Android Malware Detection Method Based on Representation Learning of Sensitive Function Call Graphs
DU Yunlong
ZHAO Shenghui
Abstract:To address the issue that Android malware was often obfuscated to evade detection,a method named sensitive function call graphs detector(SFCG_Detector)based on representation learning of sensitive function call graphs(SFCG)was proposed for detecting Android malware.Firstly,function call graphs were extracted through static analysis,and a graph pruning strategy was designed to preserve critical nodes related to sensitive application programming interfaces(API).This reduced graph complexity while retaining behavioral semantics.For node representation,semantic features and structural importance of nodes were captured using a bidirectional encoder representation from transformers(BERT)model and Katz centrality,respectively.Subsequently,the SFCG were hierarchically learned using the graph sample and aggregation(GraphSAGE)network to generate graph-level embeddings to support the classification task.Experimental results on the Canadian institute for cybersecurity malware dataset 2020(CICMalDroid 2020)demonstrated that SFCG_Detector achieved a malware detection F1-score of 98.75%and recall of 98.89%.Compared with other methods,SFCG_Detector could effectively identify Android malware and improve the performance significantly.
Keywords:Android malware detectionfunction call graphgraph pruningsemantic knowledgegraph neural network
Publication Date:2025-12-30
Online Publishing Date:2025-12-10(First online date of this platform, not the publication date of the document)
Pages:6( 535-540 )
