Experiences of landing machine learning onto market-scale mobile malware detection
Liangyi Gong, Zhenhua Li, Feng Qian, Zifan Zhang, Qi Alfred Chen, Zhiyun Qian, Hao Lin, Yunhao Liu
Abstract
App markets, being crucial and critical for today's mobile ecosystem, have also become a natural malware delivery channel since they actually "lend credibility" to malicious apps. In the past decade, machine learning (ML) techniques have been explored for automated, robust malware detection. Unfortunately, to date, we have yet to see an ML-based malware detection solution deployed at market scales. To better understand the real-world challenges, we conduct a collaborative study with a major Android app market (T-Market) offering us large-scale ground-truth data. Our study shows that the key to successfully developing such systems is manifold, including feature selection/engineering, app analysis speed, developer engagement, and model evolution. Failure in any of the above aspects would lead to the "wooden barrel effect" of the entire system. We discuss our careful design choices as well as our first-hand deployment experiences in building such an ML-powered malware detection system. We implement our design and examine its effectiveness in the T-Market for over one year, using a single commodity server to vet 10K apps every day. The evaluation results show that this design achieves an overall precision of 98% and recall of 96% with an average per-app scan time of 1.3 minutes.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 25714656-555f-42d7-bc65-e708b700633bCited by top-tier papers9
- HomDroid: detecting Android covert malware by social-network homophily analysisYueming Wu, Deqing Zou, Wei Yang, Xiang Li et al.ISSTA 2021 · 22 citations
- Virtual Device Farms for Mobile App Testing at Scale: A Pursuit for Fidelity, Efficiency, and AccessibilityHao Lin, Jiaxing Qiu, Hongyi Wang, Zhenhua Li et al.MobiCom 2023 · 18 citations
- Graph BackdoorZhaohan Xi, Ren Pang, Shouling Ji, Ting WangUSENIX Security 2021 · 12 citations
- Sifter: protecting security-critical kernel modules in Android through attack surface reductionHsin-Wei Hung, Yingtong Liu, Ardalan Amiri SaniMobiCom 2022 · 6 citations
- Primo: Practical Learning-Augmented Systems with Interpretable ModelsQinghao Hu, Harsha Nori, Peng Sun, Yonggang Wen et al.USENIX ATC 2022 · 5 citations
Builds on3
- MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral ModelsEnrico Mariconti, Lucky Onwuzurike, Panagiotis Andriotis, Emiliano De Cristofaro et al.NDSS 2017 · 471 citations
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 253 citations
- Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback LoopYanick Fratantonio, Chenxiong Qian, Simon P. Chung, Wenke LeeS&P 2017 · 126 citations
Related papers
- The Illusion of Success: Learning-Based Android Malware Detectors (Replicability Study)Michael Tegegn, Julia RubinISSTA 2026
- Robust Android Malware Detection against Adversarial Example AttacksHeng Li, Shiyao Zhou, Wei Yuan, Xiapu Luo et al.WWW 2021 · 56 citations
- Continuous Learning for Android Malware DetectionYizheng Chen, Zhoujie Ding, David A. WagnerUSENIX Security 2023
- A Large-scale Temporal Measurement of Android Malicious Apps: Persistence, Migration, and Lessons LearnedYun Shen, Pierre-Antoine Vervier, Gianluca StringhiniUSENIX Security 2022
- LAMDA: A Longitudinal Android Malware Benchmark for Concept Drift AnalysisMd Ahsanul Haque, Ismail Hossain, Md Mahmuduzzaman Kamol, Md Jahangir Alam et al.ICLR 2026 · 14 citations
