International Journal of Computer
Trends and Technology

Research Article | Open Access | Download PDF
Volume 74 | Issue 9 | Year 2026 | Article Id. IJCTT-V74I9P101 | DOI : https://doi.org/10.14445/22312803/IJCTT-V74I9P101

A Critical Review of Android Malware Detection Techniques (2014–2026): Evaluating Static, Dynamic, Hybrid, and Deep Learning Approaches


Rishish Jain, D. A. Mehta

Received Revised Accepted Published
09 Jul 2026 17 Aug 2026 02 Sep 2026 18 Sep 2026

Citation :

Rishish Jain, D. A. Mehta, "A Critical Review of Android Malware Detection Techniques (2014–2026): Evaluating Static, Dynamic, Hybrid, and Deep Learning Approaches," International Journal of Computer Trends and Technology (IJCTT), vol. 74, no. 9, pp. 1-15, 2026. Crossref, https://doi.org/10.14445/22312803/IJCTT-V74I9P101

Abstract

Over the past decade, Android malware detection has advanced a great deal, yet a persistent gap remains between the accuracy figures reported on benchmarks and what these systems actually achieve once deployed. This paper reviews thirty-one Android malware detection systems and reputation-intelligence platforms published between 2014 and 2026, spanning static, dynamic, hybrid, and deep-learning approaches, and compares them against six practical criteria: detection accuracy, obfuscation resilience, computational overhead, scalability, temporal robustness, and practical deployability. Benchmark accuracy rose from around 94% for Drebin to 98.1% for SeGDroid over this period, but Pendlebury et al.’s TESSERACT framework shows that a large share of these reported numbers is inflated by temporal and spatial evaluation bias. The paper also looks at reputation-based platforms such as VirusTotal, MetaDefender, Hybrid Analysis, and ANY.RUN, Intezer Analyze, MalwareBazaar, and AndroZoo, comparing what each contributes to Android malware research and dataset construction. Drawing on this review, a generalized multi-stage detection pipeline is proposed, and the paper closes by outlining the research gaps that should guide future work on both the research and deployment sides of Android malware detection.

Keywords

Android Malware, Deep Learning, Machine Learning, Mobile Security, Static Analysis.

References

[1] Statcounter, Mobile Operating System Market Share Worldwide, 2024. [Online]. Available: https://gs.statcounter.com/os-market-share/mobile/

[2] Google, Android Security Year in Review 2023, Google Security Blog, Technical Report, 2024. [Online]. Available: https://blog.google/products-and-platforms/products/android-enterprise/android-security-paper-2023/

[3] Daniel Arp et al., “DREBIN: Effective and Explainable Detection of Android Malware in Your Pocket,” Proceedings of NDSS, San Diego, CA, vol. 14, no. 1, pp. 23-26, 2014.
[
Google Scholar] [Publisher Link]

[4] Zhen Liu et al., “SeGDroid: An Android Malware Detection Method Based on Sensitive Function Call Graph Learning,” Expert Systems with Applications, vol. 235, 2024.
[CrossRef] [
Google Scholar] [Publisher Link]

[5] Feargus Pendlebury et al., “TESSERACT: Eliminating Experimental Bias in Malware Classification Space and Across Time,” Proceedings of 28th USENIX Security Symposium, Santa Clara, CA, pp. 729-746, 2019.
[
Google Scholar] [Publisher Link]

[6] Vaibhav Rastogi, Yan Chen, and Xuxian Jiang, “Catch Me if you Can: Evaluating Android Anti-Malware Against Transformation Attacks,” IEEE Transactions on Information Forensics and Security, vol. 9, no. 1, pp. 99-108, 2014.
[CrossRef] [
Google Scholar] [Publisher Link]

[7] Steven Arzt et al., “FlowDroid: Precise Context, Flow, Field, Object-Sensitive and Lifecycle-Aware Taint Analysis for Android Apps,” ACM Sigplan Notices, vol. 49, no. 6, pp. 259-269, 2014.
[CrossRef] [
Google Scholar] [Publisher Link]

[8] Yousra Aafer, Wenliang Du, and Heng Yin, “DroidAPIMiner: Mining API-level Features for Robust Malware Detection in Android,” International Conference on Security and Privacy in Communication Systems, Springer, vol. 127, pp. 86-103, 2013.
[CrossRef] [
Google Scholar] [Publisher Link]

[9] Yu Feng et al., “Apposcopy: Semantics-Based Detection of Android Malware through Static Analysis,” Proceedings of the 22nd ACM SIGSOFT International Symposium on Foundations of Software Engineering, Hong Kong, pp. 576-587, 2014.
[CrossRef] [
Google Scholar] [Publisher Link]

