Research Article | Open Access | Download PDF
Volume 74 | Issue 9 | Year 2026 | Article Id. IJCTT-V74I9P101 | DOI : https://doi.org/10.14445/22312803/IJCTT-V74I9P101A Critical Review of Android Malware Detection Techniques (2014–2026): Evaluating Static, Dynamic, Hybrid, and Deep Learning Approaches
Rishish Jain, D. A. Mehta
| Received | Revised | Accepted | Published |
|---|---|---|---|
| 09 Jul 2026 | 17 Aug 2026 | 02 Sep 2026 | 18 Sep 2026 |
Citation :
Rishish Jain, D. A. Mehta, "A Critical Review of Android Malware Detection Techniques (2014–2026): Evaluating Static, Dynamic, Hybrid, and Deep Learning Approaches," International Journal of Computer Trends and Technology (IJCTT), vol. 74, no. 9, pp. 1-15, 2026. Crossref, https://doi.org/10.14445/22312803/IJCTT-V74I9P101
Abstract
Over the past decade, Android malware detection has advanced a great deal, yet a persistent gap remains between the accuracy figures reported on benchmarks and what these systems actually achieve once deployed. This paper reviews thirty-one Android malware detection systems and reputation-intelligence platforms published between 2014 and 2026, spanning static, dynamic, hybrid, and deep-learning approaches, and compares them against six practical criteria: detection accuracy, obfuscation resilience, computational overhead, scalability, temporal robustness, and practical deployability. Benchmark accuracy rose from around 94% for Drebin to 98.1% for SeGDroid over this period, but Pendlebury et al.’s TESSERACT framework shows that a large share of these reported numbers is inflated by temporal and spatial evaluation bias. The paper also looks at reputation-based platforms such as VirusTotal, MetaDefender, Hybrid Analysis, and ANY.RUN, Intezer Analyze, MalwareBazaar, and AndroZoo, comparing what each contributes to Android malware research and dataset construction. Drawing on this review, a generalized multi-stage detection pipeline is proposed, and the paper closes by outlining the research gaps that should guide future work on both the research and deployment sides of Android malware detection.
Keywords
Android Malware, Deep Learning, Machine Learning, Mobile Security, Static Analysis.
References
[1] Statcounter, Mobile
Operating System Market Share Worldwide, 2024. [Online]. Available:
https://gs.statcounter.com/os-market-share/mobile/
[2] Google, Android Security
Year in Review 2023, Google Security Blog, Technical Report, 2024. [Online].
Available:
https://blog.google/products-and-platforms/products/android-enterprise/android-security-paper-2023/
[3] Daniel Arp et al., “DREBIN:
Effective and Explainable Detection of Android Malware in Your Pocket,” Proceedings of NDSS, San Diego, CA, vol.
14, no. 1, pp. 23-26, 2014.
[Google Scholar] [Publisher Link]
[4] Zhen Liu et al., “SeGDroid:
An Android Malware Detection Method Based on Sensitive Function Call Graph
Learning,” Expert Systems with
Applications, vol. 235, 2024.
[CrossRef]
[Google Scholar] [Publisher Link]
[5] Feargus Pendlebury et al., “TESSERACT:
Eliminating Experimental Bias in Malware Classification Space and Across Time,”
Proceedings of 28th USENIX
Security Symposium, Santa Clara, CA, pp. 729-746, 2019.
[Google Scholar] [Publisher Link]
[6] Vaibhav Rastogi, Yan Chen,
and Xuxian Jiang, “Catch Me if you Can: Evaluating Android Anti-Malware Against
Transformation Attacks,” IEEE
Transactions on Information Forensics and Security, vol. 9, no. 1, pp.
99-108, 2014.
[CrossRef] [Google Scholar] [Publisher Link]
[7] Steven Arzt et al.,
“FlowDroid: Precise Context, Flow, Field, Object-Sensitive and Lifecycle-Aware
Taint Analysis for Android Apps,” ACM
Sigplan Notices, vol. 49, no. 6, pp. 259-269, 2014.
[CrossRef]
[Google Scholar] [Publisher Link]
[8] Yousra Aafer, Wenliang Du,
and Heng Yin, “DroidAPIMiner: Mining API-level Features for Robust Malware
Detection in Android,” International
Conference on Security and Privacy in Communication Systems, Springer, vol. 127, pp. 86-103, 2013.
[CrossRef]
[Google Scholar] [Publisher Link]
[9] Yu Feng et al., “Apposcopy:
Semantics-Based Detection of Android Malware through Static Analysis,” Proceedings of the 22nd ACM
SIGSOFT International Symposium on Foundations of Software Engineering,
Hong Kong, pp. 576-587, 2014.
[CrossRef] [Google Scholar] [Publisher Link]
[10] Jin Li et al., “Significant
Permission Identification for Machine-Learning-Based Android Malware
Detection,” IEEE Transactions on
Industrial Informatics, vol. 14, no. 7, pp. 3216-3225, 2018.
