FEDWID roid: Android Malware Classification Based on Feature Embedding, Dynamic Weighting, and Interaction
Wei Liang, Zhi Xiong, Lingru Cai, Jianlong Xu · Concurrency and Computation Practice and Experience · 2026
ABSTRACT The threats posed by Android malware are becoming increasingly serious, and accurate detection and classification of such threats is critical in cybersecurity. This study proposes a new Android malware classification method called FEDWIDroid based on feature embedding, dynamic weighting, and interaction that addresses the shortcomings of existing Android malware classification methods concerning feature weighting and interaction. Seven types of binary features are extracted from Android installation package files. Next, the importance of these features is evaluated using information gain, the chi‐square test, and the Gini coefficient, and a subset of important features is selected using a reciprocal ranking fusion method. Gating and attention mechanisms are applied to the embedded features to perform weighted processing of the first‐ and second‐order features. Finally, the processed features are concatenated and input into a multilayer perceptron for classification. The gating and attention mechanisms dynamically weigh each element and the overall structure of the feature‐embedding vector, respectively. Feature embeddings encapsulate implicit feature interactions, whereas second‐order features directly model the explicit interactions between features. These mechanisms can capture contextual information and complex feature interactions, thereby enhancing the performance and generalizability of the classification model. The feasibility and effectiveness of the proposed method were validated by extensive testing on public datasets CICMalDroid2020 and CICMalAnal2017. For malware detection and classification tasks, the proposed method achieved detection and classification accuracies of 98.92% and 97.16% on CICMalDroid2020 and 97.12% and 90.59% on CICMalAnal2017, respectively.