{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,18]],"date-time":"2026-04-18T13:33:41Z","timestamp":1776519221353,"version":"3.51.2"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"12","license":[{"start":{"date-parts":[[2024,5,18]],"date-time":"2024-05-18T00:00:00Z","timestamp":1715990400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,5,18]],"date-time":"2024-05-18T00:00:00Z","timestamp":1715990400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/100024206","name":"Sivas University of Science and Technology","doi-asserted-by":"crossref","id":[{"id":"10.13039\/100024206","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Multimed Tools Appl"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>In this work, VoteDroid a novel fine-tuned deep learning models-based ensemble voting classifier has been proposed for detecting malicious behavior in Android applications. To this end, we proposed adopting the random search optimization algorithm for deciding the structure of the models used as voter classifiers in the ensemble classifier. We specified the potential components that can be used in each model and left the random search algorithm taking a decision about the structure of the model including the number of each component that should be used and its location in the structure. This optimization method has been used to build three different deep learning models namely CNN-ANN, pure CNN, and pure ANN. After selecting the best structure for each DL model, the selected three models have been trained and tested using the constructed image dataset. Afterward, we suggested hybridizing the fine-tuned three deep-learning models to form one ensemble voting classifier with two different working modes namely MMR (Malware Minority Rule) and LMR (Label Majority Rule). To our knowledge, this is the first time that an ensemble classifier has been fine-tuned and hybridized in this way for malware detection. The results showed that the proposed models were promising, where the classification accuracy exceeded 97% in all experiments.<\/jats:p>","DOI":"10.1007\/s11042-024-19390-7","type":"journal-article","created":{"date-parts":[[2024,5,18]],"date-time":"2024-05-18T05:02:08Z","timestamp":1716008528000},"page":"10923-10944","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":14,"title":["VoteDroid: a new ensemble voting classifier for malware detection based on fine-tuned deep learning models"],"prefix":"10.1007","volume":"84","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3327-2822","authenticated-orcid":false,"given":"Halit","family":"Bak\u0131r","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,5,18]]},"reference":[{"key":"19390_CR1","unstructured":"Check Point (2021) Mobile Security Report 2021\/ Almost every organization experienced a mobile-related attack in 2020.\u00a0https:\/\/pages.checkpoint.com\/mobile-security-report-2021.html"},{"key":"19390_CR2","unstructured":"Kathrin B-P, Vera H, Stefan K (2021) G DATA mobile malware report: criminals keep up the pace with android malware.\u00a0https:\/\/www.gdatasoftware.com\/news\/2021\/10\/37093-g-data-mobile-malware-report-criminals-keep-up-the-pace-with-android-malware. Accessed 16 May 2024"},{"key":"19390_CR3","unstructured":"David C (2024) Android Statistics (2024). https:\/\/www.businessofapps.com\/data\/android-statistics\/"},{"key":"19390_CR4","unstructured":"Tatyana S, Anton K (2021) Mobile malware evolution 2021. https:\/\/securelist.com\/mobile-malware-evolution-2021\/105876\/. Accessed 16 May 2024"},{"key":"19390_CR5","unstructured":"Julia G Mobile threats: who targeted smartphones in 2021. Kaspersky.\u00a0https:\/\/www.kaspersky.com\/blog\/mobile-malware-2021\/43996\/. Accessed 16 May 2024"},{"key":"19390_CR6","unstructured":"Eduard K Mobile malware attacks dropped in 2021 but sophistication increased. Security Week Network.\u00a0https:\/\/www.securityweek.com\/mobile-malware-attacks-dropped-2021-sophistication-increased\/. Accessed 16 May 2024"},{"key":"19390_CR7","unstructured":"Cedric P (2022) 2021 mobile malware evolution: fewer attacks, escalating dangers. https:\/\/www.techrepublic.com\/article\/2021-mobile-malware-evolution-fewer-attacks-escalating-dangers\/.