{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T17:31:01Z","timestamp":1785605461729,"version":"3.56.0"},"reference-count":65,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2025,2,23]],"date-time":"2025-02-23T00:00:00Z","timestamp":1740268800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,2,23]],"date-time":"2025-02-23T00:00:00Z","timestamp":1740268800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"European Union Next-Generation EU","award":["J73C24000060007"],"award-info":[{"award-number":["J73C24000060007"]}]},{"name":"European Union Next-Generation EU","award":["J73C24000060007"],"award-info":[{"award-number":["J73C24000060007"]}]},{"DOI":"10.13039\/501100004913","name":"Universit\u00e0 degli Studi di Palermo","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100004913","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2025,4]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>Malwares are a major threat to the security of mobile devices, and Machine Learning (ML) is a widespread approach to automatically detect them. However, running ML analysis pipelines can be excessively burdensome for energy-constrained mobile devices. On the other hand, completely off-loading all the analysis to a remote server can introduce unacceptable communication overheads and delays in the detection process. In this paper, we propose a multilevel approach for malware detection on mobile devices that combines a lightweight local analysis of static features with a more computationally expensive remote analysis of dynamic features, through the adoption of ML methods. However, the effectiveness of automatic malware detection systems based on ML is often limited by unforeseen variations in the statistical characteristics of the observed data. This phenomenon, known as concept drift, can lead to a degradation of the performance of ML models over time. The proposed malware detection system is equipped with self-evaluation capabilities, enabling it to detect the occurrence of periods when its predictions become unreliable due to concept drift so that appropriate response strategies can be activated. In particular, when such critical events occur, the self-evaluation agent triggers the execution of an additional layer of analysis, hosted by a remote server, which allows the system to react to the unexpected reduction in its detection capabilities. The computational cost of the detection process is minimized by limiting the remote analysis to only those samples for which the analysis performed on-board the mobile device is likely to incorrectly classify the app.<\/jats:p>","DOI":"10.1007\/s10922-025-09906-3","type":"journal-article","created":{"date-parts":[[2025,2,23]],"date-time":"2025-02-23T08:05:57Z","timestamp":1740297957000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["Hybrid Multilevel Detection of Mobile Devices Malware Under Concept Drift"],"prefix":"10.1007","volume":"33","author":[{"given":"Andrea","family":"Augello","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alessandra","family":"De Paola","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giuseppe","family":"Lo Re","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,2,23]]},"reference":[{"issue":"3","key":"9906_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3448609","volume":"24","author":"R Mayrhofer","year":"2021","unstructured":"Mayrhofer, R., Stoep, J.V., Brubaker, C., Kralevich, N.: The android platform security model. ACM Trans. Priv. Secur. 24(3), 1\u201335 (2021)","journal-title":"ACM Trans. Priv. Secur."},{"issue":"2","key":"9906_CR2","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10922-024-09803-1","volume":"32","author":"AM Ansari","year":"2024","unstructured":"Ansari, A.M., Nazir, M., Mustafa, K.: Smart homes app vulnerabilities, threats, and solutions: a systematic literature review. J. Netw. and Syst. Manag. 32(2), 1\u201362 (2024)","journal-title":"J. Netw. and Syst. Manag."},{"issue":"6","key":"9906_CR3","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3417978","volume":"53","author":"J Qiu","year":"2020","unstructured":"Qiu, J., Zhang, J., Luo, W., Pan, L., Nepal, S., Xiang, Y.: A survey of android malware detection with deep neural models. ACM Comput. Surv. (CSUR) 53(6), 1\u201336 (2020)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"9906_CR4","unstructured":"De Paola, A., Favaloro, S., Gaglio, S., Lo Re, G., Morana, M.: Malware detection through low-level features and stacked denoising autoencoders. In: ITASEC 2018. Italian Conf. on Cyber Security. CEUR-WS. Milan, Italy: CEUR-WS.org; (2018)"},{"issue":"2","key":"9906_CR5","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1007\/s10922-021-09635-3","volume":"30","author":"HW Li","year":"2022","unstructured":"Li, H.W., Wu, Y.S., Huang, Y.: On the feasibility of anomaly detection with fine-grained program tracing events. J. Netw. and Syst. Manag. 30(2), 28 (2022)","journal-title":"J. Netw. and Syst. Manag."},{"key":"9906_CR6","doi-asserted-by":"crossref","unstructured":"Khalid, S., Hussain, F.B.: Evaluating Dynamic Analysis Features for Android Malware Categorization. In: 2022 Int. Wireless Communications and Mobile Computing (IWCMC). Dubrovnik, Croatia: IEEE; (2022). p. 401-6","DOI":"10.1109\/IWCMC55113.2022.9824225"},{"issue":"5","key":"9906_CR7","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3329786","volume":"52","author":"O Or-Meir","year":"2019","unstructured":"Or-Meir, O., Nissim, N., Elovici, Y., Rokach, L.: Dynamic malware analysis in the modern era-a state of the art survey. ACM Comput. Surv. 52(5), 1\u201348 (2019)","journal-title":"ACM Comput. Surv."},{"issue":"3","key":"9906_CR8","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3579822","volume":"26","author":"N Lachtar","year":"2023","unstructured":"Lachtar, N., Ibdah, D., Khan, H., Bacha, A.: RansomShield: a visualization approach to defending mobile systems against ransomware. ACM Trans. Priv. Secur. 26(3), 1\u201330 (2023)","journal-title":"ACM Trans. Priv. Secur."},{"key":"9906_CR9","doi-asserted-by":"crossref","unstructured":"De Paola, A., Gaglio, S., Lo Re, G., Morana, M.: A hybrid system for malware detection on big data. In: IEEE INFOCOM 2018 - IEEE Conf. on Computer Communications Workshops (INFOCOM WKSHPS). Honolulu, HI, USA: IEEE. p. 45-50 (2018)","DOI":"10.1109\/INFCOMW.2018.8406963"},{"issue":"1","key":"9906_CR10","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1007\/s10922-021-09634-4","volume":"30","author":"S Mahdavifar","year":"2022","unstructured":"Mahdavifar, S., Alhadidi, D., Ghorbani, A.A.: Effective and efficient hybrid android malware classification using pseudo-label stacked auto-encoder. J. Netw. and Syst. Manag. 30(1), 22 (2022)","journal-title":"J. Netw. and Syst. Manag."},{"key":"9906_CR11","doi-asserted-by":"crossref","unstructured":"Kambar, M.E.Z.N., Esmaeilzadeh, A., Kim, Y., Taghva, K.: A survey on mobile malware detection methods using machine learning. In: 2022 IEEE 12th Annual Computing and Communication Workshop and Conf. (CCWC). IEEE. Las Vegas, NV, USA: IEEE. p. 0215-21 (2022)","DOI":"10.1109\/CCWC54503.2022.9720753"},{"key":"9906_CR12","doi-asserted-by":"publisher","first-page":"772","DOI":"10.1007\/s12559-015-9341-0","volume":"7","author":"I Khamassi","year":"2015","unstructured":"Khamassi, I., Sayed-Mouchaweh, M., Hammami, M., Gh\u00e9dira, K.: Self-adaptive windowing approach for handling complex concept drift. Cognitive Comput. 7, 772\u201390 (2015)","journal-title":"Cognitive Comput."