International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1711462

1711462 Vol 9 · Issue 4 Download Paper

An Ensemble Based Machine Learning Model for Android Malware Detection

Baffa Sani Mahmoud Prof. Rashid Husain Assoc. Prof. Muhammad Hassan

Subject area: Science,Engineering and Technology  ·  Area of research: Machine Learning

Abstract

The rapid growth of the Android ecosystem has been accompanied by an alarming increase in sophisticated malware, including banking Trojans, spyware, and ransomware. Traditional signature-based detection techniques are insufficient against obfuscation and zero-day attacks, highlighting the urgent need for adaptive detection mechanisms. This study aims to develop and evaluate an ensemble-based machine-learning model to enhance the detection of Android malware using the Andmaldataset. Recursive Feature Elimination (RFE) with a Decision Tree Classifier was employed to select the 20 most relevant features from the dataset. Five supervised classifiers Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), Logistic Regression, and Decision Tree were trained and evaluated. Additionally, three ensemble-learning techniques (Bagging, Boosting, and Stacking) were implemented to improve robustness and reduce false negatives. Among individual classifiers, SVM achieved the highest accuracy of 96.51%, while Random Forest recorded the strongest AUC score (0.9918). Ensemble methods outperformed individual classifiers, with Boosting yielding the highest accuracy (98.51%) and recall (96.32%), and Bagging achieving the best AUC (0.9930). Stacking also demonstrated stable and competitive performance across all metrics. The results confirm that ensemble learning significantly improves Android malware detection over single classifiers. Boosting and Bagging emerged as particularly effective strategies, offering strong accuracy and robustness against evolving malware threats.

Keywords

Android Malware, Machine Learning, Ensemble Learning, Bagging, Boosting, Stacking, Malware Detection

References

[1] Zhao, J., Mo, X., & Zheng, Q. (2018). A novel method of Android malware detection based on ensemble learning algorithm. In Proceedings of the 8th International Workshop on Computer Science and Engineering (WCSE 2018) (pp. 531–538).

[2] Wang, Y., & Wang, H. (2018). A hybrid model for Android malware detection. Journal of Information Security and Applications, 42, 1–10.

[3] Alzahrani, A., & Alshahrani, M. (2019). Android malware detection using machine learning techniques. International Journal of Computer Applications, 178(1), 1–7.

[4] Rana, M. S., & Sung, A. H. (2020). Evaluation of advanced ensemble learning techniques for Android malware detection. Vietnam Journal of Computer Science, 7(2), 145–159.

[5] Ullah, F., & Raza, A. (2020). A novel Android malware detection framework based on ensemble learning. Computers & Security, 95, 101866.

[6] Taha, A., & Barukab, O. (2022). Android malware classification using optimized ensemble learning based on genetic algorithms. Sustainability, 14, 14406.

[7] Wang, X., Zhang, L., Zhao, K., Ding, X., & Yu, M. (2022). MFDroid: A stacking ensemble learning framework for Android malware detection. Sensors, 22(7), 2597. [https://doi.org/10.3390/s22072597] (https://doi.org/10.3390/s22072597)

[8] Dhanya, L., Chitra, R., & Anusha Bamini, A. M. (2022). Performance evaluation of various ensemble classifiers for malware detection. Materials Today: Proceedings, 62, 4973–4979.

[9] Liu, Y., Tantithamthavorn, C., Li, L., & Liu, Y. (2022). Deep learning for Android malware defenses: A systematic literature review. ACM Computing Surveys, 55(8), 1–36. [https://doi.org/10.1145/3544968] (https://doi.org/10.1145/3544968)

[10] AbuAlghanam, O., Alazzam, H., Qatawneh, M., Aladwan, O., Alsharaiah, M. A., & Almaiah, M. A. (2023). Android malware detection system based on ensemble learning. Preprint.

[11] Alamro, H., Mtouaa, W., Aljameel, S., Salama, A. S., Hamza, M. A., & Othman, A. Y. (2023). Automated Android malware detection using optimal ensemble learning approach for cybersecurity. IEEE Access, 11, 72509–72517. [https://doi.org/10.1109/ACCESS.2023.3294263] (https://doi.org/10.1109/ACCESS.2023.3294263)

[12] Sumalatha, P., & Mahalakshmi, G. S. (2023). Machine learning based ensemble classifier for Android malware detection. International Journal of Computer Networks & Communications, 15(4), 111–122. [https://doi.org/10.5121/ijcnc.2023.15407] (https://doi.org/10.5121/ijcnc.2023.15407)

[13] Bakır, H. (2024). VoteDroid: A new ensemble voting classifier for malware detection based on fine-tuned deep learning models. Multimedia Tools and Applications. [https://doi.org/10.1007/s11042-024-19390-7] (https://doi.org/10.1007/s11042-024-19390-7)

