Skip to content
Review Open access

Systematic Analysis of Machine Learning, Deep Learning, and Hybrid Models for Android and IoT Ecosystems: A Review

Sep 2026 · WIREs Data Mining and Knowledge Discovery · Vol 16 · 0 citations · 110 references

Abstract

The widespread adoption of Android and the Internet of Things (IoT) devices has led to a substantial increase in malware threats, challenging the effectiveness of traditional signature‐based security mechanisms. The dynamic and evolving nature of modern malware requires intelligent and adaptive detection techniques, making machine learning (ML) and deep learning (DL) approaches increasingly important. This paper presents a systematic survey of ML and DL‐based malware detection techniques, analyzing existing studies based on learning models, feature selection, datasets, and evaluation metrics. Conventional ML algorithms and advanced DL architectures including CNNs, RNNs, autoencoders, and hybrid models are critically compared. Our analysis confirms that DL and hybrid approaches outperform traditional ML methods for complex threats, though their accuracy and F1‐score depend heavily on dataset quality, feature engineering, and tuning. We synthesize widely used datasets and evolving malware families. However, despite strong experimental results, significant challenges remain, including dataset imbalance, IoT resource constraints, limited interpretability, and generalization gaps that hinder real‐world deployment. This study concludes that future work should prioritize developing lightweight, adaptive, and explainable detection frameworks that are specifically designed to operate under the operational constraints of Android and IoT platforms.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.