Skip to content
Open access

Optimizing Android Malware Detection with Joint Feature Selection and Hidden Node Tuning: A BIGSA-HNO-ELM Framework

Aug 2026 · International journal for electronic crime investigation · 0 citations

TL;DR

This work proposes a unified malware detection framework that integrates Binary Improved Gravitational Search Algorithm for robust feature selection with Hidden Node Optimization (HNO) applied to an Extreme Learning Machine (ELM) classifier, making BIGSA-HNO-ELM a compelling solution for modern Android malware detection.

Abstract

The growing complexity and scale of Android malware present significant challenges for the development of detection systems that are both accurate and computationally efficient. Traditional machine learning methods often struggle with high-dimensional feature spaces and poorly optimized model architectures, leading to degraded accuracy and excessive resource consumption. To address these limitations, we propose a unified malware detection framework—BIGSA-HNO-ELM—that integrates Binary Improved Gravitational Search Algorithm (BIGSA) for robust feature selection with Hidden Node Optimization (HNO) applied to an Extreme Learning Machine (ELM) classifier. Evaluated on the KronoDroid dataset comprising over 78,000 Android applications with 464 hybrid static and dynamic behavioural features, the proposed framework achieves a 77% reduction in feature dimensionality, significantly lowering computational overhead while preserving high detection accuracy. Through HNO, the optimal number of ELM hidden neurons is dynamically determined, enhancing generalization and reducing overfitting. Comprehensive experiments demonstrate that the BIGSA-HNO-ELM model achieves 98.0% accuracy, 97.4 % precision, 96.2 % recall, 96.8 % F1-Score and an AUC-ROC of 97.0%, substantially outperforming baseline methods. Statistical significance testing (paired t-tests and Wilcoxon signed-rank tests, p < 0.01) confirms the robustness of these performance gains and demonstrates superior stability across 10-fold cross-validation with minimal variance in performance metrics. This integrated optimization approach not only improves predictive performance but also supports deployment in resource-constrained and real-time environments, making BIGSA-HNO-ELM a compelling solution for modern Android malware detection.

Read PDF

Similar papers

Open access Jul 2026

Intelligent Android Malware Classification Using Equilibrium Optimizer and Deep LearningModel

An intelligent Android malware detection framework that combines deep learning with the Equilibrium Optimizer to improve detection performance is presented, providing an effective and reliable solution for securing Android devices against evolving malware threats.

Aishwarya Eklar, G.Rajini · 0 citations
Jul 2026

Enhanced static analysis framework for multi-class Android malware detection using machine learning

The results have shown how well-engineered static features coupled with overfitting-aware ensemble design can give robust results of multi-class malware classification in the absence of dynamic traces, to develop additional resilience from obfuscation and runtime-evasive threats.

H. Lamkuche, Mannat Pal · 0 citations
Jul 2026

FUADroid: android malware detection with multi-view API feature fusion using machine learning

FUADroid is proposed, a static malware detection method that fuses structural and statistical-semantic views and achieves strong detection performance and exhibits improved robustness under cross-year evaluation settings.

Jiyun Yang, Fan Mei, Zheng-Dong Wan et al. · 0 citations
Open access Sep 2026

Android Malware Detection via Hybrid Static-Dynamic Analysis and Metaheuristic Feature Selection

The rapid proliferation of Android applications has significantly increased the exposure of mobile devices to malware, necessitating accurate and robust detection mechanisms. While hybrid malware analysis that combines static and dynamic features has been widely adopted for Android malware detection, the effectiveness...

Unknown authors · 0 citations
Open access Aug 2026

Optimizing Multiclass Android Malware Family Classification Using SMOTE-Tomek Links and XGBoost

The increasing sophistication of Android malware attacks has created significant challenges for accurate malware family classification, particularly under highly imbalanced data distributions where minority malware families are frequently misclassified. This study presents a robust multiclass Android malware family cla...

Ali Nur Ikhsan, Adam Prayogo Kuncoro, Debby Ummul Hidayah et al. · 0 citations
Open access Aug 2026

Empirical Evaluation and New Insights of Concept Drift in ML-Based Android Malware Detection

Despite outstanding results, machine learning-based Android malware detection models struggle with concept drift, where rapidly evolving malware characteristics degrade model effectiveness. This study examines the impact of concept drift on Android malware detection, evaluating two datasets and nine machine learning an...

Ahmed Sabbah, Mohammed F. Kharma, Radi Jarrar et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.