Empirical Evaluation of Concept Drift in ML-Based Android Malware Detection
Sabbah, Ahmed, Jarrar, Radi, Zein, Samer, Mohaisen, David
–arXiv.org Artificial Intelligence
This study examines the impact of concept drift on Android malware detection, evaluating two datasets and nine machine learning and deep learning algorithms, as well as Large Language Models (LLMs). Various feature types--static, dynamic, hybrid, semantic, and image-based--were considered. The results showed that concept drift is widespread and significantly affects model performance. Factors influencing the drift include feature types, data environments, and detection methods. Balancing algorithms helped with class imbalance but did not fully address concept drift, which primarily stems from the dynamic nature of the malware landscape. No strong link was found between the type of algorithm used and concept drift, the impact was relatively minor compared to other variables since hyperparameters were not fine-tuned, and the default algorithm configurations were used. While LLMs using few-shot learning demonstrated promising detection performance, they did not fully mitigate concept drift, highlighting the need for further investigation.
arXiv.org Artificial Intelligence
Jul-31-2025
- Country:
- Asia
- Malaysia (0.04)
- Middle East
- Europe
- Netherlands > Drenthe
- Assen (0.04)
- United Kingdom (0.04)
- Netherlands > Drenthe
- North America > United States
- Florida > Orange County
- Orlando (0.14)
- Minnesota (0.04)
- Florida > Orange County
- Asia
- Genre:
- Research Report
- Experimental Study (1.00)
- New Finding (1.00)
- Research Report
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: