AndroMesh: Android Malware Detection Using Graph Neural Networks with Function-Aware Local-Global Topology
Alpay Tekin, Ahmet Selman Bozkır, Murat Aydosa · Procedia Computer Science · 2025
As smart devices become more widely used and accessible, ensuring security in the Android ecosystem has become critical. In response, researchers have proposed numerous methods to detect malicious applications. However, many of these approaches have significant limitations. They are often resource-intensive and time-consuming. They also rely on hand-crafted features or depend on a limited set of statically generated features. These features fail to effectively capture the underlying characteristics of malicious and benign samples. In this study, we propose a novel malware detection framework that leverages function call graphs (FCGs) combined with advanced graph neural network architectures with enhanced node embedding. This paper presents a malware detection framework called AndroMesh that combines FCGs with advanced graph neural networks and enhanced node representation. We extract rich structural information to generate initial node features and design a hybrid architecture that captures local patterns using GraphSAGE and global dependencies via Exphormer. This enables comprehensive representation learning and improves malware detection performance. Experiments show that our method either outperforms or demonstrates comparable performance to existing approaches in terms of accuracy and efficiency while exhibiting robust generalization. Our results, which achieve a test accuracy of 93.5%, highlight the effectiveness of combining graph structural features with advanced neural architectures for malware detection.