\u00a0Accessed 16 May 2024"},{"issue":"11","key":"19390_CR8","doi-asserted-by":"publisher","first-page":"9333","DOI":"10.1007\/s13369-019-04081-5","volume":"44","author":"K Bakour","year":"2019","unstructured":"Bakour K, \u00dcnver HM, Ghanem R (2019) A deep camouflage: evaluating android\u2019s anti-malware systems robustness against hybridization of obfuscation techniques with injection attacks. Arab J Sci Eng 44(11):9333\u20139347","journal-title":"Arab J Sci Eng"},{"key":"19390_CR9","doi-asserted-by":"publisher","first-page":"4527","DOI":"10.1109\/TIP.2022.3184250","volume":"31","author":"Z Wang","year":"2022","unstructured":"Wang Z, Li X, Duan H, Zhang X (2022) A self-supervised residual feature learning model for multifocus image fusion. IEEE Trans Image Process 31:4527\u20134542","journal-title":"IEEE Trans Image Process"},{"key":"19390_CR10","doi-asserted-by":"publisher","unstructured":"Duan H, Long Y, Wang S, Zhang H, Willcocks CG, Shao L (2023) Dynamic unary convolution in transformers. IEEE Trans Pattern Anal Mach Intell 45(11):12747\u201312759. https:\/\/doi.org\/10.1109\/TPAMI.2022.3233482","DOI":"10.1109\/TPAMI.2022.3233482"},{"key":"19390_CR11","doi-asserted-by":"publisher","unstructured":"Shao Z, Han J, Debattista K, Pang Y (2023) Textual context-aware dense captioning with diverse words. IEEE Trans Multimedia 25:8753\u20138766. https:\/\/doi.org\/10.1109\/TMM.2023.3241517","DOI":"10.1109\/TMM.2023.3241517"},{"key":"19390_CR12","doi-asserted-by":"publisher","unstructured":"Shao Z, Han J, Debattista K, Pang Y (2024) DCMSTRD: end-to-end dense captioning via multi-scale transformer decoding. IEEE Trans Multimedia 26:7581\u20137593. https:\/\/doi.org\/10.1109\/TMM.2024.3369863","DOI":"10.1109\/TMM.2024.3369863"},{"key":"19390_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.114574","volume":"171","author":"Z Wang","year":"2021","unstructured":"Wang Z, Li X, Duan H, Su Y, Zhang X, Guan X (2021) Medical image fusion based on convolutional neural networks and non-subsampled contourlet transform. Expert Syst Appl 171","journal-title":"Expert Syst Appl"},{"issue":"7","key":"19390_CR14","first-page":"3688","volume":"44","author":"Y Liu","year":"2021","unstructured":"Liu Y, Zhang D, Zhang Q, Han J (2021) Part-object relational visual saliency. IEEE Trans Pattern Anal Mach Intell 44(7):3688\u20133704","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"19390_CR15","doi-asserted-by":"publisher","unstructured":"Shao Z, Han J, Marnerides D, Debattista K (2022) Region-object relation-aware dense captioning via transformer. IEEE Trans Neural Netw Learn Syst. https:\/\/doi.org\/10.1109\/TNNLS.2022.3152990","DOI":"10.1109\/TNNLS.2022.3152990"},{"issue":"9","key":"19390_CR16","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s42452-019-1124-x","volume":"1","author":"K Bakour","year":"2019","unstructured":"Bakour K, \u00dcnver HM, Ghanem R (2019) The android malware detection systems between hope and reality. SN Appl Sci 1(9):1\u201342","journal-title":"SN Appl Sci"},{"key":"19390_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101663","volume":"89","author":"MK Alzaylaee","year":"2020","unstructured":"Alzaylaee MK, Yerima SY, Sezer S (2020) DL-Droid: deep learning based android malware detection using real devices. Comput Secur 89","journal-title":"Comput Secur"},{"issue":"3","key":"19390_CR18","doi-asserted-by":"publisher","first-page":"773","DOI":"10.1109\/TIFS.2018.2866319","volume":"14","author":"T Kim","year":"2018","unstructured":"Kim T, Kang B, Rho M, Sezer S, Im EG (2018) A multimodal deep learning method for android malware detection using various features. IEEE Trans Inf Forensics Secur 14(3):773\u2013788","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"19390_CR19","doi-asserted-by":"publisher","first-page":"S48","DOI":"10.1016\/j.diin.2018.01.007","volume":"24","author":"EB Karbab","year":"2018","unstructured":"Karbab