Research Article | Open Access | Download PDF
Volume 74 | Issue 8 | Year 2026 | Article Id. IJETT-V74I8P118 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I8P118Android Malware Detection via Hybrid Static-Dynamic Analysis and Metaheuristic Feature Selection
Kshamta Chauhan, Ekta Gandotra
| Received | Revised | Accepted | Published |
|---|---|---|---|
| 03 Mar 2026 | 13 Jul 2026 | 22 Jul 2026 | 29 Aug 2026 |
Citation :
Kshamta Chauhan, Ekta Gandotra, "Android Malware Detection via Hybrid Static-Dynamic Analysis and Metaheuristic Feature Selection," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 8, pp. 259-277, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I8P118
Abstract
The rapid proliferation of Android applications has significantly increased the exposure of mobile devices to malware, necessitating accurate and robust detection mechanisms. While hybrid malware analysis that combines static and dynamic features has been widely adopted for Android malware detection, the effectiveness of such systems strongly depends on the selection of discriminative features. In this study, we present a systematic optimization and comparative evaluation of metaheuristic feature selection techniques within a hybrid malware analysis framework. Specifically, three metaheuristic feature selection algorithms, namely particle swarm optimization, genetic algorithm, and bat algorithm, are employed to identify the most relevant and discriminative set of features while minimizing redundancy and boosting the accuracy. An extensive set of experiments is carried out on a self-created dataset of Android applications to assess the effectiveness of the suggested approach. To further validate its effectiveness and generalizability, experiments are also performed on a benchmark dataset of Android malware. Five machine learning and three deep learning algorithms are trained with original features and the features selected using optimization algorithms for static, dynamic, and hybrid analysis approaches. Experimental results demonstrate that metaheuristic-based feature optimization consistently improves detection accuracy compared to non-optimized hybrid feature sets. According to experimental results, a gated recurrent unit constructed with features derived from the bat optimization approach for hybrid analysis gives the highest accuracy of 99.45%.
Keywords
Android malware, Hybrid malware analysis, Dynamic malware analysis, Machine Learning, Optimization algorithms, Static malware analysis.
References
[1] Statcounter Global
Stats, Mobile Operating System Market Share Worldwide, Statcounter Global
Stats, 2026. [Online]. Available:
https://gs.statcounter.com/os-market-share/mobile/worldwide
[2] Waleed Ali, “Hybrid Intelligent Android Malware Detection
using Evolving Support Vector Machine based on Genetic Algorithm and Particle
Swarm Optimization,” International Journal of Computer Science and Network
Security, vol. 19, no. 9, pp. 15-28, 2019.
[Google Scholar]
[3] Zhongru Ren et al., “End-To-End
Malware Detection for Android IoT Devices using Deep Learning,” Ad Hoc
Networks, vol. 101, 2020.
[CrossRef]
[Google Scholar] [Publisher Link]
[4] Mosaddek Hossain, Suzzana Rafi, and Shohrab
Hossain, “An Optimized Decision Tree based Android Malware Detection Approach
using Machine Learning,” Proceedings of the 7th International
Conference on Networking, Systems and Security, Association for Computing
Machinery, New York, NY, United States, pp. 115-125, 2020.
[CrossRef] [Google Scholar] [Publisher Link]
[5] Yanjie Zhao et al., “On
the Impact of Sample Duplication in Machine-Learning-based Android Malware
Detection,” ACM Transactions on Software Engineering and Methodology,
vol. 30, no. 3, pp. 1-38, 2021.
[CrossRef]
[Google Scholar] [Publisher Link]
[6] Meghna Dhalaria, and
Ekta Gandotra, “A Hybrid Approach for Android Malware Detection and Family
Classification,” International Journal of Interactive Multimedia and
Artificial Intelligence, vol. 6, no. 6, pp. 174-188, 2021.
