International Journal of Engineering
Trends and Technology

Research Article | Open Access | Download PDF
Volume 74 | Issue 8 | Year 2026 | Article Id. IJETT-V74I8P118 | DOI : https://doi.org/10.14445/22315381/IJETT-V74I8P118

Android Malware Detection via Hybrid Static-Dynamic Analysis and Metaheuristic Feature Selection


Kshamta Chauhan, Ekta Gandotra

Received Revised Accepted Published
03 Mar 2026 13 Jul 2026 22 Jul 2026 29 Aug 2026

Citation :

Kshamta Chauhan, Ekta Gandotra, "Android Malware Detection via Hybrid Static-Dynamic Analysis and Metaheuristic Feature Selection," International Journal of Engineering Trends and Technology (IJETT), vol. 74, no. 8, pp. 259-277, 2026. Crossref, https://doi.org/10.14445/22315381/IJETT-V74I8P118

Abstract

The rapid proliferation of Android applications has significantly increased the exposure of mobile devices to malware, necessitating accurate and robust detection mechanisms. While hybrid malware analysis that combines static and dynamic features has been widely adopted for Android malware detection, the effectiveness of such systems strongly depends on the selection of discriminative features. In this study, we present a systematic optimization and comparative evaluation of metaheuristic feature selection techniques within a hybrid malware analysis framework. Specifically, three metaheuristic feature selection algorithms, namely particle swarm optimization, genetic algorithm, and bat algorithm, are employed to identify the most relevant and discriminative set of features while minimizing redundancy and boosting the accuracy. An extensive set of experiments is carried out on a self-created dataset of Android applications to assess the effectiveness of the suggested approach. To further validate its effectiveness and generalizability, experiments are also performed on a benchmark dataset of Android malware. Five machine learning and three deep learning algorithms are trained with original features and the features selected using optimization algorithms for static, dynamic, and hybrid analysis approaches. Experimental results demonstrate that metaheuristic-based feature optimization consistently improves detection accuracy compared to non-optimized hybrid feature sets. According to experimental results, a gated recurrent unit constructed with features derived from the bat optimization approach for hybrid analysis gives the highest accuracy of 99.45%.

Keywords

Android malware, Hybrid malware analysis, Dynamic malware analysis, Machine Learning, Optimization algorithms, Static malware analysis.

References

[1] Statcounter Global Stats, Mobile Operating System Market Share Worldwide, Statcounter Global Stats, 2026. [Online]. Available: https://gs.statcounter.com/os-market-share/mobile/worldwide

[2] Waleed Ali, “Hybrid Intelligent Android Malware Detection using Evolving Support Vector Machine based on Genetic Algorithm and Particle Swarm Optimization,” International Journal of Computer Science and Network Security, vol. 19, no. 9, pp. 15-28, 2019.
[
Google Scholar]

[3] Zhongru Ren et al., “End-To-End Malware Detection for Android IoT Devices using Deep Learning,” Ad Hoc Networks, vol. 101, 2020.
[CrossRef] [Google Scholar] [Publisher Link]

[4] Mosaddek Hossain, Suzzana Rafi, and Shohrab Hossain, “An Optimized Decision Tree based Android Malware Detection Approach using Machine Learning,” Proceedings of the 7th International Conference on Networking, Systems and Security, Association for Computing Machinery, New York, NY, United States, pp. 115-125, 2020.
[
CrossRef] [Google Scholar] [Publisher Link]

[5] Yanjie Zhao et al., “On the Impact of Sample Duplication in Machine-Learning-based Android Malware Detection,” ACM Transactions on Software Engineering and Methodology, vol. 30, no. 3, pp. 1-38, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[6] Meghna Dhalaria, and Ekta Gandotra, “A Hybrid Approach for Android Malware Detection and Family Classification,” International Journal of Interactive Multimedia and Artificial Intelligence, vol. 6, no. 6, pp. 174-188, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[7] Bradley Barth, New Desert Scorpion Spyware Found in Malicious Chat App Aimed at Palestinians, SC Media, 2018. [Online]. Available: https://www.scmagazine.com/news/architecture/new-desert-scorpion-spyware-found-in-malicious-chat-app-aimed-at-palestinians

[8] Deepak Gupta, and Rinkle Rani, “Big Data Framework for Zero-Day Malware Detection,” Cybernetics and Systems, vol. 49, no. 2, pp. 103-121, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[9] Deepak Gupta, and Rinkle Rani, “Improving Malware Detection using Big Data and Ensemble Learning,” Computers and Electrical Engineering, vol. 86, 2020.
[CrossRef] [Google Scholar] [Publisher Link]

[10] Hussein Al Bazar et al., “A Model for Android Platform Malware Detection Utilizing Multiple Machine Learning Algorithms,” Informatica, vol. 48, no. 17, pp. 95-108, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[11]  Mohd Faizal Ab Razak et al., “Bio-inspired for Features Optimization and Malware Detection,” Arabian Journal for Science and Engineering, vol. 43, no. 12, pp. 6963-6979, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[12] Qi Li, and Xiaoyu Li, “Android Malware Detection based on Static Analysis of Characteristic Tree,” 2015 International Conference on Cyber-Enabled Distributed Computing and Knowledge Discovery, Xi'an, China, pp. 84-91, 2015.
[CrossRef] [Google Scholar] [Publisher Link]

