HFS-SVE: A Hybrid Feature Selection and Soft Voting Ensemble for Android Malware Detection
Android malware continues to evolve in complexity, creating challenges for detection systems that must distinguish malicious applications from increasingly heterogeneous benign applications. Although machine learning provides effective mechanisms for learning malware characteristics, the high dimensionality of Android malware datasets can introduce redundant and weakly informative features and increase computational requirements. To address this problem, this paper proposes a Hybrid Feature Selection and Soft-Voting Ensemble (HFS-SVE) framework that integrates complementary feature-selection and ensemble-learning strategies. The proposed framework sequentially applies Random Forest (RF) feature importance, Chi-square-based SelectKBest, correlation filtering, and L1 regularisation, reducing the original 489-feature representation to 13 selected features. These features are subsequently classified using RF, XGBoost, and LightGBM, whose probability outputs are combined through soft voting. Experimental results on the KronoDroid dataset demonstrate that the proposed HFS-SVE achieves 99.41% accuracy, 99.52% precision, 99.30% recall, 99.40% F1-score, and 99.41% ROC-AUC. The proposed framework also records the lowest measured detection time among the evaluated feature-selection strategies. Cross-dataset evaluation on Malgenome, TUANDROMD, and Drebin achieves accuracy above 98% on each dataset. The findings demonstrate that the proposed HFS-SVE can combine substantial feature-space reduction with strong Android malware detection performance, while the cross-dataset results highlight the importance of dataset variation and feature provenance when assessing generalisation.
Authors
- Hany F. Atlam (ORCID: https://orcid.org/0000-0003-4142-6377)
- Samyak M. Jeevane
Institutions
- University of Warwick (GB)
Publication Details
- Journal
- Future Internet
- Published
- 2026-09-20
- DOI
- https://doi.org/10.3390/fi18090495
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00