[CrossRef]
[Google Scholar] [Publisher Link]
[11] Anshul Arora, Sateesh K.
Peddoju, and Mauro Conti, “PermPair:
Android Malware Detection using Permission Pairs,” IEEE Transactions on Information Forensics and Security, vol. 15,
pp. 1968-1982, 2020.
[CrossRef] [Google Scholar] [Publisher Link]
[12] William Enck et al.,
“TaintDroid: An Information-Flow Tracking System for Realtime Privacy
Monitoring on Smartphones,” ACM
Transactions on Computer Systems (TOCS), vol. 32, no. 2, pp. 1-29, 2014.
[CrossRef]
[Google Scholar] [Publisher Link]
[13] Roberto Jordaney et al.,
“Transcend: Detecting Concept Drift in Malware Classification Models,” 26th USENIX Security Symposium
(USENIX Security 17), Vancouver, BC, pp. 625-642, 2017.
[Google Scholar] [Publisher Link]
[14] Mohammed K. Alzaylaee,
Suleiman Y. Yerima, and Sakir Sezer, “DL-Droid: Deep Learning based Android
Malware Detection using Real Devices,” Computers
& Security, vol. 89, pp. 1-11, 2020.
[CrossRef]
[Google Scholar] [Publisher Link]
[15] Lucky Onwuzurike et al.,
“MaMaDroid: Detecting Android Malware by Building Markov Chains of Behavioral
Models,” ACM Transactions on Privacy and
Security (TOPS), vol. 22, no. 2, pp. 1-34, 2019.
[CrossRef]
[Google Scholar] [Publisher Link]
[16] ElMouatez Billah Karbab et
al., “MalDozer: Automatic Framework for Android Malware Detection using Deep
Learning,” Digital Investigation,
vol. 24, pp. S48-S59, 2018.
[CrossRef]
[Google Scholar] [Publisher Link]
[17] Ke Xu et al., “DeepRefiner:
Multi-Layer Android Malware Detection System Applying Deep Neural Networks,” 2018 IEEE European Symposium on Security and
Privacy (EuroS&P), London, UK, pp. 473-487, 2018.
[CrossRef]
[Google Scholar] [Publisher Link]
[18] Xinjun Pei, Long Yu, and
Shengwei Tian, “AMalNet: A Deep Learning Framework based on Graph Convolutional
Networks for Malware Detection,” Computers
& Security, vol. 93, 2020.
[CrossRef]
[Google Scholar] [Publisher Link]
[19] Wai Weng Lo et al., “Graph
Neural Network-based Android Malware Classification with Jumping Knowledge,” 2022 IEEE Conference on Dependable and Secure
Computing (DSC), Edinburgh, United Kingdom, pp. 1-9, 2022.
[CrossRef]
[Google Scholar] [Publisher Link]
[20] Yafei Wu et al.,
“DeepCatra: Learning Flow- and Graph-based Behaviors for Android Malware
Detection,” IET Information Security,
vol. 17, no. 1, pp. 118-130, 2022.
[CrossRef] [Google Scholar] [Publisher Link]
[21] Jingnan Zheng et al.,
“MaskDroid: Robust Android Malware Detection with Masked Graph
Representations,” Proceedings of the 39th
IEEE/ACM International Conference on Automated Software Engineering, pp.
331-343, 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[22] Muhammad Usama Tanveer et
al., “GIT-GuardNet: Graph-Augmented Multi-Modal Learning Framework for Robust
Android Malware Detection,” Scientific
Reports, vol. 15, no. 1, pp. 1-17, 2025.
[CrossRef]
[Google Scholar] [Publisher Link]
[23] Borja Molina-Coronado et
al., “Efficient Concept Drift Handling for Batch Android Malware Detection
Models,” arXiv preprint, pp. 1-18, 2023.
[CrossRef]
[Google Scholar] [Publisher Link]
[24] Yiling He et al., “Combating
Concept Drift with Explanatory Detection and Adaptation for Android Malware
Classification,” arXiv preprint, pp.
1-19 2024.
[CrossRef] [Google Scholar] [Publisher Link]
[25] Kathrin Grosse et al.,
“Adversarial Examples for Malware Detection,” Computer Security – ESORICS 2017, Oslo, vol. 10493, pp. 62-79,
2017.
[CrossRef] [Google Scholar] [Publisher Link]
[26] Rahul Yumlembam et al.,
“IoT-based Android Malware Detection using Graph Neural Network with
Adversarial Defense,” arXiv preprint,
pp. 1-13, 2025.
[CrossRef] [Google Scholar] [Publisher Link]
[27] Guojun Liu et al.,
“Benchmarking Android Malware Detection: Traditional vs. Deep Learning Models,”
arXiv preprint, 2025.
