When Balancing Harms: Structural Conditions That Degrade Android Malware Detection After Class Imbalance Correction
Resumo
Class imbalance is a recurrent challenge in Android malware detection, and class balancing is often adopted to improve minority-class detection. This paper compares original, dimensionality-reduced, and class-balanced versions of 11 Android malware datasets, using Recall, F1-score, and execution time. Dimensionality reduction followed by class balancing improved performance in 7 of the 11 datasets; in MH100k, this combination increased Recall from 0.63 to 0.99 and reduced execution time by approximately 99%. However, class balancing reduced performance in 4 datasets, especially in cases characterized by high sparsity, reduced diversity, or near-balanced class distributions, indicating that it should be empirically validated rather than applied by default.Referências
Akintola, A. G., Balogun, A., Mojeed, H. A., Usman-Hamza, F., Salihu, S. A., Adewole, K. S., Balogun, G. B., and Sadiku, P. O. (2022). Performance analysis of machine learning methods with class imbalance problem in android malware detection. IJIM, 16(10).
Arp, D., Quiring, E., Pendlebury, F., Warnecke, A., Pierazzi, F., Wressnegger, C., Cavallaro, L., and Rieck, K. (2022). Dos and don’ts of machine learning in computer security. In 31st USENIX Security Symposium (USENIX Security 22), pages 3971–3988.
Blagus, R. and Lusa, L. (2013). SMOTE for high-dimensional class-imbalanced data. BMC Bioinformatics, 14(106).
Bragança, H., Rocha, V., Barcellos, L. V., Souto, E., Kreutz, D., and Feitosa, E. (2023). Android malware detection with mh-100k: An innovative dataset for advanced research. Data in Brief, 51:109750.
Chen, W., Yang, K., Yu, Z., Shi, Y., and Chen, C. L. P. (2024). A survey on imbalanced learning: Latest research, applications and future directions. Artificial Intelligence Review, 57(137).
Colaco, C., Bagwe, M., Bose, S., and Jain, K. (2021). Defensedroid: A modern approach to android malware detection. Strad Research, 8(5).
Das, S., Mullick, S. S., and Zelinka, I. (2022). On supervised class-imbalanced learning: An updated perspective and some key challenges. IEEE Transactions on Artificial Intelligence, 3(6).
Demircioğlu, A. (2024). Applying oversampling before cross-validation will lead to high bias in radiomics. Scientific Reports, 14(1).
Ge, X., Huang, Y., Hui, Z., Wang, X., and Cao, X. (2021). Impact of datasets on machine learning based methods in android malware detection: an empirical study. In 2021 IEEE 21st International Conference on Software Quality, Reliability and Security (QRS). IEEE.
Gomes, A. L., Ferreira, L., Nogueira, A. G. D., Kreutz, D., Schmidt, D., Mansilha, R. B., and Paim, K. O. (2026). Statistical ranking: A voting-based ensemble approach to feature selection in android malware detection. Manuscript submitted for review.
Guan, J., Jiang, X., and Mao, B. (2021). A method for class-imbalance learning in android malware detection. Electronics, 10(24).
Haluška, R., Brabec, J., and Komárek, T. (2022). Benchmark of data preprocessing methods for imbalanced classification. In 2022 IEEE International Conference on Big Data.
He, H. and Garcia, E. A. (2009). Learning from imbalanced data. IEEE Transactions on Knowledge and Data Engineering, 21(9):1263–1284.
John, R. and Di Troia, F. (2025). Comparing balancing techniques for malware classification. In Machine Learning, Deep Learning and AI for Cybersecurity. Springer.
Rocha, V., Bragança, H., Kreutz, D., and Feitosa, E. (2024). Mh-fsf: um framework para reprodução, experimentação e avaliação de métodos de seleção de características. In Anais Estendidos do XXIV Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais. SBC.
Sisto, A. (2013). Androcrawl: Studying alternative android marketplaces. Master’s thesis, Politecnico di Milano.
Sun, N., Zhang, J., Rimba, P., Gao, S., Zhang, L. Y., and Xiang, Y. (2018). Data-driven cybersecurity incident prediction: A survey. IEEE communications surveys & tutorials, 21(2).
Vairetti, C., Assadi, J. L., and Maldonado, S. (2024). Efficient hybrid oversampling and intelligent undersampling for imbalanced big data classification. Expert Systems with Applications, 246:123149.