[CrossRef]
[Google Scholar] [Publisher Link]
[7] Bradley Barth, New
Desert Scorpion Spyware Found in Malicious Chat App Aimed at Palestinians, SC
Media, 2018. [Online]. Available:
https://www.scmagazine.com/news/architecture/new-desert-scorpion-spyware-found-in-malicious-chat-app-aimed-at-palestinians
[8] Deepak Gupta, and
Rinkle Rani, “Big Data Framework for Zero-Day Malware Detection,” Cybernetics
and Systems, vol. 49, no. 2, pp. 103-121, 2018.
[CrossRef]
[Google Scholar] [Publisher Link]
[9] Deepak Gupta, and
Rinkle Rani, “Improving Malware Detection using Big Data and Ensemble
Learning,” Computers and Electrical Engineering, vol. 86, 2020.
[CrossRef] [Google Scholar] [Publisher Link]
[10] Hussein Al Bazar et al., “A Model for Android Platform
Malware Detection Utilizing Multiple Machine Learning Algorithms,” Informatica,
vol. 48, no. 17, pp. 95-108, 2024.
[CrossRef]
[Google Scholar] [Publisher Link]
[11] Mohd Faizal Ab Razak
et al., “Bio-inspired for Features Optimization and Malware Detection,” Arabian
Journal for Science and Engineering, vol. 43, no. 12, pp. 6963-6979, 2018.
[CrossRef]
[Google Scholar] [Publisher Link]
[12] Qi Li, and Xiaoyu Li, “Android Malware Detection based on
Static Analysis of Characteristic Tree,” 2015 International Conference on
Cyber-Enabled Distributed Computing and Knowledge Discovery, Xi'an, China,
pp. 84-91, 2015.
[CrossRef]
[Google Scholar] [Publisher Link]
[13] B. Suribabu Naick et
al., “Malware Detection in Android Mobile Devices by Applying Swarm
Intelligence Optimization and Machine Learning for API Calls,”
International Journal of Intelligent Systems
and Applications in Engineering, vol.
10, no. 3s, pp. 67-74, 2022.
[Google Scholar] [Publisher Link]
[14] Rajesh Kumar et al.,
“A Multimodal Malware Detection Technique for Android IoT Devices using Various
Features,” IEEE Access, vol. 7, pp. 64411-64430, 2019.
[CrossRef]
[Google Scholar] [Publisher Link]
[15] Iman Almomani, Aala Alkhayer, and Walid El-Shafai, “A
Crypto-Steganography Approach for Hiding Ransomware within HEVC Streams in
Android IoT Devices,” Sensors, vol. 22, no. 6, pp. 1-20, 2022.
[CrossRef]
[Google Scholar] [Publisher Link]
[16] P. Ravi Kiran Varma et al., “Bat Optimization Algorithm for
Wrapper-based Feature Selection and Performance Improvement of Android Malware
Detection,” IET Networks, vol. 10, no. 3, pp. 131-140, 2021.
[CrossRef]
[Google Scholar] [Publisher Link]
[17] Eslavath Ravi, and Mummadi Upendra Kumar, “A Comparative
Study on Machine Learning and Deep Learning Methods for Malware Detection,” Journal
of Theoretical and Applied Information Technology, vol. 100, no. 20, pp.
6117-
6129, 2022.
[Google Scholar] [Publisher Link]
[18] P.C. Senthil Mahesh, and S. Hemalatha, “An Efficient Android
Malware Detection using Adaptive Red Fox Optimization based CNN,” Wireless
Personal Communications, vol. 126, no. 1, pp. 679-700, 2022.
[CrossRef]
[Google Scholar] [Publisher Link]
[19] Lingru Cai, Yao Li, and Zhi Xiong, “JOWMDroid: Android
Malware Detection based on Feature Weighting with Joint Optimization of
Weight-Mapping and Classifier Parameters,” Computers and Security, vol.
100, 2021.
[CrossRef]
[Google Scholar] [Publisher Link]
[20] Salamatu Aliyu Sulaiman et al., “Android Malware
Classification using Whale Optimization Algorithm,” i-manager's Journal on Mobile
Applications and Technologies, vol. 5, no. 2, pp. 37-45, 2019.
[CrossRef]
[Google Scholar] [Publisher Link]
[21] Omar A. Alzubi et al., “An Efficient Malware Detection
Approach with Feature Weighting based on Harris Hawks Optimization,” Cluster
Computing, vol. 25, no. 4, pp. 2369-2387, 2022.
