Home / Current Issue / Paper 1711462
An Ensemble Based Machine Learning Model for Android Malware Detection
Subject area: Science,Engineering and Technology · Area of research: Machine Learning
Abstract
The rapid growth of the Android ecosystem has been accompanied by an alarming increase in sophisticated malware, including banking Trojans, spyware, and ransomware. Traditional signature-based detection techniques are insufficient against obfuscation and zero-day attacks, highlighting the urgent need for adaptive detection mechanisms. This study aims to develop and evaluate an ensemble-based machine-learning model to enhance the detection of Android malware using the Andmaldataset. Recursive Feature Elimination (RFE) with a Decision Tree Classifier was employed to select the 20 most relevant features from the dataset. Five supervised classifiers Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), Logistic Regression, and Decision Tree were trained and evaluated. Additionally, three ensemble-learning techniques (Bagging, Boosting, and Stacking) were implemented to improve robustness and reduce false negatives. Among individual classifiers, SVM achieved the highest accuracy of 96.51%, while Random Forest recorded the strongest AUC score (0.9918). Ensemble methods outperformed individual classifiers, with Boosting yielding the highest accuracy (98.51%) and recall (96.32%), and Bagging achieving the best AUC (0.9930). Stacking also demonstrated stable and competitive performance across all metrics. The results confirm that ensemble learning significantly improves Android malware detection over single classifiers. Boosting and Bagging emerged as particularly effective strategies, offering strong accuracy and robustness against evolving malware threats.
Keywords
Android Malware, Machine Learning, Ensemble Learning, Bagging, Boosting, Stacking, Malware Detection
References
[1] Zhao, J., Mo, X., & Zheng, Q. (2018). A novel method of Android malware detection based on ensemble learning algorithm. In Proceedings of the 8th International Workshop on Computer Science and Engineering (WCSE 2018) (pp. 531–538).
[2] Wang, Y., & Wang, H. (2018). A hybrid model for Android malware detection. Journal of Information Security and Applications, 42, 1–10.
[3] Alzahrani, A., & Alshahrani, M. (2019). Android malware detection using machine learning techniques. International Journal of Computer Applications, 178(1), 1–7.
[4] Rana, M. S., & Sung, A. H. (2020). Evaluation of advanced ensemble learning techniques for Android malware detection. Vietnam Journal of Computer Science, 7(2), 145–159.
[5] Ullah, F., & Raza, A. (2020). A novel Android malware detection framework based on ensemble learning. Computers & Security, 95, 101866.
[6] Taha, A., & Barukab, O. (2022). Android malware classification using optimized ensemble learning based on genetic algorithms. Sustainability, 14, 14406.
[7] Wang, X., Zhang, L., Zhao, K., Ding, X., & Yu, M. (2022). MFDroid: A stacking ensemble learning framework for Android malware detection. Sensors, 22(7), 2597. [https://doi.org/10.3390/s22072597] (https://doi.org/10.3390/s22072597)
[8] Dhanya, L., Chitra, R., & Anusha Bamini, A. M. (2022). Performance evaluation of various ensemble classifiers for malware detection. Materials Today: Proceedings, 62, 4973–4979.
[9] Liu, Y., Tantithamthavorn, C., Li, L., & Liu, Y. (2022). Deep learning for Android malware defenses: A systematic literature review. ACM Computing Surveys, 55(8), 1–36. [https://doi.org/10.1145/3544968] (https://doi.org/10.1145/3544968)
[10] AbuAlghanam, O., Alazzam, H., Qatawneh, M., Aladwan, O., Alsharaiah, M. A., & Almaiah, M. A. (2023). Android malware detection system based on ensemble learning. Preprint.
