Proceedings of International Conference on Applied Innovation in IT  ·  2026/06/12  ·  Vol. 14  ·  Issue 3  ·  pp. 37–50
Android Malware Detection Using Semantic Permission Analysis
Ali Hussein Mohammed Ali and Musaab Riyadh Abdulrazzaq
Scalable Static analysis is progressively considered as the basis of Android malware detection, but the raw permission vectors are sparse, noisy and hard to interpret in the changing app ecosystems. In this paper, the authors of the research hypothesise a semantic permission-based detection pipeline to compress Android permissions into understandable capability sets and combine objective weighting with multi-criteria decision making (MCDM) to extract audit risk indicators. Using a conservative VirusTotal-based labeling policy to construct a balanced AndroZoo subset (38,062 apps) and test ablation baselines (becoming successively more inclusive of raw permission binary, semantic category statistics, objective weights (Entropy and CRITIC) and MCDM risk scores (TOPSIS/VIKOR). Using stratified holdout split, the optimal configuration (hybrid features with Random Forest) has an Accuracy of 83.16 and ROC-AUC of 91.73 (F1 = 83.25, MCC = 0.663), indicating that the inclusion of MCDM-derived risk signals can both increase the performance in terms of Discriminative and Increase the interpretability. The suggested design is aimed at large-scale screening processes whereby predictive and transparent risk cues should be present besides prediction. It has limitations: it depends on VirusTotal-style labels (subject to engine disagreement and temporal drift) and the existing evaluation is not yet external-dataset-generalization, temporal split validation, or robustness against obfuscation, and these are put as prioritized extensions to future work.
Android Malware Detection Static Analysis Semantic Categories Entropy Weighting CRITIC TOPSIS.
References
  1. Y. Pan, X. Ge, C. Fang, and Y. Fan, “A Systematic Literature Review of Android Malware Detection Using Static Analysis,” IEEE Access, vol. 8, pp. 116363-116379, 2020, [Online]. Available: https://doi.org/10.1109/ACCESS.2020.3002842.
  2. A. Alzubaidi, “Recent Advances in Android Mobile Malware Detection: A Systematic Literature Review,” 2021, Institute of Electrical and Electronics Engineers Inc., [Online]. Available: https://doi.org/10.1109/ACCESS.2021.3123187.
  3. S. F. Ali, M. R. Abdulrazzaq, and M. T. Gaata, “Learning Techniques-Based Malware Detection: A Comprehensive Review,” Mesopotamian Journal of CyberSecurity, vol. 5, no. 1, pp. 273-300, 2025.
  4. R. H. Mahdi and H. Trabelsi, “Detection of Malware by Using YARA Rules,” in 2024 21st International Multi-Conference on Systems, Signals & Devices (SSD), 2024, pp. 1-8, [Online]. Available: https://doi.org/10.1109/SSD61670.2024.10549308.
  5. T. Pathak, T. S. Kumar, and U. Barman, “Static analysis framework for permission-based dataset generation and android malware detection using machine learning,” EURASIP Journal on Information Security, vol. 2024, no. 1, p. 33, 2024.
  6. S. R. T. Mat, M. F. A. Razak, M. N. M. Kahar, J. M. Arif, and A. Firdaus, “A Bayesian probability model for Android malware detection,” ICT Express, vol. 8, no. 3, pp. 424-431, 2022, [Online]. Available: https://doi.org/10.1016/j.icte.2021.09.003.
  7. Z. Namrud, S. Kpodjedo, A. Bali, and C. Talhi, “Deep-Layer Clustering to Identify Permission Usage Patterns of Android App Categories,” IEEE Access, vol. 10, pp. 24240-24254, 2022, [Online]. Available: https://doi.org/10.1109/ACCESS.2022.3156083.
  8. Y. Song, Y. Geng, J. Wang, S. Gao, and W. Shi, “Permission Sensitivity-Based Malicious Application Detection for Android,” Security and Communication Networks, vol. 2021, 2021, [Online]. Available: https://doi.org/10.1155/2021/6689486.
  9. K. Allix, T. F. Bissyandé, J. Klein, and Y. Le Traon, “AndroZoo: collecting millions of Android apps for the research community,” in Proceedings of the 13th International Conference on Mining Software Repositories, in MSR ’16, New York, NY, USA: Association for Computing Machinery, 2016, pp. 468-471, [Online]. Available: https://doi.org/10.1145/2901739.2903508.
  10. J. Wang, X. H. Liu, M. Huang, P. Zhou, and Y. Xu, “Android Malware Detection Method Combining Multi-Frequency Features and Convolutional Neural Networks,” IEEE Access, p. 1, 2025, [Online]. Available: https://doi.org/10.1109/ACCESS.2025.3550124.