},{"key":"9906_CR13","unstructured":"Yang, L., Guo, W., Hao, Q., Ciptadi, A., Ahmadzadeh, A., Xing, X., et al.: CADE: Detecting and Explaining Concept Drift Samples for Security Applications. In: 30th USENIX Security Symp. (USENIX Security 21). Vancouver, BC, Canada: USENIX Association; p. 2327-44 (2021)"},{"key":"9906_CR14","unstructured":"Chen, Y., Ding, Z., Wagner, D.: Continuous Learning for Android Malware Detection. In: 32nd USENIX Security Symp. (USENIX Security 23). Anaheim, CA: USENIX Association. p. 1127-44 (2023)"},{"issue":"2","key":"9906_CR15","doi-asserted-by":"publisher","first-page":"28","DOI":"10.1007\/s10922-024-09800-4","volume":"32","author":"A Sherawat","year":"2024","unstructured":"Sherawat, A., Nath, S.B., Addya, S.K.: Optimizing completion time of requests in serverless computing. J. Netw. and Syst. Manag. 32(2), 28 (2024)","journal-title":"J. Netw. and Syst. Manag."},{"key":"9906_CR16","unstructured":"Stats, S.G.: Mobile Operating System Market Share Worldwide (2023)"},{"key":"9906_CR17","doi-asserted-by":"publisher","first-page":"102399","DOI":"10.1016\/j.cose.2021.102399","volume":"110","author":"A Guerra-Manzanares","year":"2021","unstructured":"Guerra-Manzanares, A., Bahsi, H., Nomm, S.: KronoDroid: time-based hybrid-featured dataset for effective android malware detection and characterization. Comput. & Secur. 110, 102399 (2021)","journal-title":"Comput. & Secur."},{"key":"9906_CR18","doi-asserted-by":"crossref","unstructured":"Borojerdi HR, Abadi M.: MalHunter: Automatic generation of multiple behavioral signatures for polymorphic malware detection. In: ICCKE 2013. Mashhad, Iran: IEEE. p. 430-6 (2013)","DOI":"10.1109\/ICCKE.2013.6682867"},{"issue":"1","key":"9906_CR19","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1007\/s10922-021-09621-9","volume":"30","author":"S Tsimenidis","year":"2022","unstructured":"Tsimenidis, S., Lagkas, T., Rantos, K.: Deep learning in IoT intrusion detection. J. Netw. and Syst. Manag. 30(1), 8 (2022)","journal-title":"J. Netw. and Syst. Manag."},{"issue":"2","key":"9906_CR20","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3494535","volume":"25","author":"M Botacin","year":"2022","unstructured":"Botacin, M., Moreira, F.B., Navaux, P.O.A., Gr\u00e9gio, A., Alves, M.A.Z.: Terminator: a secure coprocessor to accelerate real-time antiViruses using inspection breakpoints. ACM Trans. Priv. Secur. 25(2), 1\u201334 (2022)","journal-title":"ACM Trans. Priv. Secur."},{"key":"9906_CR21","doi-asserted-by":"publisher","first-page":"184","DOI":"10.1007\/978-3-319-64701-2_14","volume-title":"Netw. and Syst. Secur.","author":"A Gharib","year":"2017","unstructured":"Gharib, A., Ghorbani, A.: DNA-Droid: a real-time android ransomware detection framework. In: Yan, Z., Molva, R., Mazurczyk, W., Kantola, R. (eds.) Netw. and Syst. Secur., pp. 184\u2013198. Springer Int. Publishing, Cham (2017)"},{"issue":"8","key":"9906_CR22","doi-asserted-by":"publisher","first-page":"1009","DOI":"10.3390\/e23081009","volume":"23","author":"C Ding","year":"2021","unstructured":"Ding, C., Luktarhan, N., Lu, B., Zhang, W.: A hybrid analysis-based approach to android malware family classification. Entropy 23(8), 1009 (2021)","journal-title":"Entropy"},{"key":"9906_CR23","doi-asserted-by":"publisher","first-page":"101849","DOI":"10.1016\/j.pmcj.2023.101849","volume":"96","author":"B Molina-Coronado","year":"2023","unstructured":"Molina-Coronado, B., Mori, U., Mendiburu, A., Miguel-Alonso, J.: Efficient concept drift handling for batch android malware detection models. Pervasive and Mobile Comput. 96, 101849 (2023)","journal-title":"Pervasive and Mobile Comput."},{"key":"9906_CR24","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-023-00759-y","author":"E Alkhateeb","year":"2024","unstructured":"Alkhateeb, E., Ghorbani, A., Habibi Lashkari, A.: A survey on run-time packers and mitigation techniques. Int. J. Inf. Secur. (2024). https:\/\/doi.org\/10.1007\/s10207-023-00759-y","journal-title":"Int. J. Inf. Secur."