Trandroid: An Android Mobile Threat Detection System Using Transformer Neural Networks
Thabet Kacem, Sourou Tossou · Electronics · 2025
In recent years, Android malware have been evolving and becoming more sophisticated at an alarming rate, highlighting the need for robust and evolving detection schemes. Despite the popularity of artificial intelligence-based approaches, they still struggle to generalize for various reasons. For instance, due to the reliance on handcrafted features for the machine learning approaches and the dependence on static datasets for the case of deep learning. In this paper, we bridge this gap by proposing Trandroid, an approach to detect diverse and real-world attack patterns targeting Android using transformers. This approach represents a major extension of our previous research to tackle this problem by developing a transformer-based Android attack detection system using the TUANDROMD dataset. Our choice of TUANDROMD was motivated by its wide coverage of Android attacks, support for metadata, and usage of feature extraction that makes it a good choice to build a holistic threat detection for Android using advanced AI models. We achieved a high accuracy rate of 99.25% with our state-of-the-art transformer model compared to the other classifiers we developed for comparison purposes, including Recurrent Neural Networks (RNNs), the Gated Recurrent Units (GRUs), Convolutional Neural Networks (CNNs), Long-Term Short-Term Memory (LSTM), and the hybrid CNN-LSTM model. Our Trandroid model also outperforms other approaches in the literature, considering all the performance indicators we used. These findings indicate the effectiveness of transformers in dealing with the evolving nature of Android malware and their promising potential for real-world deployment in mobile platforms.