MalFlows: Context-aware Fusion of Heterogeneous Flow Semantics for Android Malware Detection

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Meng, Zhaoyi, Xu, Fenglei, Zhao, Wenxiang, Wang, Wansen, Huang, Wenchao, Cui, Jie, Zhong, Hong, Xiong, Yan
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914201237192704
author Meng, Zhaoyi
Xu, Fenglei
Zhao, Wenxiang
Wang, Wansen
Huang, Wenchao
Cui, Jie
Zhong, Hong
Xiong, Yan
author_facet Meng, Zhaoyi
Xu, Fenglei
Zhao, Wenxiang
Wang, Wansen
Huang, Wenchao
Cui, Jie
Zhong, Hong
Xiong, Yan
contents Static analysis, a fundamental technique in Android app examination, enables the extraction of control flows, data flows, and inter-component communications (ICCs), all of which are essential for malware detection. However, existing methods struggle to leverage the semantic complementarity across different types of flows for representing program behaviors, and their context-unaware nature further hinders the accuracy of cross-flow semantic integration. We propose and implement MalFlows, a novel technique that achieves context-aware fusion of heterogeneous flow semantics for Android malware detection. Our goal is to leverage complementary strengths of the three types of flow-related information for precise app profiling. We adopt a heterogeneous information network (HIN) to model the rich semantics across these program flows. We further propose flow2vec, a context-aware HIN embedding technique that distinguishes the semantics of HIN entities as needed based on contextual constraints across different flows and learns accurate app representations through the joint use of multiple meta-paths. The representations are finally fed into a channel-attention-based deep neural network for malware classification. To the best of our knowledge, this is the first study to comprehensively aggregate the strengths of diverse flow-related information for assessing maliciousness within apps. We evaluate MalFlows on a large-scale dataset comprising over 20 million flow instances extracted from more than 31,000 real-world apps. Experimental results demonstrate that MalFlows outperforms representative baselines in Android malware detection, and meanwhile, validate the effectiveness of flow2vec in accurately learning app representations from the HIN constructed over the heterogeneous flows.
format Preprint
id arxiv_https___arxiv_org_abs_2508_03588
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle MalFlows: Context-aware Fusion of Heterogeneous Flow Semantics for Android Malware Detection
Meng, Zhaoyi
Xu, Fenglei
Zhao, Wenxiang
Wang, Wansen
Huang, Wenchao
Cui, Jie
Zhong, Hong
Xiong, Yan
Cryptography and Security
Software Engineering
Static analysis, a fundamental technique in Android app examination, enables the extraction of control flows, data flows, and inter-component communications (ICCs), all of which are essential for malware detection. However, existing methods struggle to leverage the semantic complementarity across different types of flows for representing program behaviors, and their context-unaware nature further hinders the accuracy of cross-flow semantic integration. We propose and implement MalFlows, a novel technique that achieves context-aware fusion of heterogeneous flow semantics for Android malware detection. Our goal is to leverage complementary strengths of the three types of flow-related information for precise app profiling. We adopt a heterogeneous information network (HIN) to model the rich semantics across these program flows. We further propose flow2vec, a context-aware HIN embedding technique that distinguishes the semantics of HIN entities as needed based on contextual constraints across different flows and learns accurate app representations through the joint use of multiple meta-paths. The representations are finally fed into a channel-attention-based deep neural network for malware classification. To the best of our knowledge, this is the first study to comprehensively aggregate the strengths of diverse flow-related information for assessing maliciousness within apps. We evaluate MalFlows on a large-scale dataset comprising over 20 million flow instances extracted from more than 31,000 real-world apps. Experimental results demonstrate that MalFlows outperforms representative baselines in Android malware detection, and meanwhile, validate the effectiveness of flow2vec in accurately learning app representations from the HIN constructed over the heterogeneous flows.
title MalFlows: Context-aware Fusion of Heterogeneous Flow Semantics for Android Malware Detection
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2508.03588