electrical Engineering, 127:110542.
Zou, B., Cao, C., Tao, F., and Wang, L. (2022). Imclnet: A lightweight deep neural network for image-based malware classification. Journal of Information Security and Applications, 70:103313.
de Oliveira, V. M., de Oliveira, H. M., Santos, G. M., Geremias, J., and Viegas, E. K. (2025). A big data framework for scalable and cross-dataset capable machine learning in network intrusion detection systems. IEEE Access, 13:129419–129431.
Espindola, A. d. S., Casimiro, A., Santin, A. O., Ferreira, P. M., and Viegas, E. K. (2026a). Enhancing intrusion detection generalization via diversity-driven multi-view ensemble learning in industrial systems. Future Generation Computer Systems, 182:108458.
Espindola, A. d. S., Santin, A. O., Casimiro, A., Ferreira, P. M., and Viegas, E. K. (2026b). Understanding the adversary: A survey of adversarial machine learning in network intrusion detection. Computer Science Review, 62:100995.
Geremias, J., Viegas, E. K., Santin, A. O., Britto, A., and Horchulhack, P. (2023). Towards a reliable hierarchical android malware detection through image-based cnn. In 2023 IEEE 20th Consumer Communications & Networking Conference (CCNC), page 242–247. IEEE.
Horchulhack, P., Viegas, E. K., and Santin, A. O. (2022). Detection of service provider hardware over-commitment in container orchestration environments. In GLOBECOM 2022 - 2022 IEEE Global Communications Conference, page 6354–6359. IEEE.
Lan, T., Darwaish, A., Nait-Abdesselam, F., and Gu, P. (2023). Defensive randomization against adversarial attacks in image-based android malware detection. In ICC 2023 - IEEE International Conference on Communications. IEEE.
Maniriho, P., Mahmood, A. N., and Chowdhury, M. J. M. (2024). A survey of recent advances in deep learning models for detecting malware in desktop and mobile platforms. ACM Comput. Surv., 56(6):1–41.
Rodrigues, M. G., Viegas, E. K., Santin, A. O., and Enembreck, F. (2025). A mlops architecture for near real-time distributed stream learning operation deployment. Journal of Network and Computer Applications, 238:104169.
Sharma, T. and Rattan, D. (2025). Characterization of android malwares and their families. ACM Comput. Surv., 57(5):1–31.
Shen, L., Feng, J., Chen, Z., Sun, Z., Liang, D., Li, H., and Wang, Y. (2023). Self-attention based convolutional-LSTM for android malware detection using network traffics grayscale image. Appl. Intell., 53(1):683–705.
Shu, L., Dong, S., Su, H., and Huang, J. (2023). Android malware detection methods based on convolutional neural network: A survey. IEEE Trans. Emerg. Top. Comput. Intell., pages 1–21.
StatCounter (2026). Mobile operating system market share worldwide.
Tang, J., Xu, W., Peng, T., Zhou, S., Pi, Q., He, R., and Hu, X. (2024). Android malware detection based on a novel mixed bytecode image combined with attention mechanism. Journal of Information Security and Applications, 82:103721.
Usama Tanveer, M., Munir, K., Alabdulatif, A., Najdawi, A. R., and Jhaveri, R. H. (2025). Malware-seqguard: An approach utilizing lstm and gru for effective detection of evolving malware in android environments. IEEE Access, 13:117355–117373.
Viegas, E. K., Santin, A. O., Cogo, V. V., and Abreu, V. (2020). Facing the Unknown: A Stream Learning Intrusion Detection System for Reliable Model Updates, page 898–909. Springer International Publishing.
Xiao, X., Zhang, S., Mercaldo, F., Hu, G., and Sangaiah, A. K. (2017). Android malware detection based on system call sequences and lstm. Multimedia Tools and Applications, 78(4):3979–3999.
Yadav, P., Menon, N., Ravi, V., Vishvanathan, S., and Pham, T. D. (2022). Efficient-Net convolutional neural networks-based android malware detection. Comput. Secur., 115(102622):102622.
Yapici, M. M. (2025). 3dmaldroid: A novel 3d image based approach for android malware detection and classification. Computers and Electrical Engineering, 127:110542.
Zou, B., Cao, C., Tao, F., and Wang, L. (2022). Imclnet: A lightweight deep neural network for image-based malware classification. Journal of Information Security and Applications, 70:103313.
Publicado
01/09/2026
Como Citar
GEREMIAS, Jhonatan; VIEGAS, Altair O.; VIEGAS, Eduardo K..
Um Modelo Baseado em Redes Neurais Profundas e Redes Neurais Recorrentes para Análise Sequencial de Binários Android. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 1182-1195.
DOI: https://doi.org/10.5753/sbseg.2026.27821.
