字节码
计算机科学
Android(操作系统)
恶意软件
Android恶意软件
人工智能
可执行文件
操作系统
计算机安全
机器学习
虚拟机
作者
Jiahao Song,Runzhi Li,Zijiao Zhang
标识
DOI:10.1145/3603273.3635055
摘要
The high market share and open-source nature of the Android system led to a significant increase in the number of malicious Android applications. It poses a lot of threats for users, such as financial costs, privacy breaches, and remote control. It is more efficient to construct accurate models to detect Android malware. We propose a novel Android malware detection framework MGIDroid. It considers two modality feature representations at the same: the function call graph (FCG) and Dex bytecode image features of Android applications. First, we construct an FCG that describes the relations between function calls for an Android application. We use GraphSAGE with the SAGPool model to extract FCG features. Next, we convert Dalvik Executable files of Android applications to Dex bytecode image, Resnet model with Convolutional Block Attention Module (CBAM) is adopted to extract image features that represent the data section of an Android application. Then, we use soft attention to fuse two modalities features to finish classification. Lastly, extensive experiments were conducted to evaluate the effectiveness of our approach. The results show that our proposed method outperforms other methods and achieves a high f1-score of 98.60%.
科研通智能强力驱动
Strongly Powered by AbleSci AI