Dynamic Android Malware Detection Using Hierarchical Graph Attention Neural Networks on Traffic Flow Node Interactions
Jiayin Feng, Limin Shen, Shuxia Liu, Hui Li, Zhen Chen · IEEE Transactions on Consumer Electronics · 2025
The proliferation of IoT technologies has increased Android-based consumer electronics software, while these applications are susceptible to malware attacks. Applying network traffic for Android malware detection is being extensively developed. Existing approaches primarily focus on statistical features or visualized features of network traffic to detect malware. However, they require labeled data to maintain the detection accuracy. To further enhance detection accuracy and reduce the labeling rate of data, NFNI-MGATMg is proposed to detect Android malware and classify malware categories. First, the Network Flow Node Interaction Graph (NFNI) is introduced to convert the network traffic into the graph. Subsequently, the line graph principle is employed to transform the edges of NFNI into nodes, and both the node graphs and edge-node graphs are fed into the Multi-layer Graph Attention Network Merger (MGATMg) model to aggregate neighbor nodes for effective Android malware detection with limited labeled data. By leveraging MGATMg, it is possible to effectively capture both structural features and statistical features of network traffic, thereby enhancing the accuracy of malware detection. Finally, comprehensive experiments are designed to verify the effectiveness of our framework; the F1-scores of our model reached 98.83% and 91.7% for malware detection and malware category classification, respectively.