Análise Espaço-Temporal de Binários Android Usando Representação Byte-to-Video

  • Caio Kloppel PUCPR
  • Jhonatan Geremias PUCPR
  • Altair O. Santin PUCPR
  • Eduardo K. Viegas PUCPR

Resumo


Este artigo apresenta um framework de detecção de malware Android baseado em uma representação espaço-temporal dos arquivos binários das aplicações. A abordagem proposta utiliza uma codificação Byte-to-Video, na qual o arquivo analisado é convertido em uma sequência de frames de alta resolução, preservando sua estrutura original. Essa representação é processada por uma Convolutional Neural Network 3D (3D-CNN), permitindo a extração de características espaciais e de dependências entre diferentes regiões do bytecode. Ao tratar o binário como uma sequência de vídeo, o modelo identifica padrões maliciosos distribuídos ao longo do código sem as perdas introduzidas pelo redimensionamento tradicional de imagens 2D. Os experimentos em um dataset próprio, com mais de 22 mil amostras, mostram uma melhoria de 0,02 no F1-Score em relação às abordagens convencionais. Além disso, a avaliação no dataset CICMalDroid alcançou uma taxa de verdadeiro-positivo média de 0,97 entre diferentes famílias de malware, superando métodos existentes na literatura.

Referências

de Oliveira, V. M., de Oliveira, H. M., Santos, G. M., Geremias, J., and Viegas, E. K. (2025). A big data framework for scalable and cross-dataset capable machine learning in network intrusion detection systems. IEEE Access, 13:129419–129431.

Dong, S., Shu, L., and Huang, J. (2026). A novel detection method for unknown android malware via image representation. Journal of Information Security and Applications, 99:104451.

Dong, S., Shu, L., and Nie, S. (2024). Android malware detection method based on cnn and dnn bybrid mechanism. IEEE Transactions on Industrial Informatics, 20(5):7744–7753.

Espindola, A. d. S., Casimiro, A., Santin, A. O., Ferreira, P. M., and Viegas, E. K. (2026a). Enhancing intrusion detection generalization via diversity-driven multi-view ensemble learning in industrial systems. Future Generation Computer Systems, 182:108458.

Espindola, A. d. S., Santin, A. O., Casimiro, A., Ferreira, P. M., and Viegas, E. K. (2026b). Understanding the adversary: A survey of adversarial machine learning in network intrusion detection. Computer Science Review, 62:100995.

Geremias, J., Britto, A. S., Santin, A. O., and Viegas, E. K. (2026). Sparse mixture of experts for image-based multi-view android malware detection. In 2026 International Wireless Communications and Mobile Computing (IWCMC), page 1487–1492. IEEE.

Geremias, J., Viegas, E. K., Santin, A. O., Britto, A., and Horchulhack, P. (2022). Towards multi-view android malware detection through image-based deep learning. In 2022 International Wireless Communications and Mobile Computing (IWCMC), page 572–577. IEEE.

Geremias, J., Viegas, E. K., Santin, A. O., Britto, A., and Horchulhack, P. (2023). Towards a reliable hierarchical android malware detection through image-based cnn. In 2023 IEEE 20th Consumer Communications amp; Networking Conference (CCNC), page 242–247. IEEE.

Haidros Rahima Manzil, H. and Manohar Naik, S. (2024). Detection approaches for android malware: Taxonomy and review analysis. Expert Systems with Applications, 238:122255.

Haq, I. U., Khan, T. A., and Akhunzada, A. (2021). A dynamic robust dl-based model for android malware detection. IEEE Access, 9:74510–74521.

Li, H., Cheng, X., Wang, L., and Wang, H. (2026). Towards improved dnn-based android malware detection via uncertainty estimation. ACM Transactions on Software Engineering and Methodology.

Li, H., Cheng, X., Zhang, G., Xu, G., Xu, G., and Wang, H. (2025). Mitigating emergent malware label noise in dnn-based android malware detection. Proceedings of the ACM on Software Engineering, 2(FSE):1136–1159.

List, S. (2026). The mobile threat landscape in 2025. Misalkar, H. D. and Harshavardhanan, P. (2025). Tdbamla: Temporal and dynamic behavior analysis in android malware using lstm and attention mechanisms. Computer Standards & Interfaces, 92:103920.

Musikawan, P., Kongsorot, Y., You, I., and So-In, C. (2023). An enhanced deep learning neural network for the detection and identification of android malware. IEEE Internet of Things Journal, 10(10):8560–8577.

Shu, L., Dong, S., Su, H., and Huang, J. (2023). Android malware detection methods based on convolutional neural network: A survey. IEEE Transactions on Emerging Topics in Computational Intelligence, 7(5):1330–1350.

Usama Tanveer, M., Munir, K., Alabdulatif, A., Najdawi, A. R., and Jhaveri, R. H. (2025). Malware-seqguard: An approach utilizing lstm and gru for effective detection of evolving malware in android environments. IEEE Access, 13:117355–117373.

Vasan, D., Alazab, M., Wassan, S., Naeem, H., Safaei, B., and Zheng, Q. (2020). Imcfn: Image-based malware classification using fine-tuned convolutional neural network architecture. Computer Networks, 171:107138.

Yapici, M. M. (2025). 3dmaldroid: A novel 3d image based approach for android malware detection and classification. Computers and Electrical Engineering, 127:110542.

Zhang, X., Wang, J., Xu, J., and Gu, C. (2023). Detection of android malware based on deep forest and feature enhancement. IEEE Access, 11:29344–29359.
Publicado
01/09/2026
KLOPPEL, Caio; GEREMIAS, Jhonatan; SANTIN, Altair O.; VIEGAS, Eduardo K.. Análise Espaço-Temporal de Binários Android Usando Representação Byte-to-Video. In: WORKSHOP DE TRABALHOS DE INICIAÇÃO CIENTÍFICA E DE GRADUAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 381-391. DOI: https://doi.org/10.5753/sbseg_estendido.2026.27930.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 3 4 > >>