Advanced Financial Fraud Malware Detection Method in the Android Environment

Citations

WEB OF SCIENCE

3
Citations

SCOPUS

4

초록

The open-source structure and ease of development in the Android platform are exploited by attackers to develop malicious programs, greatly increasing malicious Android apps aimed at committing financial fraud. This study proposes a machine learning (ML) model based on static analysis to detect malware. We validated the significance of private datasets collected from Bank A, comprising 183,938,730 and 11,986 samples of benign and malicious apps, respectively. Undersampling was performed to adjust the proportion of benign applications in the training data because the data on benign and malicious apps were unbalanced. Moreover, 92 datasets were compiled through daily training to evaluate the proposed approach, with benign app data updated over 70 days (D-70 to D-1) and malware app data cumulatively aggregated to address the imbalance. Five ML algorithms were used to evaluate the proposed approach, and the optimal hyperparameter values for each algorithm were obtained using a grid search method. We then evaluated the models using common evaluation metrics, such as accuracy, precision, recall, F1-Score, etc. The LightGBM model was selected for its superior performance, achieving high accuracy and effectiveness. The optimal decision threshold for determining whether an application was malicious was 0.5. Following re-evaluation, the LightGBM model obtained accuracy and F1-Score values of 99.99% and 97.04%, respectively, highlighting the potential of using the proposed model for real-world financial fraud detection.

키워드

Androidfinancial fraudmalwarestatic analysismachine learningunbalanced datahyperparametersAPPS
제목
Advanced Financial Fraud Malware Detection Method in the Android Environment
저자
Shin, JaehoKim, DaehyunLee, Kyungho
DOI
10.3390/app15073905
발행일
2025-04-02
유형
Review
저널명
Applied Sciences (Switzerland)
15
7