Robust Android malware detection against obfuscation and adversarial attacks using RGB Markov images and deep ensemble learning

Kawthar Chakif, Faria Nawshin, Devrim Ünal · Knowledge-Based Systems · 2026

Android malware detection remains a critical challenge as adversaries increasingly employ evasion strategies to bypass traditional defenses. This study introduces a novel ensemble-based detection framework that transforms APK components into RGB Markov images, encoding both structural and statistical byte patterns. A deep ensemble of EfficientNet-B0, ConvNeXt-Small, and Swin-Base models processes these images, integrating their predictions through majority voting to provide reliable decision support. A balanced dataset, KindiDroid, was constructed comprising 95,400 images, including 16,100 unobfuscated samples and 79,300 obfuscated variants generated with thirteen Obfuscapk techniques. The ensemble achieved an F1-score of 99.13% and an AUC of 99.86% on clean data, while preserving over 96% performance across all obfuscation strategies despite being trained solely on unobfuscated samples. Furthermore, resilience against adversarial evasion was demonstrated, with adversarial training restoring performance above 97% under FGSM attacks and above 94% under PGD attacks applied to both clean and obfuscated inputs. These results establish a new benchmark, underscoring the ability of the framework to provide robust defense under realistic black-box and white-box scenarios.

Read the paper · More papers on PaperTik