Image-Based Approach for Android Malware Detection Using APK Component Fusion and Deep Learning

El Youssofi Chaymae, Chougdali Khalid · 2025

The increase of Android malware, coupled with the growing sophistication of obfuscation techniques, underscores the critical need for advanced detection mechanisms. An innovative method is introdcued that converts essential APK components—namely, classes.dex (Dalvik executable), AndroidManifest.xml (manifest and configuration files), and resources.arsc (compiled resources)—into grayscale images. Incremental feature fusion is then applied to integrate both individual and combined components, allowing a comprehensive assessment of their impact on detection performance. The CICMalDroid 2020 dataset was employed to evaluate multiple convolutional neural network (CNN) architectures, with ResNet50 achieving the best results. The model attained an accuracy of 98.83%, a precision of 99.27%, and a recall of 99.15%, demonstrating the effectiveness of feature integration and deep learning techniques in overcoming obfuscation challenges and offering a robust solution for real-world Android malware detection systems.

Read the paper · More papers on PaperTik