  11. H. Kato, T. Sasaki, and I. Sasase, “Android Malware Detection Based on Composition Ratio of Permission Pairs,” IEEE Access, vol. 9, pp. 130006-130019, 2021, [Online]. Available: https://doi.org/10.1109/ACCESS.2021.3113711.
  12. S. Banik and J. P. Singh, “Android Malware Detection by Correlated Real Permission Couples Using FP Growth Algorithm and Neural Networks,” IEEE Access, vol. 11, pp. 124996-125010, 2023, [Online]. Available: https://doi.org/10.1109/ACCESS.2023.3323845.
  13. J. Xu, Y. Li, R. H. Deng, and K. Xu, “SDAC: A Slow-Aging Solution for Android Malware Detection Using Semantic Distance Based API Clustering,” IEEE Transactions on Dependable and Secure Computing, vol. 19, no. 2, pp. 1149-1163, Mar. 2022, [Online]. Available: https://doi.org/10.1109/TDSC.2020.3005088.
  14. Z. Meng et al., “Detecting Android Malware by Visualizing App Behaviors from Multiple Complementary Views,” IEEE Transactions on Information Forensics and Security, p. 1, 2025, [Online]. Available: https://doi.org/10.1109/TIFS.2025.3547301.
  15. H. He and E. A. Garcia, “Learning from Imbalanced Data,” IEEE Transactions on Knowledge and Data Engineering, vol. 21, no. 9, pp. 1263-1284, Sep. 2009, [Online]. Available: https://doi.org/10.1109/TKDE.2008.239.
  16. C. Drummond, R. C. Holte, and others, “C4.5, class imbalance, and cost sensitivity: why under-sampling beats over-sampling,” in Workshop on Learning from Imbalanced Datasets II, 2003.
  17. D. Arp, M. Spreitzenbarth, M. Hubner, H. Gascon, K. Rieck, and C. Siemens, “Drebin: Effective and explainable detection of android malware in your pocket,” in NDSS, 2014, pp. 23-26.
  18. G. S. Tuncay, “Android permissions: Evolution, attacks, and best practices,” IEEE Security & Privacy, vol. 22, no. 6, pp. 40-49, 2024.
  19. S. Martinčić-Ipšić, T. Miličić, and L. Todorovski, “The influence of feature representation of text on the performance of document classification,” Applied Sciences, vol. 9, no. 4, p. 743, 2019.
  20. A. Sabbah, R. Jarrar, S. Zein, and D. Mohaisen, “Understanding Concept Drift with Deprecated Permissions in Android Malware Detection,” arXiv, Jul. 2025, [Online]. Available: https://doi.org/10.48550/arXiv.2507.22231.
  21. O. A. Akanbi, I. S. Amiri, and E. Fazeldehkordi, A Machine-Learning Approach to Phishing Detection and Defense. Syngress, 2014.
  22. C. E. Shannon, “A mathematical theory of communication,” The Bell System Technical Journal, vol. 27, no. 3, pp. 379-423, 1948.
  23. Y. Sharma and A. Arora, “IPAnalyzer: A Novel Android Malware Detection System Using Ranked Intents and Permissions,” Multimedia Tools and Applications, vol. 83, no. 10, pp. 12345-12362, Mar. 2024, [Online]. Available: https://doi.org/10.1007/s11042-024-18511-6.
  24. A. Alomar, A. A. Aljarullah, and S. Abu-Ghazalah, “Permissions-Based Android Malware Detection Using Machine Learning,” Neural Computing and Applications, vol. 37, no. 6, pp. 5255-5270, Dec. 2024, [Online]. Available: https://doi.org/10.1007/s00521-024-10950-4.
  25. Y. Sharma and A. Arora, “A Comprehensive Review on Permissions-Based Android Malware Detection,” International Journal of Information Security, vol. 23, no. 3, pp. 1877-1912, Mar. 2024, [Online]. Available: https://doi.org/10.1007/s10207-024-00822-2.
  26. S. Jogsan, “A Survey on Permission-Based Malware Detection in Android Applications,” International Journal of Engineering Research and Technology, vol. 9, no. 4, pp. 774-778, May 2020, [Online]. Available: https://doi.org/10.17577/IJERTV9IS040774.


Proceedings of the International Conference on Applied Innovations in IT by Anhalt University of Applied Sciences is licensed under CC BY-SA 4.0
 ·  This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License

ICAIIT 2026
International Conference on Applied Innovation in IT
Navigation
Publisher
ISSN2199-8876
Location Anhalt University of Applied Sciences
Phone +49 (0) 3496 67 5611
Address Building 01, Room 425
Bernburger Str. 55
D-06366 Köthen, Germany
Open Access License

All works are licensed under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0), unless otherwise noted.

Published by ICAIIT in cooperation with Anhalt University of Applied Sciences.

© 2026 ICAIIT — International Conference on Applied Innovations in IT. Anhalt University of Applied Sciences, Köthen, Germany.
Visitors: site traffic counter