DriftDroid: temporal behavioral drift analysis for android malware detection
Android malware detectors often perform well under random or temporally mixed evaluation, yet deployed systems classify applications appearing after training. DriftDroid is a temporal behavioral drift measurement protocol for dynamic Android malware detection, not a new detector architecture: it measures how historical runtime-behavior evidence transfers to applications and explains performance decay. KronoDroid supplies 14,348 tabular behavioral profiles and 10,000 event-sequence traces as the historical source domain; a balanced 6,000-sample AndroZoo hold-out from 2024 onward is reserved for testing. Applications are represented with 62 train-domain event tags and 165 aggregate features, evaluated across sequence and tabular probes without target-domain refitting. Although KronoDroid validation scores are high, temporal testing reveals degradation: the best sequence model reaches 0.7988 macro-F1 on AndroZoo, whereas the best tabular model reaches 0.7010. The dominant tabular failure mode is benign-side drift, as recent benign applications increasingly exhibit network, file, cryptographic, SDK, and service behaviors historically correlated with malware. Thus, Android malware evaluation requires temporal hold-outs and representation-aware drift analysis. As secondary operational evidence, tabular tree ensembles recover with 600 labeled future-domain samples, closing 72–80% of the temporal performance gap, whereas sequence models provide stronger unadapted detection, while multi-seed fine-tuning with a separate target-domain validation subset improves both sequence probes and reveals a non-monotonic adaptation response with greater seed/split sensitivity for BiLSTM.
Authors
- A. H. Abdul Hafez (ORCID: https://orcid.org/0000-0002-1908-5521)
- Halit Bakır (ORCID: https://orcid.org/0000-0003-3327-2822)
- Eid Mohammad Albalawi (ORCID: https://orcid.org/0000-0003-4872-4932)
- Muhammet Tan (ORCID: https://orcid.org/0009-0004-9430-372X)
Institutions
- Sivas Bilim ve Teknoloji Üniversitesi (TR)
- King Faisal University (SA)
Publication Details
- Journal
- Scientific Reports
- Published
- 2026-10-07
- DOI
- https://doi.org/10.1038/s41598-026-73718-x
- Primary Topic
- Advanced Malware Detection Techniques
- Type
- article
- Field-Weighted Citation Impact
- 0.00