Wongvorachan, T., He, S., and Bulut, O. (2023). A comparison of undersampling, oversampling, and smote methods for dealing with imbalanced classification in educational data mining. Information, 14(1).
Arp, D., Quiring, E., Pendlebury, F., Warnecke, A., Pierazzi, F., Wressnegger, C., Cavallaro, L., and Rieck, K. (2022). Dos and don’ts of machine learning in computer security. In 31st USENIX Security Symposium (USENIX Security 22), pages 3971–3988.
Blagus, R. and Lusa, L. (2013). SMOTE for high-dimensional class-imbalanced data. BMC Bioinformatics, 14(106).
Bragança, H., Rocha, V., Barcellos, L. V., Souto, E., Kreutz, D., and Feitosa, E. (2023). Android malware detection with mh-100k: An innovative dataset for advanced research. Data in Brief, 51:109750.
Chen, W., Yang, K., Yu, Z., Shi, Y., and Chen, C. L. P. (2024). A survey on imbalanced learning: Latest research, applications and future directions. Artificial Intelligence Review, 57(137).
Colaco, C., Bagwe, M., Bose, S., and Jain, K. (2021). Defensedroid: A modern approach to android malware detection. Strad Research, 8(5).
Das, S., Mullick, S. S., and Zelinka, I. (2022). On supervised class-imbalanced learning: An updated perspective and some key challenges. IEEE Transactions on Artificial Intelligence, 3(6).
Demircioğlu, A. (2024). Applying oversampling before cross-validation will lead to high bias in radiomics. Scientific Reports, 14(1).
Ge, X., Huang, Y., Hui, Z., Wang, X., and Cao, X. (2021). Impact of datasets on machine learning based methods in android malware detection: an empirical study. In 2021 IEEE 21st International Conference on Software Quality, Reliability and Security (QRS). IEEE.
Gomes, A. L., Ferreira, L., Nogueira, A. G. D., Kreutz, D., Schmidt, D., Mansilha, R. B., and Paim, K. O. (2026). Statistical ranking: A voting-based ensemble approach to feature selection in android malware detection. Manuscript submitted for review.
Guan, J., Jiang, X., and Mao, B. (2021). A method for class-imbalance learning in android malware detection. Electronics, 10(24).
Haluška, R., Brabec, J., and Komárek, T. (2022). Benchmark of data preprocessing methods for imbalanced classification. In 2022 IEEE International Conference on Big Data.
He, H. and Garcia, E. A. (2009). Learning from imbalanced data. IEEE Transactions on Knowledge and Data Engineering, 21(9):1263–1284.
John, R. and Di Troia, F. (2025). Comparing balancing techniques for malware classification. In Machine Learning, Deep Learning and AI for Cybersecurity. Springer.
Rocha, V., Bragança, H., Kreutz, D., and Feitosa, E. (2024). Mh-fsf: um framework para reprodução, experimentação e avaliação de métodos de seleção de características. In Anais Estendidos do XXIV Simpósio Brasileiro de Segurança da Informação e de Sistemas Computacionais. SBC.
Sisto, A. (2013). Androcrawl: Studying alternative android marketplaces. Master’s thesis, Politecnico di Milano.
Sun, N., Zhang, J., Rimba, P., Gao, S., Zhang, L. Y., and Xiang, Y. (2018). Data-driven cybersecurity incident prediction: A survey. IEEE communications surveys & tutorials, 21(2).
Vairetti, C., Assadi, J. L., and Maldonado, S. (2024). Efficient hybrid oversampling and intelligent undersampling for imbalanced big data classification. Expert Systems with Applications, 246:123149.
Wongvorachan, T., He, S., and Bulut, O. (2023). A comparison of undersampling, oversampling, and smote methods for dealing with imbalanced classification in educational data mining. Information, 14(1).
Publicado
01/09/2026
Como Citar
OLIVEIRA, Lucas Ferreira Areias de; SILVA, Anna Luiza Gomes da; DINIZ, Angelo; KREUTZ, Diego; SCHMIDT, Dionatan R.; MANSILHA, Rodrigo; PAIM, Kayuã Oleques.
When Balancing Harms: Structural Conditions That Degrade Android Malware Detection After Class Imbalance Correction. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 1324-1339.
DOI: https://doi.org/10.5753/sbseg.2026.29256.
