Skip to content
Open access

XEnDroid: Explainable Stacking Ensemble Learning for Dynamic Android Malware Detection

Aug 2026 · Journal of ISMAC · Vol 8, pp. 308-323 · 0 citations · 13 references

TL;DR

XEnDroid (Xplainable Ensemble Droid), an advanced stacking ensemble approach for detecting malware on Android phones by combining random forest, convolution neural network, and transformer models under a logistic regression model is proposed.

Abstract

Android malware attributes to the increasing usage of code obfuscation, polymorphism, and dynamic execution. In this study, we propose XEnDroid (Xplainable Ensemble Droid), an advanced stacking ensemble approach for detecting malware on Android phones by combining random forest, convolution neural network, and transformer models under a logistic regression model. Dynamic behavioral features such as API, system call, and network activities are used for extracting features that are later reduced using PCA and processed through SMOTE. Model transparency is ensured by incorporating SHAP and LIME, which helps in understanding both global feature significance and prediction explanation locally. An experimental analysis using the CICMalDroid2020 dataset proves the effectiveness of the proposed method, as it results in 94.6% accuracy, 94.1% precision, 94.2% recall, 94.1% F1-score, and 0.986 AUC score.

Read PDF

Similar papers

Open access Aug 2026

Deep Learning for Malware Detection: TransformerBased Analysis of Windows Executables

A Transformerbased deep learning approach for detecting malicious Windows Portable Executable files is presented, significantly outperforming baseline methods including LightGBM, MalConv, and LSTM.

E. Baghirov · 0 citations
Open access Aug 2026

XAI-Guided Graph-Based Feature Engineering and Heterogeneous Ensemble Learning for Android Malware Detection

Android malware continues to evolve in sophistication, creating a need for accurate, efficient, and interpretable detection mechanisms. This paper proposes a novel Android malware detection framework that integrates graph-based software engineering analysis, explainable artificial intelligence (XAI), and heterogeneous...

Shahid Alam, Amina Jameel, Zahida Parveen et al. · 0 citations
Open access Aug 2026

A Hybrid Feature Model for Android Malware Detection

Android malware has become a significant cybersecurity threat due to the open nature of the Android platform. To address this issue, the present study proposes a hybrid malware detection model that combines static and dynamic features with feature selection and ensemble learning. Three feature selection methods, includ...

H. Alharbi, R. Marie · 0 citations
Open access Sep 2026

A lightweight static-analysis framework with optimized feature selection for android malware detection and classification

Android malware is growing rapidly, making detection more challenging and necessitating systems that are both accurate and efficient. This study aims to design a lightweight and reliable framework for Android malware detection and classification that reduces computational costs while maintaining strong performance. The...

V. Dwivedi, Akhilesh A. Waoo · 0 citations
Open access Aug 2026

Intelligent malware detection on Android smartphones via a hybrid approach using gradient boosting and convolutional neural network

Evaluation using metrics such as accuracy, precision, F1 score, and false positive rate indicates that CNN-GBM outperforms existing deep learning models, and enhancements stem from the effective integration of CNN feature extraction with GBM’s boosting capabilities.

C. Chimeleze, Norziana Jamil, Z. M. Zain et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.