Classificação de Malware Android com Multi-View e Late Fusion de Probabilidades

  • Philipe Fransozi PUCPR
  • Altair O. Santin PUCPR
  • Eduardo K. Viegas PUCPR

Resumo


A detecção de malware Android baseada em aprendizado de máquina tem se consolidado como uma alternativa diante da evolução e da diversidade de aplicações maliciosas no ecossistema. Apesar do potencial das abordagens multi-view, a integração direta de características heterogêneas frequentemente falha em explorar sinais complementares devido à dominância discriminativa da perspectiva estática. Para contornar essa limitação, o presente trabalho apresenta uma arquitetura baseada em late fusion probabilística que preserva a independência operacional de cada representação ao longo do pipeline de aprendizado de máquina. O método avalia estratégias de combinação linear e de fusão seletiva condicionada à confiança, isolando o comportamento de cada perspectiva antes da tomada de decisão. Dessa forma, utilizamos as características dinâmicas prioritariamente em cenários em que o classificador estático apresenta alto grau de incerteza. Os resultados experimentais obtidos com base em 50.500 aplicações alinhadas demonstram que as abordagens de fusão propostas superam, de forma consistente, o modelo estático unimodal de referência. Especificamente, a estratégia de integração tardia atinge o melhor desempenho absoluto do sistema, reduzindo o erro residual em aproximadamente 1,7% em relação ao F1-score máximo atingível.

Referências

Almarri, S., Bodokhi, A., and Frikha, M. (2025). A review of the recent trends in mobile malware evolution, detection, and analysis. IEEE Access, 13:108415–108445.

Bashir, S., Maqbool, F., Khan, F. H., and Abid, A. S. (2024). Hybrid machine learning model for malware analysis in android apps. Pervasive and Mobile Computing, 97:101859.

de Oliveira, V. M., de Oliveira, H. M., Santos, G. M., Geremias, J., and Viegas, E. K. (2025). A big data framework for scalable and cross-dataset capable machine learning in network intrusion detection systems. IEEE Access, 13:129419–129431.

Duan, G., Liu, H., Cai, M., Sun, J., and Chen, H. (2024). Madroid: A maliciousness-aware multifeatured dataset for detecting android malware. Computers & Security, 144:103969.

Espindola, A. d. S., Casimiro, A., Santin, A. O., Ferreira, P. M., and Viegas, E. K. (2026a). Enhancing intrusion detection generalization via diversity-driven multi-view ensemble learning in industrial systems. Future Generation Computer Systems, 182:108458.

Espindola, A. d. S., Santin, A. O., Casimiro, A., Ferreira, P. M., and Viegas, E. K. (2026b). Understanding the adversary: A survey of adversarial machine learning in network intrusion detection. Computer Science Review, 62:100995.

Ferreira, I., Oliveira, J. V. O. d., Purkott, F., Geremias, J., and Viegas, E. K. (2026). Lightweight multi-view dynamic android malware detection via time-windowed feature extraction. International Journal of Information Security, 25(3).

Filho, A. G., Viegas, E. K., Santin, A. O., and Geremias, J. (2025). A dynamic network intrusion detection model for infrastructure as code deployed environments. Journal of Network and Systems Management, 33(4).

Geremias, J., Britto, A. S., Santin, A. O., and Viegas, E. K. (2026). Sparse mixture of experts for image-based multi-view android malware detection. In 2026 International Wireless Communications and Mobile Computing (IWCMC), page 1487–1492. IEEE.

Guerra-Manzanares, A. (2024). Machine learning for android malware detection: Mission accomplished? a comprehensive review of open challenges and future perspectives. Computers & Security, 138:103654.

Kilic, K., Atacak, I., and Dogru, I. A. (2025). Fabldroid: Malware detection based on hybrid analysis with factor analysis and broad learning methods for android applications. Engineering Science and Technology, an International Journal, 62:101945.

Manzil, H. H. R. and Naik, M. (2024). Detection approaches for android malware: Taxonomy and review analysis. Expert Systems with Applications, 238:122255.

Meng, Y., Luktarhan, N., Yang, X., and Zhao, G. (2025a). Gbadroid: an android malware detection method based on multi-view feature fusion. The Journal of Supercomputing, 81(3).

Meng, Z., Zhang, J., Guo, J., Wang, W., Huang, W., Cui, J., Zhong, H., and Xiong, Y. (2025b). Detecting android malware by visualizing app behaviors from multiple complementary views. IEEE Transactions on Information Forensics and Security, 20:2915–2929.

Nasser, A. R., Hasan, A. M., and Humaidi, A. J. (2024). Dl-amdet: Deep learning-based malware detector for android. Intelligent Systems with Applications, 21:200318.

Rashid, M. U., Qureshi, S., Abid, A., Alqahtany, S. S., Alqazzaz, A., ul Hassan, M., Al Reshan, M. S., and Shaikh, A. (2025). Hybrid android malware detection and classification using deep neural networks. International Journal of Computational Intelligence Systems, 18(1):52.

Taher, F., AlFandi, O., Al-kfairy, M., Al Hamadi, H., and Alrabaee, S. (2023). Droiddetectmw: A hybrid intelligent model for android malware detection. Applied Sciences, 13(13):7720.

Trung, D. M., Hao, T. D. A., Minh, L. H., Khoa, N. H., Cam, N. T., Pham, V.-H., and Duy, P. T. (2025). Dmldroid: Deep multimodal fusion framework for android malware detection with resilience to code obfuscation and adversarial perturbations.

Wu, Q., Li, M., Zhu, X., and Liu, B. (2020). Mviidroid: A multiple view information integration approach for android malware detection and family identification. IEEE MultiMedia, 27(4):48–57.

Yunmar, R. A., Kusumawardani, S. S., Widyawan, and Mohsen, F. (2024). Hybrid android malware detection: A review of heuristic-based approach. IEEE Access, 12:41255–41286.

Zhang, S. et al. (2025). Mpdroid: A multimodal pre-training android malware detection method with static and dynamic features. Computers & Security, 150:104262.
Publicado
01/09/2026
FRANSOZI, Philipe; SANTIN, Altair O.; VIEGAS, Eduardo K.. Classificação de Malware Android com Multi-View e Late Fusion de Probabilidades. In: WORKSHOP DE TRABALHOS DE INICIAÇÃO CIENTÍFICA E DE GRADUAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 419-430. DOI: https://doi.org/10.5753/sbseg_estendido.2026.28877.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 3 4 > >>