[CrossRef]
[Google Scholar] [Publisher Link]
[22] Santosh K. Smmarwar et al., “An Optimized and Efficient
Android Malware Detection Framework for Future Sustainable Computing,” Sustainable
Energy Technologies and Assessments, vol. 54, pp. 1-8, 2022.
[CrossRef]
[Google Scholar] [Publisher Link]
[23] Altyeb Taha, and Omar Barukab, “Android Malware
Classification using Optimized Ensemble Learning based on Genetic Algorithms,” Sustainability,
vol. 14, no. 21, pp. 1-11, 2022.
[CrossRef]
[Google Scholar] [Publisher Link]
[24] Vitor Monte Afonso et al., “Identifying Android Malware using
Dynamically Obtained Features,” Journal of Computer Virology and Hacking
Techniques, vol. 11, no. 1, pp. 9-17, 2015.
[CrossRef]
[Google Scholar] [Publisher Link]
[25] Vikas Sihag et al., “De-Lady: Deep Learning based Android
Malware Detection using Dynamic Features,” Journal of Internet Services and
Information Security, vol. 11, no. 2, pp. 34-45, 2021.
[CrossRef]
[Google Scholar] [Publisher Link]
[26] Fei Tong, and Zheng Yan, “A Hybrid Approach of Mobile Malware
Detection in Android,” Journal of Parallel and Distributed Computing,
vol. 103, pp. 22-31, 2017.
[CrossRef]
[Google Scholar] [Publisher Link]
[27] Altyeb Altaher, and Omar Mohammed Barukab, “Intelligent
Hybrid Approach for Android Malware Detection based on Permissions and API
Calls,” International Journal of Advanced Computer Science and Applications,
vol. 8, no. 6, pp. 60-67, 2017.
[CrossRef]
[Google Scholar] [Publisher Link]
[28] Abdullah Talha Kabakus, and Ibrahim Alper Dogru, “An In-Depth
Analysis of Android Malware using Hybrid Techniques,” Digital Investigation,
vol. 24, pp. 25-33, 2018.
[CrossRef]
[Google Scholar] [Publisher Link]
[29] Farhan Ullah, Gautam Srivastava, and Shamsher Ullah, “A
Malware Detection System using a Hybrid Approach of Multi-Heads Attention-based
Control Flow Traces and Image Visualization,” Journal of Cloud Computing,
vol. 11, no. 1, pp. 1-21, 2022.
[CrossRef]
[Google Scholar] [Publisher Link]
[30] Fatma Taher et al., “DroidDetectMW: A Hybrid Intelligent
Model for Android Malware Detection,” Applied Sciences, vol. 13, no. 13,
pp. 1-23, 2023.
[CrossRef]
[Google Scholar] [Publisher Link]
[31] VirusShare.com, 2023. [Online]. Available:
https://virusshare.com/
[32] APKPure APK for Android Download, 2023. [Online]. Available:
https://apkpure.com/apkpure/com.apkpure.aegon
[33] APKMirror - Free APK Downloads - Free and Safe Android APK
Downloads, 2023. [Online]. Available: https://www.apkmirror.com/
[34] Download Security Software for Windows, Mac, Android and iOS
| Avira Antivirus, 2023. [Online]. Available:
https://www.avira.com/?srsltid=AfmBOopZnoAzM0OmbWjT4SyY_Kk8iFWN-2etKe4G3EAPGMTYTtRI8QM6
[35] William Enck et al., “A Study of Android Application
Security,” 20th USENIX Security Symposium, vol. 2, no. 2,
2011.
[Google Scholar] [Publisher Link]
[36] Ronghua Tian et al., “An Automated Classification System
based on the Strings of Trojan and Virus Families,” 2009 4th
International Conference on Malicious and Unwanted Software, Montreal, QC,
Canada, pp. 23-30, 2009.
[CrossRef]
[Google Scholar] [Publisher Link]
[37] Nick Sayer, “Google Code Archive - Long-Term Storage for
Google Code Project Hosting,” Retrieved from the Internet, 2014.