EB, Debbabi M, Derhab A, Mouheb D (2018) MalDozer: automatic framework for android malware detection using deep learning. Digit Investig 24:S48\u2013S59","journal-title":"Digit Investig"},{"issue":"6","key":"19390_CR20","doi-asserted-by":"publisher","first-page":"1455","DOI":"10.1109\/TIFS.2018.2879302","volume":"14","author":"H Cai","year":"2018","unstructured":"Cai H, Meng N, Ryder B, Yao D (2018) Droidcat: effective android malware detection and categorization via app-level profiling. IEEE Trans Inf Forensics Secur 14(6):1455\u20131470","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"19390_CR21","doi-asserted-by":"crossref","unstructured":"Rana M, Rahman SSMM, Sung AH (2018) Evaluation of tree based machine learning classifiers for android malware detection. In: International Conference on Computational Collective Intelligence, Springer, pp 377\u2013385","DOI":"10.1007\/978-3-319-98446-9_35"},{"key":"19390_CR22","doi-asserted-by":"crossref","unstructured":"T\u00fcrker S, Can AB (2019) Andmfc: android malware family classification framework. In 2019 IEEE 30th International Symposium on Personal, Indoor and Mobile Radio Communications (PIMRC Workshops), IEE, pp 1\u20136","DOI":"10.1109\/PIMRCW.2019.8880840"},{"key":"19390_CR23","doi-asserted-by":"crossref","unstructured":"Keyes DS, Li B, Kaur G, Lashkari AH, Gagnon F, Massicotte F (2021) EntropLyzer: Android Malware classification and characterization using Entropy Analysis of dynamic characteristics. In: 2021 Reconciling Data Analytics, Automation, Privacy, and Security: A Big Data Challenge (RDAAPS). IEEE, pp 1\u201312","DOI":"10.1109\/RDAAPS48126.2021.9452002"},{"key":"19390_CR24","doi-asserted-by":"publisher","first-page":"844","DOI":"10.1016\/j.future.2020.10.008","volume":"115","author":"SI Imtiaz","year":"2021","unstructured":"Imtiaz SI, ur Rehman S, Javed AR, Jalil Z, Liu X, Alnumay WS (2021) DeepAMD: detection and identification of Android malware using high-efficient deep artificial neural network. Future Gener Comput Syst 115:844\u2013856","journal-title":"Future Gener Comput Syst"},{"key":"19390_CR25","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102264","volume":"106","author":"H Gao","year":"2021","unstructured":"Gao H, Cheng S, Zhang W (2021) GDroid: android malware detection and classification with graph convolutional network. Comput Secur 106","journal-title":"Comput Secur"},{"issue":"8","key":"19390_CR26","doi-asserted-by":"publisher","first-page":"3133","DOI":"10.1007\/s00521-020-05195-w","volume":"33","author":"K Bakour","year":"2021","unstructured":"Bakour K, \u00dcnver HM (2021) VisDroid: android malware classification based on local and global image features, bag of visual words and machine learning techniques. Neural Comput Appl 33(8):3133\u20133153","journal-title":"Neural Comput Appl"},{"issue":"7","key":"19390_CR27","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s42452-020-3132-2","volume":"2","author":"HM \u00dcnver","year":"2020","unstructured":"\u00dcnver HM, Bakour K (2020) Android malware detection based on image-based features and machine learning techniques. SN Appl Sci 2(7):1\u201315","journal-title":"SN Appl Sci"},{"issue":"18","key":"19390_CR28","doi-asserted-by":"publisher","first-page":"11499","DOI":"10.1007\/s00521-021-05816-y","volume":"33","author":"K Bakour","year":"2021","unstructured":"Bakour K, \u00dcnver HM (2021) DeepVisDroid: android malware detection by hybridizing image-based features with deep learning techniques. Neural Comput Appl 33(18):11499\u201311516","journal-title":"Neural Comput Appl"},{"key":"19390_CR29","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2023.108804","volume":"110","author":"H Bak\u0131r","year":"2023","unstructured":"Bak\u0131r H, Bak\u0131r R (2023) DroidEncoder: malware detection using auto-encoder based feature extractor and machine learning algorithms. Comput Electr Eng 110","journal-title":"Comput Electr Eng"},{"key":"19390_CR30","unstructured":"Yilmaz EK, Bakir H (2023) Hyperparameter tunning and feature selection methods for malware detection. Politeknik Dergisi, p\u00a01-1"},{"key":"19390_CR31","doi-asserted-by":"publisher","unstructured":"Bak\u0131r H, Ceviz \u00d6 (2024) Empirical enhancement of intrusion detection systems: a comprehensive approach with genetic algorithm-based hyperparameter tuning and hybrid feature selection. Arab J Sci Eng.