Interpretable by Design: MH-AutoML for Transparent and Efficient Android Malware Detection without Compromising Performance

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Assolin, Joner, Canto, Gabriel, Kreutz, Diego, Feitosa, Eduardo, Bragança, Hendrio, Nogueira, Angelo, Rocha, Vanderson
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918075193884672
author Assolin, Joner
Canto, Gabriel
Kreutz, Diego
Feitosa, Eduardo
Bragança, Hendrio
Nogueira, Angelo
Rocha, Vanderson
author_facet Assolin, Joner
Canto, Gabriel
Kreutz, Diego
Feitosa, Eduardo
Bragança, Hendrio
Nogueira, Angelo
Rocha, Vanderson
contents Malware detection in Android systems requires both cybersecurity expertise and machine learning (ML) techniques. Automated Machine Learning (AutoML) has emerged as an approach to simplify ML development by reducing the need for specialized knowledge. However, current AutoML solutions typically operate as black-box systems with limited transparency, interpretability, and experiment traceability. To address these limitations, we present MH-AutoML, a domain-specific framework for Android malware detection. MH-AutoML automates the entire ML pipeline, including data preprocessing, feature engineering, algorithm selection, and hyperparameter tuning. The framework incorporates capabilities for interpretability, debugging, and experiment tracking that are often missing in general-purpose solutions. In this study, we compare MH-AutoML against seven established AutoML frameworks: Auto-Sklearn, AutoGluon, TPOT, HyperGBM, Auto-PyTorch, LightAutoML, and MLJAR. Results show that MH-AutoML achieves better recall rates while providing more transparency and control. The framework maintains computational efficiency comparable to other solutions, making it suitable for cybersecurity applications where both performance and explainability matter.
format Preprint
id arxiv_https___arxiv_org_abs_2506_23314
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Interpretable by Design: MH-AutoML for Transparent and Efficient Android Malware Detection without Compromising Performance
Assolin, Joner
Canto, Gabriel
Kreutz, Diego
Feitosa, Eduardo
Bragança, Hendrio
Nogueira, Angelo
Rocha, Vanderson
Cryptography and Security
Artificial Intelligence
68T99
I.2
Malware detection in Android systems requires both cybersecurity expertise and machine learning (ML) techniques. Automated Machine Learning (AutoML) has emerged as an approach to simplify ML development by reducing the need for specialized knowledge. However, current AutoML solutions typically operate as black-box systems with limited transparency, interpretability, and experiment traceability. To address these limitations, we present MH-AutoML, a domain-specific framework for Android malware detection. MH-AutoML automates the entire ML pipeline, including data preprocessing, feature engineering, algorithm selection, and hyperparameter tuning. The framework incorporates capabilities for interpretability, debugging, and experiment tracking that are often missing in general-purpose solutions. In this study, we compare MH-AutoML against seven established AutoML frameworks: Auto-Sklearn, AutoGluon, TPOT, HyperGBM, Auto-PyTorch, LightAutoML, and MLJAR. Results show that MH-AutoML achieves better recall rates while providing more transparency and control. The framework maintains computational efficiency comparable to other solutions, making it suitable for cybersecurity applications where both performance and explainability matter.
title Interpretable by Design: MH-AutoML for Transparent and Efficient Android Malware Detection without Compromising Performance
topic Cryptography and Security
Artificial Intelligence
68T99
I.2
url https://arxiv.org/abs/2506.23314