},{"key":"9906_CR25","doi-asserted-by":"crossref","unstructured":"Sugunan, K., Gireesh\u00a0Kumar, T., Dhanya, K.: Static and dynamic analysis for android malware detection. In: Advances in Big Data and Cloud Computing. Springer. Singapore: Springer; p. 147-55 (2018)","DOI":"10.1007\/978-981-10-7200-0_13"},{"key":"9906_CR26","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-023-00712-z","author":"M Zyout","year":"2023","unstructured":"Zyout, M., Shatnawi, R., Najadat, H.: Malware classification approaches utilizing binary and text encoding of permissions. Int. J. Inf. Secur. (2023). https:\/\/doi.org\/10.1007\/s10207-023-00712-z","journal-title":"Int. J. Inf. Secur."},{"key":"9906_CR27","doi-asserted-by":"publisher","first-page":"59","DOI":"10.1007\/s10207-020-00489-5","volume":"20","author":"P Liu","year":"2021","unstructured":"Liu, P., Wang, W., Luo, X., Wang, H., Liu, C.: NSDroid: efficient multi-classification of android malware using neighborhood signature in local function call graphs. Int. J. Inf. Secur. 20, 59\u201371 (2021)","journal-title":"Int. J. Inf. Secur."},{"issue":"5","key":"9906_CR28","doi-asserted-by":"publisher","first-page":"523","DOI":"10.1007\/s10207-019-00471-w","volume":"19","author":"A Alzaidi","year":"2020","unstructured":"Alzaidi, A., Alshehri, S., Buhari, S.M.: DroidRista: a highly precise static data flow analysis framework for android applications. Int. J. Inf. Secur. 19(5), 523\u201336 (2020)","journal-title":"Int. J. Inf. Secur."},{"issue":"1","key":"9906_CR29","doi-asserted-by":"publisher","first-page":"107","DOI":"10.1007\/s10207-022-00626-2","volume":"22","author":"PG Balikcioglu","year":"2023","unstructured":"Balikcioglu, P.G., Sirlanci, M., Kucuk, A., Ulukapi, B.: Malicious code detection in android: the role of sequence characteristics and disassembling methods. Int. J. Inf. Secur. 22(1), 107\u201318 (2023)","journal-title":"Int. J. Inf. Secur."},{"key":"9906_CR30","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/s10207-018-0415-3","volume":"18","author":"ML Bernardi","year":"2019","unstructured":"Bernardi, M.L., Cimitile, M., Distante, D., Martinelli, F., Mercaldo, F.: Dynamic malware detection and phylogeny analysis using process mining. Int. J. Inf. Secur. 18, 257\u201384 (2019)","journal-title":"Int. J. Inf. Secur."},{"issue":"1","key":"9906_CR31","doi-asserted-by":"publisher","first-page":"137","DOI":"10.1007\/s10207-022-00624-4","volume":"22","author":"S Hamzenejadi","year":"2023","unstructured":"Hamzenejadi, S., Ghazvini, M., Hosseini, S.: Mobile botnet detection: a comprehensive survey. Int. J. of Inf. Secur. 22(1), 137\u201375 (2023)","journal-title":"Int. J. of Inf. Secur."},{"key":"9906_CR32","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-023-00699-7","author":"R Wang","year":"2023","unstructured":"Wang, R., Gao, J., Huang, S.: AIHGAT: a novel method of malware detection and homology analysis using assembly instruction heterogeneous graph. Int. J. Inf. Secur. (2023). https:\/\/doi.org\/10.1007\/s10207-023-00699-7","journal-title":"Int. J. Inf. Secur."},{"key":"9906_CR33","doi-asserted-by":"publisher","first-page":"583","DOI":"10.1007\/s10207-014-0238-9","volume":"13","author":"S Sen","year":"2014","unstructured":"Sen, S.: Using instance-weighted naive Bayes for adapting concept drift in masquerade detection. Int. J. Inf. Secur. 13, 583\u201390 (2014)","journal-title":"Int. J. Inf. Secur."},{"issue":"3","key":"9906_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3439802","volume":"24","author":"AS Ami","year":"2021","unstructured":"Ami, A.S., Kafle, K., Moran, K., Nadkarni, A., Poshyvanyk, D.: Systematic mutation-based evaluation of the soundness of security-focused android static analysis techniques. ACM Trans. Priv. Secur. 24(3), 1\u201337 (2021)","journal-title":"ACM Trans. Priv. Secur."},{"key":"9906_CR35","doi-asserted-by":"crossref","unstructured":"Concone, F., De\u00a0Paola, A., Lo\u00a0Re, G., Morana, M.: Twitter analysis for real-time malware discovery. In: 2017 AEIT Int. Annual Conf. p. 1-6 (2017)","DOI":"10.23919\/AEIT.2017.8240551"},{"key":"9906_CR36","doi-asserted-by":"publisher","first-page":"103706","DOI":"10.1016\/j.cose.2024.103706","volume":"139","author":"Y Jiang","year":"2024","unstructured":"Jiang, Y., Li, G., Li, S., Guo, Y.: BenchMFC: a benchmark dataset for trustworthy malware family classification under concept drift. Comput. & Secur. 