[11] Alamro, H., Mtouaa, W., Aljameel, S., Salama, A. S., Hamza, M. A., & Othman, A. Y. (2023). Automated Android malware detection using optimal ensemble learning approach for cybersecurity. IEEE Access, 11, 72509–72517. [https://doi.org/10.1109/ACCESS.2023.3294263] (https://doi.org/10.1109/ACCESS.2023.3294263)
[12] Sumalatha, P., & Mahalakshmi, G. S. (2023). Machine learning based ensemble classifier for Android malware detection. International Journal of Computer Networks & Communications, 15(4), 111–122. [https://doi.org/10.5121/ijcnc.2023.15407] (https://doi.org/10.5121/ijcnc.2023.15407)
[13] Bakır, H. (2024). VoteDroid: A new ensemble voting classifier for malware detection based on fine-tuned deep learning models. Multimedia Tools and Applications. [https://doi.org/10.1007/s11042-024-19390-7] (https://doi.org/10.1007/s11042-024-19390-7)
[14] Bakır, H. (2024). Vote-Droid: A new ensemble voting classifier for malware detection based on fine-tuned deep learning models. Multimedia Tools and Applications. https://doi.org/10.1007/s11042-024-19390-7SpringerLink
[15] Amer, E. (2021, June 9). Permission-based approach for Android malware analysis through ensemble-based voting model. In A. Bahaa‑Eldin, A. AbdelRaouf, N. A. M. Shorim, R. O. M. Rashad, & S. E. Elbohy (Eds.), 2021 International Mobile, Intelligent, and Ubiquitous Computing Conference (MIUCC 2021) (pp. 135–139). IEEE. https://doi.org/10.1109/MIUCC52538.2021.9447675
[16] Android Open-Source Project. (2024). Architecture overview. Retrieved from https://source.android.com
[17] Google Developers. (2024). Android runtime (ART). Retrieved from https://developer.android.com
[18] Mishra, A., & Saha, P. (2023). "Security Enhancements in Android Kernel and HAL for IoT Devices." International Journal of Mobile Computing and Networking, 11(1), 22–35.
[19] Sharma, R., Singh, V., & Bhatia, M. (2025). "A Review of Android OS Architecture and Security Challenges." Journal of Mobile Systems and Applications, 19(2), 77–89.
[20] Comparitech. (2025, April 18). 20+ Android malware stats for 2025. https://www.comparitech.com/blog/vpn-privacy/20-current-android-malware-stats/
[21] Doctor Web. (2025, March 27). Q1 2025 review of virus activity on mobile devices. https://news.drweb.com/show/?i=14991&lng=en
[22] Spacelift. (2025, May 8). 50+ malware statistics for 2025. https://spacelift.io/blog/malware-statistics
[23] Deepstrike. (2025, April 28). 50+ malware statistics 2025: Attacks, trends and infections. https://deepstrike.io/blog/Malware-Attacks-and-Infections-2025
[24] Enck, W., Ongtang, M., & McDaniel, P. (2009). Understanding Android security. IEEE Security & Privacy, 7(1), 50–57. https://doi.org/10.1109/MSP.2009.26
How to cite this paper
@article{1711462,
author = {Baffa Sani Mahmoud, Prof. Rashid Husain, Assoc. Prof. Muhammad Hassan},
title = {An Ensemble Based Machine Learning Model for Android Malware Detection},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {4},
pages = {1207-1217},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1711462.pdf},
abstract = {The rapid growth of the Android ecosystem has been accompanied by an alarming increase in sophisticated malware, including banking Trojans, spyware, and ransomware. Traditional signature-based detection techniques are insufficient against obfuscation and zero-day attacks, highlighting the urgent need for adaptive detection mechanisms. This study aims to develop and evaluate an ensemble-based machine-learning model to enhance the detection of Android malware using the Andmaldataset. Recursive Feature Elimination (RFE) with a Decision Tree Classifier was employed to select the 20 most relevant features from the dataset. Five supervised classifiers Random Forest, Support Vector Machine (SVM), K-Nearest Neighbors (KNN), Logistic Regression, and Decision Tree were trained and evaluated. Additionally, three ensemble-learning techniques (Bagging, Boosting, and Stacking) were implemented to improve robustness and reduce false negatives. Among individual classifiers, SVM achieved the highest accuracy of 96.51%, while Random Forest recorded the strongest AUC score (0.9918). Ensemble methods outperformed individual classifiers, with Boosting yielding the highest accuracy (98.51%) and recall (96.32%), and Bagging achieving the best AUC (0.9930). Stacking also demonstrated stable and competitive performance across all metrics. The results confirm that ensemble learning significantly improves Android malware detection over single classifiers. Boosting and Bagging emerged as particularly effective strategies, offering strong accuracy and robustness against evolving malware threats.},
keywords = {Android Malware, Machine Learning, Ensemble Learning, Bagging, Boosting, Stacking, Malware Detection},
month = {October},
}