TC-AMD: Android Malware Detection through Transfomer-CNN Hybrid Architecture
Namrata Govind Ambekar, Surmila Thokchom, Soumen Moulik · 2024
The upsurge of Android-based IoT devices has resulted in the exploitation of malware. Malicious applications pose significant risks, including unauthorized access, remote manipulation and privacy violations. Ensuring the security of these devices has become a critical industry concern. This paper introduces a hybrid neural network architecture called TC-AMD, which combines the use of a scalable and efficient transformer with a convolutional neural network (CNN) for detecting Android malware. This proposed TC-AMD model enhances the ability to detect Android malware by integrating the thorough understanding capabilities of the transformer with the localized feature extraction capabilities of CNN. This study utilizes the TUANDROMD dataset, which comprises permission-based and API-based features of Android applications, to distinguish between malicious and benign applications. The proposed TC-AMD model effectively classifies goodware and malware applications. It achieves a remarkable precision of 0.9750, recall of 0.9700, specificity of 0.9850, a low false positive rate (FPR) of 0.0150, f1 score of 0.9725 and impressive accuracy of 0.9770.