[13]  B. Suribabu Naick et al., “Malware Detection in Android Mobile Devices by Applying Swarm Intelligence Optimization and Machine Learning for API Calls,” International Journal of Intelligent Systems and Applications in Engineering, vol. 10, no. 3s, pp. 67-74, 2022.
[
Google Scholar] [Publisher Link]

[14]  Rajesh Kumar et al., “A Multimodal Malware Detection Technique for Android IoT Devices using Various Features,” IEEE Access, vol. 7, pp. 64411-64430, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[15] Iman Almomani, Aala Alkhayer, and Walid El-Shafai, “A Crypto-Steganography Approach for Hiding Ransomware within HEVC Streams in Android IoT Devices,” Sensors, vol. 22, no. 6, pp. 1-20, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[16] P. Ravi Kiran Varma et al., “Bat Optimization Algorithm for Wrapper-based Feature Selection and Performance Improvement of Android Malware Detection,” IET Networks, vol. 10, no. 3, pp. 131-140, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[17] Eslavath Ravi, and Mummadi Upendra Kumar, “A Comparative Study on Machine Learning and Deep Learning Methods for Malware Detection,” Journal of Theoretical and Applied Information Technology, vol. 100, no. 20, pp. 6117- 6129, 2022.
[
Google Scholar] [Publisher Link]

[18] P.C. Senthil Mahesh, and S. Hemalatha, “An Efficient Android Malware Detection using Adaptive Red Fox Optimization based CNN,” Wireless Personal Communications, vol. 126, no. 1, pp. 679-700, 2022.
[CrossRef] [Google Scholar] [Publisher Link

[19] Lingru Cai, Yao Li, and Zhi Xiong, “JOWMDroid: Android Malware Detection based on Feature Weighting with Joint Optimization of Weight-Mapping and Classifier Parameters,” Computers and Security, vol. 100, 2021.
[CrossRef] [Google Scholar] [Publisher Link

[20] Salamatu Aliyu Sulaiman et al., “Android Malware Classification using Whale Optimization Algorithm,” i-manager's Journal on Mobile Applications and Technologies, vol. 5, no. 2, pp. 37-45, 2019.
[CrossRef] [Google Scholar] [Publisher Link]

[21] Omar A. Alzubi et al., “An Efficient Malware Detection Approach with Feature Weighting based on Harris Hawks Optimization,” Cluster Computing, vol. 25, no. 4, pp. 2369-2387, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[22] Santosh K. Smmarwar et al., “An Optimized and Efficient Android Malware Detection Framework for Future Sustainable Computing,” Sustainable Energy Technologies and Assessments, vol. 54, pp. 1-8, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[23] Altyeb Taha, and Omar Barukab, “Android Malware Classification using Optimized Ensemble Learning based on Genetic Algorithms,” Sustainability, vol. 14, no. 21, pp. 1-11, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[24] Vitor Monte Afonso et al., “Identifying Android Malware using Dynamically Obtained Features,” Journal of Computer Virology and Hacking Techniques, vol. 11, no. 1, pp. 9-17, 2015.
[CrossRef] [Google Scholar] [Publisher Link]

[25] Vikas Sihag et al., “De-Lady: Deep Learning based Android Malware Detection using Dynamic Features,” Journal of Internet Services and Information Security, vol. 11, no. 2, pp. 34-45, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[26] Fei Tong, and Zheng Yan, “A Hybrid Approach of Mobile Malware Detection in Android,” Journal of Parallel and Distributed Computing, vol. 103, pp. 22-31, 2017.
[CrossRef] [Google Scholar] [Publisher Link]

[27] Altyeb Altaher, and Omar Mohammed Barukab, “Intelligent Hybrid Approach for Android Malware Detection based on Permissions and API Calls,” International Journal of Advanced Computer Science and Applications, vol. 8, no. 6, pp. 60-67, 2017.
[CrossRef] [Google Scholar] [Publisher Link]

[28] Abdullah Talha Kabakus, and Ibrahim Alper Dogru, “An In-Depth Analysis of Android Malware using Hybrid Techniques,” Digital Investigation, vol. 24, pp. 25-33, 2018.
[CrossRef] [Google Scholar] [Publisher Link]

[29] Farhan Ullah, Gautam Srivastava, and Shamsher Ullah, “A Malware Detection System using a Hybrid Approach of Multi-Heads Attention-based Control Flow Traces and Image Visualization,” Journal of Cloud Computing, vol. 11, no. 1, pp. 1-21, 2022.
[CrossRef] [Google Scholar] [Publisher Link]

[30] Fatma Taher et al., “DroidDetectMW: A Hybrid Intelligent Model for Android Malware Detection,” Applied Sciences, vol. 13, no. 13, pp. 1-23, 2023.
[CrossRef] [Google Scholar] [Publisher Link]

