Enhancing android security with explainable AI: a hybrid malware detection framework using static and dynamic features

Citation

Abstract

Mobile phones have become a major target of cyberattacks because of their vast number of users and open-source nature. Among these many threats, Adware and Trojans are frequent and serious threats that undermine user privacy and all-around system reliability. We investigate the effectiveness of machine learning in classifying malware samples into either Adware or Trojan. We discuss a rigorous data prepro- cessing pipeline to balance the class distribution by synthetic oversampling, filtering features based on their statistical characteristics, and scaling numeric variables to have zero mean and unit variance. Multiple model evaluation metrics-precision, recall, F1 score, balanced accuracy, and ROC AUC-indicate our models can tell the differences between these classes with Random Forest achieving 96% accuracy in both features. Of particular note are ensemble classifiers, which achieve high performance and demonstrate how integrating various decision boundaries can yield superior results without excessive computational overhead. These findings speak vol- umes on the practical importance of robust preprocessing, balanced datasets, and interpretable methods for feature importance in order to delve deeper into malicious behaviors. The study gives ample emphasis on evidence-based model selection and shows how such advanced strategies can fortify cybersecurity measures in today’s ever-changing world of mobile technologies.

Description

Cataloged from PDF version of thesis.
Includes bibliographical references (pages 48-49).
This thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science and Engineering, 2025.

Publisher Link

Type

Thesis