DriftDroid: temporal behavioral drift analysis for android malware detection

Android malware detectors often perform well under random or temporally mixed evaluation, yet deployed systems classify applications appearing after training. DriftDroid is a temporal behavioral drift measurement protocol for dynamic Android malware detection, not a new detector architecture: it measures how historical runtime-behavior evidence transfers to applications and explains performance decay. KronoDroid supplies 14,348 tabular behavioral profiles and 10,000 event-sequence traces as the historical source domain; a balanced 6,000-sample AndroZoo hold-out from 2024 onward is reserved for testing. Applications are represented with 62 train-domain event tags and 165 aggregate features, evaluated across sequence and tabular probes without target-domain refitting. Although KronoDroid validation scores are high, temporal testing reveals degradation: the best sequence model reaches 0.7988 macro-F1 on AndroZoo, whereas the best tabular model reaches 0.7010. The dominant tabular failure mode is benign-side drift, as recent benign applications increasingly exhibit network, file, cryptographic, SDK, and service behaviors historically correlated with malware. Thus, Android malware evaluation requires temporal hold-outs and representation-aware drift analysis. As secondary operational evidence, tabular tree ensembles recover with 600 labeled future-domain samples, closing 72–80% of the temporal performance gap, whereas sequence models provide stronger unadapted detection, while multi-seed fine-tuning with a separate target-domain validation subset improves both sequence probes and reveals a non-monotonic adaptation response with greater seed/split sensitivity for BiLSTM.

Authors

Institutions

Publication Details

Journal
Scientific Reports
Published
2026-10-07
DOI
https://doi.org/10.1038/s41598-026-73718-x
Primary Topic
Advanced Malware Detection Techniques
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
article

DriftDroid: temporal behavioral drift analysis for android malware detection

A. H. Abdul Hafez, Halit Bakır, Eid Mohammad Albalawi, Muhammet Tan
Scientific Reports
Advanced Malware Detection Techniques
article

DriftDroid: temporal behavioral drift analysis for android malware detection

A. H. Abdul Hafez, Halit Bakır, Eid Mohammad Albalawi, Muhammet Tan
article en

Abstract

Android malware detectors often perform well under random or temporally mixed evaluation, yet deployed systems classify applications appearing after training. DriftDroid is a temporal behavioral drift measurement protocol for dynamic Android malware detection, not a new detector architecture: it measures how historical runtime-behavior evidence transfers to applications and explains performance decay. KronoDroid supplies 14,348 tabular behavioral profiles and 10,000 event-sequence traces as the historical source domain; a balanced 6,000-sample AndroZoo hold-out from 2024 onward is reserved for testing. Applications are represented with 62 train-domain event tags and 165 aggregate features, evaluated across sequence and tabular probes without target-domain refitting. Although KronoDroid validation scores are high, temporal testing reveals degradation: the best sequence model reaches 0.7988 macro-F1 on AndroZoo, whereas the best tabular model reaches 0.7010. The dominant tabular failure mode is benign-side drift, as recent benign applications increasingly exhibit network, file, cryptographic, SDK, and service behaviors historically correlated with malware. Thus, Android malware evaluation requires temporal hold-outs and representation-aware drift analysis. As secondary operational evidence, tabular tree ensembles recover with 600 labeled future-domain samples, closing 72–80% of the temporal performance gap, whereas sequence models provide stronger unadapted detection, while multi-seed fine-tuning with a separate target-domain validation subset improves both sequence probes and reveals a non-monotonic adaptation response with greater seed/split sensitivity for BiLSTM.

Scientific Reports
Sivas Bilim ve Teknoloji Üniversitesi (TR), King Faisal University (SA)
Openalex Percentile: Top 11%
Advanced Malware Detection Techniques
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.

DriftDroid: temporal behavioral drift analysis for android malware detection — A. H. Abdul Hafez, Halit Bakır, et al. · Scientific Reports (2026) | TGRS Research Map | TGRS