[10] Jin Li et al., “Significant Permission Identification for Machine-Learning-Based Android Malware Detection,” IEEE Transactions on Industrial Informatics, vol. 14, no. 7, pp. 3216-3225, 2018.
[CrossRef] [
Google Scholar] [Publisher Link]

[11] Anshul Arora, Sateesh K. Peddoju, and Mauro Conti, “PermPair: Android Malware Detection using Permission Pairs,” IEEE Transactions on Information Forensics and Security, vol. 15, pp. 1968-1982, 2020.
[CrossRef] [
Google Scholar] [Publisher Link]

[12] William Enck et al., “TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones,” ACM Transactions on Computer Systems (TOCS), vol. 32, no. 2, pp. 1-29, 2014.
[CrossRef] [
Google Scholar] [Publisher Link]

[13] Roberto Jordaney et al., “Transcend: Detecting Concept Drift in Malware Classification Models,” 26th USENIX Security Symposium (USENIX Security 17), Vancouver, BC, pp. 625-642, 2017.
[
Google Scholar] [Publisher Link]

[14] Mohammed K. Alzaylaee, Suleiman Y. Yerima, and Sakir Sezer, “DL-Droid: Deep Learning based Android Malware Detection using Real Devices,” Computers & Security, vol. 89, pp. 1-11, 2020.
[CrossRef] [
Google Scholar] [Publisher Link]

[15] Lucky Onwuzurike et al., “MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral Models,” ACM Transactions on Privacy and Security (TOPS), vol. 22, no. 2, pp. 1-34, 2019.
[CrossRef] [
Google Scholar] [Publisher Link]

[16] ElMouatez Billah Karbab et al., “MalDozer: Automatic Framework for Android Malware Detection using Deep Learning,” Digital Investigation, vol. 24, pp. S48-S59, 2018.
[CrossRef] [
Google Scholar] [Publisher Link]

[17] Ke Xu et al., “DeepRefiner: Multi-Layer Android Malware Detection System Applying Deep Neural Networks,” 2018 IEEE European Symposium on Security and Privacy (EuroS&P), London, UK, pp. 473-487, 2018.
[CrossRef] [
Google Scholar] [Publisher Link]

[18] Xinjun Pei, Long Yu, and Shengwei Tian, “AMalNet: A Deep Learning Framework based on Graph Convolutional Networks for Malware Detection,” Computers & Security, vol. 93, 2020.
[CrossRef] [
Google Scholar] [Publisher Link]

[19] Wai Weng Lo et al., “Graph Neural Network-based Android Malware Classification with Jumping Knowledge,” 2022 IEEE Conference on Dependable and Secure Computing (DSC), Edinburgh, United Kingdom, pp. 1-9, 2022.
[CrossRef] [
Google Scholar] [Publisher Link]

[20] Yafei Wu et al., “DeepCatra: Learning Flow- and Graph-based Behaviors for Android Malware Detection,” IET Information Security, vol. 17, no. 1, pp. 118-130, 2022.
[CrossRef] [
Google Scholar] [Publisher Link]

[21] Jingnan Zheng et al., “MaskDroid: Robust Android Malware Detection with Masked Graph Representations,” Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering, pp. 331-343, 2024.
[CrossRef] [
Google Scholar] [Publisher Link]

[22] Muhammad Usama Tanveer et al., “GIT-GuardNet: Graph-Augmented Multi-Modal Learning Framework for Robust Android Malware Detection,” Scientific Reports, vol. 15, no. 1, pp. 1-17, 2025.
[CrossRef] [
Google Scholar] [Publisher Link]

[23] Borja Molina-Coronado et al., “Efficient Concept Drift Handling for Batch Android Malware Detection Models,” arXiv preprint, pp. 1-18, 2023.
[CrossRef] [
Google Scholar] [Publisher Link]

[24] Yiling He et al., “Combating Concept Drift with Explanatory Detection and Adaptation for Android Malware Classification,” arXiv preprint, pp. 1-19 2024.
[CrossRef] [
Google Scholar] [Publisher Link]

[25] Kathrin Grosse et al., “Adversarial Examples for Malware Detection,” Computer Security – ESORICS 2017, Oslo, vol. 10493, pp. 62-79, 2017.
[CrossRef] [
Google Scholar] [Publisher Link]

[26] Rahul Yumlembam et al., “IoT-based Android Malware Detection using Graph Neural Network with Adversarial Defense,” arXiv preprint, pp. 1-13, 2025.
[CrossRef] [
Google Scholar] [Publisher Link]

[27] Guojun Liu et al., “Benchmarking Android Malware Detection: Traditional vs. Deep Learning Models,” arXiv preprint, 2025.
[CrossRef] [
Google Scholar] [Publisher Link]