139, 103706 (2024)","journal-title":"Comput. & Secur."},{"key":"9906_CR37","doi-asserted-by":"crossref","unstructured":"Barbero, F., Pendlebury, F., Pierazzi, F., Cavallaro, L.: Transcending transcend: Revisiting malware classification in the presence of concept drift. In: 2022 IEEE Symp. on Security and Privacy (SP). IEEE. San Francisco, CA: IEEE . p. 805-23 (2022)","DOI":"10.1109\/SP46214.2022.9833659"},{"key":"9906_CR38","doi-asserted-by":"publisher","DOI":"10.1145\/3313391","author":"L Onwuzurike","year":"2019","unstructured":"Onwuzurike, L., Mariconti, E., Andriotis, P., Cristofaro, E.D., Ross, G., Stringhini, G.: MaMaDroid: detecting android malware by building markov chains of behavioral models (Extended Version). ACM Trans. Priv. Secur. (2019). https:\/\/doi.org\/10.1145\/3313391","journal-title":"ACM Trans. Priv. Secur."},{"key":"9906_CR39","doi-asserted-by":"crossref","unstructured":"Xu, K., Li, Y., Deng, R., Chen, K., Xu, J.: DroidEvolver: Self-Evolving Android Malware Detection System. In: 2019 IEEE European Symp. on Security and Privacy (EuroS &P). Stockholm, Sweden: IEEE; p. 47-62 (2019)","DOI":"10.1109\/EuroSP.2019.00014"},{"key":"9906_CR40","doi-asserted-by":"publisher","first-page":"97180","DOI":"10.1109\/ACCESS.2021.3093366","volume":"9","author":"AA Darem","year":"2021","unstructured":"Darem, A.A., Ghaleb, F.A., Al-Hashmi, A.A., Abawajy, J.H., Alanazi, S.M., Al-Rezami, A.Y.: An adaptive behavioral-based incremental batch learning malware variants detection model using concept drift detection and sequential deep learning. IEEE Access. 9, 97180\u201396 (2021)","journal-title":"IEEE Access."},{"key":"9906_CR41","doi-asserted-by":"publisher","first-page":"117200","DOI":"10.1016\/j.eswa.2022.117200","volume":"206","author":"A Guerra-Manzanares","year":"2022","unstructured":"Guerra-Manzanares, A., Luckner, M., Bahsi, H.: Android malware concept drift using system calls: detection, characterization and challenges. Expert Syst. with Appl. 206, 117200 (2022)","journal-title":"Expert Syst. with Appl."},{"key":"9906_CR42","doi-asserted-by":"publisher","first-page":"118590","DOI":"10.1016\/j.eswa.2022.118590","volume":"212","author":"F Ceschin","year":"2023","unstructured":"Ceschin, F., Botacin, M., Gomes, H.M., Pinag\u00e9, F., Oliveira, L.S., Gr\u00e9gio, A.: Fast & furious: on the modelling of malware detection as an evolving data stream. Expert Syst. with Appl. 212, 118590 (2023)","journal-title":"Expert Syst. with Appl."},{"key":"9906_CR43","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-020-00536-1","author":"H Alecakir","year":"2021","unstructured":"Alecakir, H., Can, B., Sen, S.: Attention: there is an inconsistency between android permissions and application metadata! Int. J. Inf. Secur. (2021). https:\/\/doi.org\/10.1007\/s10207-020-00536-1","journal-title":"Int. J. Inf. Secur."},{"key":"9906_CR44","doi-asserted-by":"publisher","first-page":"103629","DOI":"10.1016\/j.cose.2023.103629","volume":"137","author":"DW Fernando","year":"2024","unstructured":"Fernando, D.W., Komninos, N.: FeSAD ransomware detection framework with machine learning using adaption to concept drift. Comput. & Secur. 137, 103629 (2024)","journal-title":"Comput. & Secur."},{"key":"9906_CR45","doi-asserted-by":"crossref","unstructured":"Agate, V., De\u00a0Paola, A., Drago, S., Ferraro, P., Lo\u00a0Re, G.: Enhancing IoT Network Security with Concept Drift-Aware Unsupervised Threat Detection. In: 2024 IEEE Symposium on Computers and Communications (ISCC). IEEE (2024)","DOI":"10.1109\/ISCC61673.2024.10733733"},{"issue":"1","key":"9906_CR46","doi-asserted-by":"publisher","first-page":"6","DOI":"10.1007\/s10922-023-09781-w","volume":"32","author":"MA Elsayed","year":"2024","unstructured":"Elsayed, M.A., Zincir-Heywood, N.: BoostSec: adaptive attack detection for vehicular networks. J. Netw. and Syst. Manag. 