[Google Scholar]
[38] Cuckoo Droid,
Installation-CuckooDroid v1.0 Book, Cuckoo Droid, 2023. [Online]. Available:
https://cuckoo-droid.readthedocs.io/en/latest/installation/
[39] Gerhard Venter, and Jaroslaw Sobieszczanski-Sobieski,
“Particle Swarm Optimization,” AIAA Journal,, vol. 41, no. 8, pp.
1583-1589, 2003.
[CrossRef] [Google Scholar] [Publisher Link]
[40] G. Venter, AIAA 2002-1235 Particle Swarm Optimization 43rd
AIAAIASMEIASCEIAHSIASC Structures, Structural Dynamics, Materials Conference
April 22-25, 2002, Denver,
Colorado, 2019. [Online]. Available:
https://www.cs.odu.edu/~mln/ltrs-pdfs/NASA-aiaa-2002-1235.pdf
[41] Sourabh Katoch, Sumit Singh Chauhan, and Vijay Kumar, “A
Review on Genetic Algorithm: Past, Present, and Future,” Multimedia Tools
and Applications, vol. 80, no. 5, pp. 8091-8126, 2021.
[CrossRef]
[Google Scholar] [Publisher Link]
[42] Xin‐She Yang, and Amir Hossein Gandomi, “Bat Algorithm: A
Novel Approach for Global Engineering Optimization,” Engineering
Computations, vol. 29, no. 5, pp. 464-483, 2012.
[CrossRef]
[Google Scholar] [Publisher Link]
[43] S.S. Keerthi, and E.G. Gilbert, “Convergence of a Generalized
SMO Algorithm for SVM Classifier Design,” Machine Learning, vol. 46, no.
1, pp. 351-360, 2002.
[CrossRef]
[Google Scholar] [Publisher Link]
[44] Andy Liaw, and Matthew Wiener, “Classification and Regression
by Randomforest,” R News, vol. 2, no. 3, pp. 18-22, 2002.
[Google Scholar]
[45] Laura S. Wood, “Introduction,” Seminars in Oncology
Nursing, vol. 28, no. 3, pp. 141-142, 2012.
[CrossRef]
[Publisher Link]
[46] J.R. Quinlan, “Learning Decision Tree Classifiers,” ACM
Computing Surveys, vol. 28, no. 1, pp. 71-72, 1996.
[CrossRef]
[Google Scholar] [Publisher Link]
[47] Pedro Domingos, and Michael Pazzani, “On the Optimality of
the Simple Bayesian Classifier Underzero-One Loss,” Machine Learning,
vol. 29, no. 2, pp. 103-130, 1997.
[CrossRef]
[Google Scholar] [Publisher Link]
[48] Felix A. Gers, Nicol
N. Schraudolph, and Jürgen Schmidhuber, “Learning Precise Timing with LSTM
Recurrent Networks,” Journal of Machine Learning Research, vol. 3, pp.
115-143, 2002.
[Google Scholar] [Publisher Link]
[49] Alex Sherstinsky, “Fundamentals of Recurrent Neural Network
(RNN) and Long Short-Term Memory (LSTM) Network,” Physica D: Nonlinear
Phenomena, vol. 404, pp. 1-28, 2020.
[CrossRef]
[Google Scholar] [Publisher Link]
[50] Farhad Mortezapour Shiri et al., “A Comprehensive Overview
and Comparative Analysis on Deep Learning Models: CNN, RNN, LSTM, GRU,” arXiv
preprint, pp. 1-62, 2024.
[CrossRef]
[Google Scholar] [Publisher Link]
[51] Scikit-Learn, Scikit-Learn: Machine Learning in Python -
scikit-learn 1.2.2 Documentation, 2023. [Online]. Available: https://scikit-learn.org/stable/whats_new/v1.2.html
[52] Daniel Arp et al.,
“Drebin: Effective and Explainable Detection of Android Malware in your
Pocket,” Network and Distributed System Security Symposium, vol. 14, no.
1, pp. 1-15, 2014.
[Google Scholar] [Publisher Link]