[28] Yin Minn Pa Pa et al., “An Attacker's Dream? Exploring the Capabilities of ChatGPT for Developing Malware,” Proceedings of the 16th Cyber Security Experimentation and Test Workshop, pp. 10-18, 2023.
[CrossRef] [
Google Scholar] [Publisher Link]

[29] Google Security Operations, VirusTotal API v3 Overview, 2024. [Online]. Available: https://docs.virustotal.com/reference/overview

[30] OPSWAT, MetaDefender: A More Private Alternative to VirusTotal, 2024. [Online]. Available: https://www.opswat.com/blog/metadefender-more-private-alternative-virustotal

[31] CrowdStrike, Hybrid Analysis, 2024. [Online]. Available: https://www.hybrid-analysis.com

[32] ANY.RUN, Interactive Online Malware Sandbox, 2024. [Online]. Available: https://any.run

[33] Intezer, Intezer Analyze, 2024. [Online]. Available: https://analyze.intezer.com

[34] abuse.ch, MalwareBazaar, 2024. [Online]. Available: https://bazaar.abuse.ch

[35] Jotti, Jotti's Malware Scan, 2024. [Online]. Available: https://virusscan.jotti.org

[36] Kevin Allix et al., “AndroZoo: Collecting Millions of Android Apps for the Research Community,” Proceedings of the 13th International Conference on Mining Software Repositories, Austin, TX, pp. 468-471, 2016.
[CrossRef] [
Google Scholar] [Publisher Link]

[37] Haoyu Wang et al., “RmvDroid: Towards a Reliable Android Malware Dataset with App Metadata,” 2019 IEEE/ACM 16th International Conference on Mining Software Repositories (MSR), Montreal, QC, Canada, pp. 404-408, 2019.
[CrossRef] [
Google Scholar] [Publisher Link]

[38] Aziz Mohaisen, Omar Alrawi, and Manar Mohaisen, “AMAL: High-Fidelity, Behavior-Based Automated Malware Analysis and Classification,” Computers & Security, vol. 52, pp. 251-266, 2015.
[CrossRef] [
Google Scholar] [Publisher Link]

[39] Marco Tulio Ribeiro, Sameer Singh, and Carlos Guestrin, “Why Should I Trust You?: Explaining the Predictions of Any Classifier,” Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, San Francisco, CA, USA, pp. 1135-1144, 2016.
[CrossRef] [
Google Scholar] [Publisher Link]

[40] Scott M. Lundberg, and Su-In Lee, “A Unified Approach to Interpreting Model Predictions,” Advances in Neural Information Processing Systems (NeurIPS), vol. 30, pp. 1-10, 2017.
[
Google Scholar] [Publisher Link]

[41] Zhitao Ying et al., “GNNExplainer: Generating Explanations for Graph Neural Networks,” Advances in Neural Information Processing Systems (NeurIPS), vol. 32, pp. 1-12, 2019.
[
Google Scholar] [Publisher Link]

[42] Josh Achiam, “GPT-4 Technical Report,” arXiv preprint, pp. 1-100, 2023.
[CrossRef] [
Google Scholar] [Publisher Link]

[43] Maryam Tanha, and Somayeh Kafaie, “A Review of Explainable AI for Android Malware Detection and Analysis,” IEEE Access, vol. 13, pp. 141958-141974, 2025.
[CrossRef] [
Publisher Link]

[44] Parvez Faruki et al., “Android Security: A Survey of Issues, Malware Penetration, and Defenses,” IEEE Communications Surveys & Tutorials, vol. 17, no. 2, pp. 998-1022, 2015.
[CrossRef] [
Google Scholar] [Publisher Link]

[45] Doan Minh Trung et al., “DMLDroid: Deep Multimodal Fusion Framework for Android Malware Detection with Resilience to Code Obfuscation and Adversarial Perturbations,” arXiv preprint, pp. 1-17, 2025.
[CrossRef] [
Google Scholar] [Publisher Link]

[46] Md. Habibullah Shakib, “Android Malware Detection using Transformer, Decoder and Encoder Models,” Array, vol. 28, pp. 1-13, 2025.
[CrossRef] [
Google Scholar] [Publisher Link]

[47] Giuseppina Andresini et al., “Anakin: Explainable Android Malware Detection with Graph Neural Networks,” Cybersecurity, vol. 9, no. 1, pp. 1-37, 2026.
[CrossRef] [
Google Scholar] [Publisher Link]

[48] Abhinandan Banik, and Jyoti Prakash Singh, “A BERT and PSO Framework for Android Malware Detection using Real Permissions and API Calls,” Discover Computing, vol. 29, no. 1, pp. 1-38, 2026.
[CrossRef] [
Google Scholar] [Publisher Link]