32(1), 6 (2024)","journal-title":"J. Netw. and Syst. Manag."},{"issue":"5","key":"9906_CR47","doi-asserted-by":"publisher","first-page":"1718","DOI":"10.1016\/j.patcog.2007.10.015","volume":"41","author":"AH Ko","year":"2008","unstructured":"Ko, A.H., Sabourin, R., Britto, A.S., Jr.: From dynamic classifier selection to dynamic ensemble selection. Pattern Recognit. 41(5), 1718\u201331 (2008)","journal-title":"Pattern Recognit."},{"key":"9906_CR48","doi-asserted-by":"publisher","first-page":"138","DOI":"10.1016\/j.inffus.2020.09.004","volume":"66","author":"P Zyblewski","year":"2021","unstructured":"Zyblewski, P., Sabourin, R., Wo\u017aniak, M.: Preprocessed dynamic classifier ensemble selection for highly imbalanced drifted data streams. Inf. Fusion. 66, 138\u201354 (2021)","journal-title":"Inf. Fusion."},{"key":"9906_CR49","doi-asserted-by":"crossref","unstructured":"Agate, V., Drago, S., Ferraro, P., Lo\u00a0Re, G.: Anomaly Detection for Reoccurring Concept Drift in Smart Environments. In: 2022 18th Int. Conf. on Mobility, Sensing and Networking (MSN) p. 113-20 (2022)","DOI":"10.1109\/MSN57253.2022.00031"},{"key":"9906_CR50","doi-asserted-by":"publisher","DOI":"10.1145\/3503463","author":"N Daoudi","year":"2022","unstructured":"Daoudi, N., Allix, K., Bissyand\u00e9, T.F., Klein, J.: A deep dive inside DREBIN: an explorative analysis beyond android malware detection scores. ACM Trans. Priv. Secur. (2022). https:\/\/doi.org\/10.1145\/3503463","journal-title":"ACM Trans. Priv. Secur."},{"key":"9906_CR51","doi-asserted-by":"crossref","unstructured":"Liu, F.T., Ting, K.M., Zhou, Z.H.: Isolation Forest. In: 2008 Eighth IEEE Int. Conf. on Data Mining. Pisa, Italy: IEEE p. 413-22 (2008)","DOI":"10.1109\/ICDM.2008.17"},{"key":"9906_CR52","doi-asserted-by":"publisher","first-page":"102613","DOI":"10.1016\/j.cose.2022.102613","volume":"115","author":"S Liu","year":"2022","unstructured":"Liu, S., Feng, P., Wang, S., Sun, K., Cao, J.: Enhancing malware analysis sandboxes with emulated user behavior. Comput. & Secur. 115, 102613 (2022)","journal-title":"Comput. & Secur."},{"issue":"1","key":"9906_CR53","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1007\/s10515-023-00378-w","volume":"30","author":"Y Cui","year":"2023","unstructured":"Cui, Y., Sun, Y., Lin, Z.: DroidHook: a novel API-hook based Android malware dynamic analysis sandbox. Autom. Softw. Eng. 30(1), 10 (2023)","journal-title":"Autom. Softw. Eng."},{"issue":"2","key":"9906_CR54","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/s10207-019-00447-w","volume":"19","author":"R Patil","year":"2020","unstructured":"Patil, R., Dudeja, H., Modi, C.: Designing in-VM-assisted lightweight agent-based malware detection framework for securing virtual machines in cloud computing. Int. J. Inf. Secur. 19(2), 147\u201362 (2020)","journal-title":"Int. J. Inf. Secur."},{"issue":"1","key":"9906_CR55","first-page":"3093","volume":"13","author":"S Aurangzeb","year":"2023","unstructured":"Aurangzeb, S., Aleem, M.: Evaluation and classification of obfuscated Android malware through deep learning using ensemble voting mechanism. Sci. Reports. 13(1), 3093 (2023)","journal-title":"Sci. Reports."},{"key":"9906_CR56","doi-asserted-by":"crossref","unstructured":"Arp, D., Spreitzenbarth, M., Hubner, M., Gascon, H., Rieck, K., Siemens, C. 2014 Drebin: Effective and explainable detection of android malware in your pocket. In: Ndss. 14, 23-6 (2014)","DOI":"10.14722\/ndss.2014.23247"},{"issue":"1","key":"9906_CR57","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/s11416-022-00432-3","volume":"19","author":"A Guerra-Manzanares","year":"2023","unstructured":"Guerra-Manzanares, A., Bahsi, H., Luckner, M.: Leveraging the first line of defense: a study on the evolution and usage of android security permissions for enhanced android malware detection. J. Comput. Virol. and Hacking Tech. 19(1), 65\u201396 (2023)","journal-title":"J. Comput. Virol. and Hacking Tech."