McNdroid: A Longitudinal Multimodal Benchmark for Robust Drift Detection in Android Malware

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Kamol, Md Mahmuduzzaman, Lopez, Jesus, Nowmi, Saeefa Rubaiyet, Rivas, Emilia, Haque, Md Ahsanul, Raff, Edward, Piplai, Aritran, Rahman, Mohammad Saidur
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917470923653120
author Kamol, Md Mahmuduzzaman
Lopez, Jesus
Nowmi, Saeefa Rubaiyet
Rivas, Emilia
Haque, Md Ahsanul
Raff, Edward
Piplai, Aritran
Rahman, Mohammad Saidur
author_facet Kamol, Md Mahmuduzzaman
Lopez, Jesus
Nowmi, Saeefa Rubaiyet
Rivas, Emilia
Haque, Md Ahsanul
Raff, Edward
Piplai, Aritran
Rahman, Mohammad Saidur
contents Machine learning (ML) in real-world systems must contend with concept drift, adversarial actors, and a spectrum of potential features with varying costs and benefits. Malware naturally exhibits all of these complexities, but for the same reason, it is challenging to curate and organize data to study these factors. We present McNdroid, to our knowledge the largest longitudinal multimodal Android malware benchmark for malware detection and drift analysis. McNdroid spans 2013--2025, excluding 2015, and represents each application with three aligned modalities--static features from manifests and smali code, dynamic behavioral features from sandbox execution, and graph-based features from function-call graphs. Using temporally separated splits, we evaluate standard ML and deep-learning detectors across increasing train--test time gaps. Results show clear temporal degradation, while multimodal fusion outperforms the best single modality across long-term temporal gaps. Cross-modal agreement also declines over time, suggesting that drift affects both individual feature spaces and the consistency among modalities. We further analyze modality-specific drift, malware-family evolution, and temporal changes in model explanations. We publicly release McNdroid, benchmark splits, and code to support reproducible research on temporal generalization and robust multimodal learning in security-critical, non-stationary settings.
format Preprint
id arxiv_https___arxiv_org_abs_2605_06894
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle McNdroid: A Longitudinal Multimodal Benchmark for Robust Drift Detection in Android Malware
Kamol, Md Mahmuduzzaman
Lopez, Jesus
Nowmi, Saeefa Rubaiyet
Rivas, Emilia
Haque, Md Ahsanul
Raff, Edward
Piplai, Aritran
Rahman, Mohammad Saidur
Cryptography and Security
Machine Learning
Machine learning (ML) in real-world systems must contend with concept drift, adversarial actors, and a spectrum of potential features with varying costs and benefits. Malware naturally exhibits all of these complexities, but for the same reason, it is challenging to curate and organize data to study these factors. We present McNdroid, to our knowledge the largest longitudinal multimodal Android malware benchmark for malware detection and drift analysis. McNdroid spans 2013--2025, excluding 2015, and represents each application with three aligned modalities--static features from manifests and smali code, dynamic behavioral features from sandbox execution, and graph-based features from function-call graphs. Using temporally separated splits, we evaluate standard ML and deep-learning detectors across increasing train--test time gaps. Results show clear temporal degradation, while multimodal fusion outperforms the best single modality across long-term temporal gaps. Cross-modal agreement also declines over time, suggesting that drift affects both individual feature spaces and the consistency among modalities. We further analyze modality-specific drift, malware-family evolution, and temporal changes in model explanations. We publicly release McNdroid, benchmark splits, and code to support reproducible research on temporal generalization and robust multimodal learning in security-critical, non-stationary settings.
title McNdroid: A Longitudinal Multimodal Benchmark for Robust Drift Detection in Android Malware
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2605.06894