Catch the Intruder: Collaborative and Personalized Malware Detection By On-Device Application Fingerprinting

Amirmohammad Pasdar, Young Choon Lee, Seok-Hee Hong · 2023

The vulnerability of smartphones to cyber attacks has been a serious concern to users arising from the integrity of installed applications (mobile apps). These apps are to provide legitimate and diversified on-the-go services. However, some have uncovered ways to penetrate smartphones for malicious behaviors. While some development and distribution regulations, such as Google Play Protect are in place, their effectiveness is often limited due primarily to falling behind the emergence of new malware. This paper presents an Analytic-based deep neural network Android Malware detection (ADAM) to detect potentially dangerous apps based on a set of features and patterns, i.e., application fingerprints, extracted from mobile apps. In particular, ADAM uses these features and patterns to train feature-specific DNNs to have consensus on the application labels when their ground truth is unknown. In addition, ADAM leverages the transfer learning technique to obtain its adjustability to new applications across smartphones. This is done by reusing the pre-trained model(s) and making them more adaptable by model personalization and federated learning (FL) techniques. This adjustability facilitates collaborative detection and independent labeling across smartphones, assisted by FL guards, which protect ADAM against poisoning attacks through model analysis. ADAM relies on a diverse dataset containing more than 153000 applications with over 41000 extracted features for DNNs training. ADAM’s feature-specific DNNs, on average, achieved more than 98% accuracy compared to Play Protect and antivirus software, resulting in an outstanding performance against data manipulation attacks.

Read the paper · More papers on PaperTik