[CrossRef]
[Google Scholar] [Publisher Link]
[28] Yin Minn Pa Pa et al., “An
Attacker's Dream? Exploring the Capabilities of ChatGPT for Developing
Malware,” Proceedings of the 16th
Cyber Security Experimentation and Test Workshop, pp. 10-18, 2023.
[CrossRef]
[Google Scholar] [Publisher Link]
[29] Google Security Operations,
VirusTotal API v3 Overview, 2024. [Online]. Available:
https://docs.virustotal.com/reference/overview
[30] OPSWAT, MetaDefender: A More Private Alternative to VirusTotal, 2024. [Online]. Available: https://www.opswat.com/blog/metadefender-more-private-alternative-virustotal
[31] CrowdStrike, Hybrid
Analysis, 2024. [Online]. Available: https://www.hybrid-analysis.com
[32] ANY.RUN, Interactive Online
Malware Sandbox, 2024. [Online]. Available: https://any.run
[33] Intezer, Intezer Analyze,
2024. [Online]. Available: https://analyze.intezer.com
[34] abuse.ch, MalwareBazaar,
2024. [Online]. Available: https://bazaar.abuse.ch
[35] Jotti, Jotti's Malware
Scan, 2024. [Online]. Available: https://virusscan.jotti.org
[36] Kevin Allix et al.,
“AndroZoo: Collecting Millions of Android Apps for the Research Community,” Proceedings of the 13th
International Conference on Mining Software Repositories, Austin, TX, pp.
468-471, 2016.
[CrossRef] [Google Scholar] [Publisher Link]
[37] Haoyu Wang et al.,
“RmvDroid: Towards a Reliable Android Malware Dataset with App Metadata,” 2019 IEEE/ACM 16th International
Conference on Mining Software Repositories (MSR), Montreal, QC, Canada, pp.
404-408, 2019.
[CrossRef] [Google Scholar] [Publisher Link]
[38] Aziz Mohaisen, Omar Alrawi,
and Manar Mohaisen, “AMAL: High-Fidelity, Behavior-Based Automated Malware
Analysis and Classification,” Computers
& Security, vol. 52, pp. 251-266, 2015.
[CrossRef]
[Google Scholar] [Publisher Link]
[39] Marco Tulio Ribeiro, Sameer
Singh, and Carlos Guestrin, “Why Should I Trust You?: Explaining the
Predictions of Any Classifier,” Proceedings
of the 22nd ACM SIGKDD International Conference on Knowledge
Discovery and Data Mining, San Francisco, CA, USA, pp. 1135-1144, 2016.
[CrossRef]
[Google Scholar] [Publisher Link]
[40] Scott M. Lundberg, and
Su-In Lee, “A Unified Approach to Interpreting Model Predictions,” Advances in Neural Information Processing
Systems (NeurIPS), vol. 30, pp. 1-10, 2017.
[Google Scholar] [Publisher Link]
[41] Zhitao Ying et al.,
“GNNExplainer: Generating Explanations for Graph Neural Networks,” Advances in Neural Information Processing
Systems (NeurIPS), vol. 32, pp. 1-12, 2019.
[Google Scholar] [Publisher Link]
[42] Josh Achiam, “GPT-4
Technical Report,” arXiv preprint,
pp. 1-100, 2023.
[CrossRef] [Google Scholar] [Publisher Link]
[43] Maryam Tanha, and Somayeh
Kafaie, “A Review of Explainable AI for Android Malware Detection and
Analysis,” IEEE Access, vol. 13, pp.
141958-141974, 2025.
[CrossRef] [Publisher Link]
[44] Parvez Faruki et al.,
“Android Security: A Survey of Issues, Malware Penetration, and Defenses,” IEEE Communications Surveys & Tutorials,
vol. 17, no. 2, pp. 998-1022, 2015.
[CrossRef]
[Google Scholar] [Publisher Link]
[45] Doan Minh Trung et al.,
“DMLDroid: Deep Multimodal Fusion Framework for Android Malware Detection with
Resilience to Code Obfuscation and Adversarial Perturbations,” arXiv preprint, pp. 1-17, 2025.
[CrossRef]
[Google Scholar] [Publisher Link]
[46] Md. Habibullah Shakib,
“Android Malware Detection using Transformer, Decoder and Encoder Models,” Array, vol. 28, pp. 1-13, 2025.
[CrossRef]
[Google Scholar] [Publisher Link]
[47] Giuseppina Andresini et
al., “Anakin: Explainable Android Malware Detection with Graph Neural
Networks,” Cybersecurity, vol. 9, no.
1, pp. 1-37, 2026.
[CrossRef] [Google Scholar] [Publisher Link]
[48] Abhinandan Banik, and Jyoti
Prakash Singh, “A BERT and PSO Framework for Android Malware Detection using
Real Permissions and API Calls,” Discover
Computing, vol. 29, no. 1, pp. 1-38, 2026.
[CrossRef]
[Google Scholar] [Publisher Link]