},{"key":"9906_CR58","doi-asserted-by":"crossref","unstructured":"Gama, J., Sebastiao, R., Rodrigues, P.P.: Issues in evaluation of stream learning algorithms. In: Proc. of the 15th ACM SIGKDD international conference on Knowledge discovery and data mining 329-38 (2009)","DOI":"10.1145\/1557019.1557060"},{"key":"9906_CR59","unstructured":"Arp, D., Quiring, E., Pendlebury, F., Warnecke, A., Pierazzi, F., Wressnegger, C., et\u00a0al.: Dos and don\u2019ts of machine learning in computer security. In: 31st USENIX Security Symp. (USENIX Security 22) p. 3971-88 (2022)"},{"key":"9906_CR60","doi-asserted-by":"crossref","unstructured":"Chen, Z., Zhang, Z., Kan, Z., Yang, L., Cortellazzi, J., Pendlebury, F., et\u00a0al.: Is It Overkill? Analyzing Feature-Space Concept Drift in Malware Detectors. In: Proc. of The 6th Deep Learning Security and Privacy Workshop (DLSP), in conjunction with IEEE Symp. on Security and Privacy (IEEE SP). San Francisco, CA: IEEE (2023)","DOI":"10.1109\/SPW59333.2023.00007"},{"key":"9906_CR61","doi-asserted-by":"crossref","unstructured":"Street, W.N., Kim, Y.: A streaming ensemble algorithm (SEA) for large-scale classification. In: Proc. of the seventh ACM SIGKDD international conference on Knowledge discovery and data mining p. 377-82 (2001)","DOI":"10.1145\/502512.502568"},{"issue":"5","key":"9906_CR62","doi-asserted-by":"publisher","first-page":"730","DOI":"10.1109\/TKDE.2009.156","volume":"22","author":"LL Minku","year":"2009","unstructured":"Minku, L.L., White, A.P., Yao, X.: The impact of diversity on online ensemble learning in the presence of concept drift. IEEE Trans. knowl. and Data Eng. 22(5), 730\u201342 (2009)","journal-title":"IEEE Trans. knowl. and Data Eng."},{"key":"9906_CR63","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-26450-9_20","author":"P Faruki","year":"2016","unstructured":"Faruki, P., Bhandari, S., Laxmi, V., Gaur, M., Conti, M.: Droidanalyst: synergic app framework for static and dynamic app analysis. Recent Adv. Comput. Intell. Def. and Secur. (2016). https:\/\/doi.org\/10.1007\/978-3-319-26450-9_20","journal-title":"Recent Adv. Comput. Intell. Def. and Secur."},{"key":"9906_CR64","doi-asserted-by":"publisher","DOI":"10.1007\/s10586-024-04484-6","author":"AM AlSobeh","year":"2024","unstructured":"AlSobeh, A.M., Gaber, K., Hammad, M.M., Nuser, M., Shatnawi, A.: Android malware detection using time-aware machine learning approach. Clust. Comput. (2024). https:\/\/doi.org\/10.1007\/s10586-024-04484-6","journal-title":"Clust. Comput."},{"key":"9906_CR65","doi-asserted-by":"crossref","unstructured":"Singh, J., Singh, J.: Malware classification using multi-layer perceptron model. In: International Conference on Innovative Computing and Communications: Proceedings of ICICC 2020, Volume 2. Springer p. 155-68 (2021)","DOI":"10.1007\/978-981-15-5148-2_14"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-025-09906-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-025-09906-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-025-09906-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,18]],"date-time":"2025-04-18T11:49:19Z","timestamp":1744976959000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-025-09906-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,2,23]]},"references-count":65,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2025,4]]}},"alternative-id":["9906"],"URL":"https:\/\/doi.org\/10.1007\/s10922-025-09906-3","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,2,23]]},"assertion":[{"value":"5 June 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 November 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 January 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 February 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no Conflict of interest to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"36"}}