[14] Bakır, H. (2024). Vote-Droid: A new ensemble voting classifier for malware detection based on fine-tuned deep learning models. Multimedia Tools and Applications. https://doi.org/10.1007/s11042-024-19390-7SpringerLink

[15] Amer, E. (2021, June 9). Permission-based approach for Android malware analysis through ensemble-based voting model. In A. Bahaa‑Eldin, A. AbdelRaouf, N. A. M. Shorim, R. O. M. Rashad, & S. E. Elbohy (Eds.), 2021 International Mobile, Intelligent, and Ubiquitous Computing Conference (MIUCC 2021) (pp. 135–139). IEEE. https://doi.org/10.1109/MIUCC52538.2021.9447675

[16] Android Open-Source Project. (2024). Architecture overview. Retrieved from https://source.android.com

[17] Google Developers. (2024). Android runtime (ART). Retrieved from https://developer.android.com

[18] Mishra, A., & Saha, P. (2023). "Security Enhancements in Android Kernel and HAL for IoT Devices." International Journal of Mobile Computing and Networking, 11(1), 22–35.

[19] Sharma, R., Singh, V., & Bhatia, M. (2025). "A Review of Android OS Architecture and Security Challenges." Journal of Mobile Systems and Applications, 19(2), 77–89.

[20] Comparitech. (2025, April 18). 20+ Android malware stats for 2025. https://www.comparitech.com/blog/vpn-privacy/20-current-android-malware-stats/

[21] Doctor Web. (2025, March 27). Q1 2025 review of virus activity on mobile devices. https://news.drweb.com/show/?i=14991&lng=en

[22] Spacelift. (2025, May 8). 50+ malware statistics for 2025. https://spacelift.io/blog/malware-statistics

[23] Deepstrike. (2025, April 28). 50+ malware statistics 2025: Attacks, trends and infections. https://deepstrike.io/blog/Malware-Attacks-and-Infections-2025

[24] Enck, W., Ongtang, M., & McDaniel, P. (2009). Understanding Android security. IEEE Security & Privacy, 7(1), 50–57. https://doi.org/10.1109/MSP.2009.26

How to cite this paper

Baffa Sani Mahmoud, Prof. Rashid Husain, Assoc. Prof. Muhammad Hassan "An Ensemble Based Machine Learning Model for Android Malware Detection" Iconic Research And Engineering Journals Volume 9 Issue 4 2025 Page 1207-1217
Baffa Sani Mahmoud, Prof. Rashid Husain, Assoc. Prof. Muhammad Hassan "An Ensemble Based Machine Learning Model for Android Malware Detection" Iconic Research And Engineering Journals, vol. 9, no. 4, Oct. 2025
Baffa Sani Mahmoud, Prof. Rashid Husain, Assoc. Prof. Muhammad Hassan (2025). An Ensemble Based Machine Learning Model for Android Malware Detection. Iconic Research And Engineering Journals, 9(4).
Baffa Sani Mahmoud, Prof. Rashid Husain, Assoc. Prof. Muhammad Hassan "An Ensemble Based Machine Learning Model for Android Malware Detection" Iconic Research And Engineering Journals, vol. 9, no. 4, Oct. 2025.
@article{1711462,
      author = {Baffa Sani Mahmoud, Prof. Rashid Husain, Assoc. Prof. Muhammad Hassan},
      title = {An Ensemble Based Machine Learning Model for Android Malware Detection},
      journal = {Iconic Research And Engineering Journals},
      year = {2025},
      volume = {9},
      number = {4},
      pages = {1207-1217},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1711462.pdf},
      abstract = {The rapid growth of the Android ecosystem has been accompanied by an alarming increase in sophisticated malware, including banking Trojans, spyware, and ransomware. Traditional signature-based detection techniques are insufficient against obfuscation and zero-day attacks, highlighting the urgent need for adaptive detection mechanisms. This study aims to develop and evaluate an ensemble-based machine-learning model to enhance the detection of Android malware using the Andmaldataset. Recursive Feature Elimination (RFE) with a Decision Tree Classifier was employed to select the 20 most relevant features from the dataset. Five supervised classifiers Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), Logistic Regression, and Decision Tree were trained and evaluated. Additionally, three ensemble-learning techniques (Bagging, Boosting, and Stacking) were implemented to improve robustness and reduce false negatives. Among individual classifiers, SVM achieved the highest accuracy of 96.51%, while Random Forest recorded the strongest AUC score (0.9918). Ensemble methods outperformed individual classifiers, with Boosting yielding the highest accuracy (98.51%) and recall (96.32%), and Bagging achieving the best AUC (0.9930). Stacking also demonstrated stable and competitive performance across all metrics. The results confirm that ensemble learning significantly improves Android malware detection over single classifiers. Boosting and Bagging emerged as particularly effective strategies, offering strong accuracy and robustness against evolving malware threats.},
      keywords = {Android Malware, Machine Learning, Ensemble Learning, Bagging, Boosting, Stacking, Malware Detection},
      month = {October},
  }