[31] VirusShare.com, 2023. [Online]. Available: https://virusshare.com/

[32] APKPure APK for Android Download, 2023. [Online]. Available: https://apkpure.com/apkpure/com.apkpure.aegon

[33] APKMirror - Free APK Downloads - Free and Safe Android APK Downloads, 2023. [Online]. Available: https://www.apkmirror.com/

[34] Download Security Software for Windows, Mac, Android and iOS | Avira Antivirus, 2023. [Online]. Available: https://www.avira.com/?srsltid=AfmBOopZnoAzM0OmbWjT4SyY_Kk8iFWN-2etKe4G3EAPGMTYTtRI8QM6

[35] William Enck et al., “A Study of Android Application Security,” 20th USENIX Security Symposium, vol. 2, no. 2, 2011.
[Google Scholar] [Publisher Link]

[36] Ronghua Tian et al., “An Automated Classification System based on the Strings of Trojan and Virus Families,” 2009 4th International Conference on Malicious and Unwanted Software, Montreal, QC, Canada, pp. 23-30, 2009.
[CrossRef] [Google Scholar] [Publisher Link]

[37] Nick Sayer, “Google Code Archive - Long-Term Storage for Google Code Project Hosting,” Retrieved from the Internet, 2014.
[Google Scholar]

[38] Cuckoo Droid, Installation-CuckooDroid v1.0 Book, Cuckoo Droid, 2023. [Online]. Available: https://cuckoo-droid.readthedocs.io/en/latest/installation/

[39] Gerhard Venter, and Jaroslaw Sobieszczanski-Sobieski, “Particle Swarm Optimization,” AIAA Journal,, vol. 41, no. 8, pp. 1583-1589, 2003.
[CrossRef] [Google Scholar] [Publisher Link]

[40] G. Venter, AIAA 2002-1235 Particle Swarm Optimization 43rd AIAAIASMEIASCEIAHSIASC Structures, Structural Dynamics, Materials Conference April 22-25, 2002, Denver, Colorado, 2019. [Online]. Available:  https://www.cs.odu.edu/~mln/ltrs-pdfs/NASA-aiaa-2002-1235.pdf

[41] Sourabh Katoch, Sumit Singh Chauhan, and Vijay Kumar, “A Review on Genetic Algorithm: Past, Present, and Future,” Multimedia Tools and Applications, vol. 80, no. 5, pp. 8091-8126, 2021.
[CrossRef] [Google Scholar] [Publisher Link]

[42] Xin‐She Yang, and Amir Hossein Gandomi, “Bat Algorithm: A Novel Approach for Global Engineering Optimization,” Engineering Computations, vol. 29, no. 5, pp. 464-483, 2012.
[CrossRef] [Google Scholar] [Publisher Link]

[43] S.S. Keerthi, and E.G. Gilbert, “Convergence of a Generalized SMO Algorithm for SVM Classifier Design,” Machine Learning, vol. 46, no. 1, pp. 351-360, 2002.
[CrossRef] [Google Scholar] [Publisher Link]

[44] Andy Liaw, and Matthew Wiener, “Classification and Regression by Randomforest,” R News, vol. 2, no. 3, pp. 18-22, 2002.
[Google Scholar]

[45] Laura S. Wood, “Introduction,” Seminars in Oncology Nursing, vol. 28, no. 3, pp. 141-142, 2012.
[CrossRef] [Publisher Link]

[46] J.R. Quinlan, “Learning Decision Tree Classifiers,” ACM Computing Surveys, vol. 28, no. 1, pp. 71-72, 1996.
[CrossRef] [Google Scholar] [Publisher Link]

[47] Pedro Domingos, and Michael Pazzani, “On the Optimality of the Simple Bayesian Classifier Underzero-One Loss,” Machine Learning, vol. 29, no. 2, pp. 103-130, 1997.
[CrossRef] [Google Scholar] [Publisher Link]

[48] Felix A. Gers, Nicol N. Schraudolph, and Jürgen Schmidhuber, “Learning Precise Timing with LSTM Recurrent Networks,” Journal of Machine Learning Research, vol. 3, pp. 115-143, 2002.
[Google Scholar] [Publisher Link]

[49] Alex Sherstinsky, “Fundamentals of Recurrent Neural Network (RNN) and Long Short-Term Memory (LSTM) Network,” Physica D: Nonlinear Phenomena, vol. 404, pp. 1-28, 2020.
[CrossRef] [Google Scholar] [Publisher Link

[50] Farhad Mortezapour Shiri et al., “A Comprehensive Overview and Comparative Analysis on Deep Learning Models: CNN, RNN, LSTM, GRU,” arXiv preprint, pp. 1-62, 2024.
[CrossRef] [Google Scholar] [Publisher Link]

[51] Scikit-Learn, Scikit-Learn: Machine Learning in Python - scikit-learn 1.2.2 Documentation, 2023. [Online]. Available: https://scikit-learn.org/stable/whats_new/v1.2.html

[52] Daniel Arp et al., “Drebin: Effective and Explainable Detection of Android Malware in your Pocket,” Network and Distributed System Security Symposium, vol. 14, no. 1, pp. 1-15, 2014.
[Google Scholar] [Publisher Link]