\u00a0https:\/\/doi.org\/10.1007\/s13369-024-08949-z","DOI":"10.1007\/s13369-024-08949-z"},{"key":"19390_CR32","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s42452-020-03374-x","volume":"2","author":"R Ghanem","year":"2020","unstructured":"Ghanem R, Erbay H (2020) Context-dependent model for spam detection on social networks. SN Appl Sci 2:1\u20138","journal-title":"SN Appl Sci"},{"issue":"3","key":"19390_CR33","doi-asserted-by":"publisher","first-page":"3697","DOI":"10.1007\/s11042-022-13397-8","volume":"82","author":"R Ghanem","year":"2023","unstructured":"Ghanem R, Erbay H (2023) Spam detection on social networks using deep contextualized word representation. Multimed Tools Appl 82(3):3697\u20133712","journal-title":"Multimed Tools Appl"},{"key":"19390_CR34","doi-asserted-by":"publisher","unstructured":"Demircio\u011flu U, Bak\u0131r H (2024) Artificial intelligence-based position control: reinforcement learning approach in spring mass damper systems. Phys Scr\u00a099(4):046003.\u00a0https:\/\/doi.org\/10.1088\/1402-4896\/ad2e57","DOI":"10.1088\/1402-4896\/ad2e57"},{"issue":"6","key":"19390_CR35","doi-asserted-by":"publisher","first-page":"17601","DOI":"10.1007\/s11042-023-16200-4","volume":"83","author":"H Bak\u0131r","year":"2024","unstructured":"Bak\u0131r H, \u00c7ay\u0131r AN, Navruz TS (2024) A comprehensive experimental study for analyzing the effects of data augmentation techniques on voice classification. Multimed Tools Appl 83(6):17601\u201317628","journal-title":"Multimed Tools Appl"},{"key":"19390_CR36","doi-asserted-by":"publisher","unstructured":"Bak\u0131r H (2024) Evaluating the impact of tuned pre-trained architectures\u2019 feature maps on deep learning model performance for tomato disease detection. Multimed Tools Appl\u00a083:18147\u201318168.\u00a0https:\/\/doi.org\/10.1007\/s11042-023-17503-2","DOI":"10.1007\/s11042-023-17503-2"},{"key":"19390_CR37","doi-asserted-by":"crossref","unstructured":"Demircio\u011flu U, Sayil A, Bak\u0131r H (2024) Detecting cutout shape and predicting its location in sandwich structures using free vibration analysis and tuned machine-learning algorithms. Arab J Sci Eng\u00a049(2):1611\u20131624","DOI":"10.1007\/s13369-023-07917-3"},{"key":"19390_CR38","doi-asserted-by":"crossref","unstructured":"Demircio\u011flu U, Bak\u0131r H, \u00c7ak\u0131r MT (2024) Machine learning analysis of data obtained by finite element method: a new approach in structural design. Phys Scr 99(3):036004","DOI":"10.1088\/1402-4896\/ad23bb"},{"key":"19390_CR39","doi-asserted-by":"crossref","unstructured":"Arp D, Spreitzenbarth M, Hubner M, Gascon H, Rieck K, Siemens CERT (2014) Drebin: effective and explainable detection of android malware in your pocket. In Ndss 14:23\u201326","DOI":"10.14722\/ndss.2014.23247"},{"key":"19390_CR40","doi-asserted-by":"crossref","unstructured":"Zhou Y, Jiang X (2012) Dissecting android malware: characterization and evolution. In: 2012 IEEE Symposium on Security and Privacy, IEEE, pp 95\u2013109","DOI":"10.1109\/SP.2012.16"}],"container-title":["Multimedia Tools and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-024-19390-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11042-024-19390-7\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-024-19390-7.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T05:05:09Z","timestamp":1746075909000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11042-024-19390-7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,5,18]]},"references-count":40,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2025,4]]}},"alternative-id":["19390"],"URL":"https:\/\/doi.org\/10.1007\/s11042-024-19390-7","relation":{},"ISSN":["1573-7721"],"issn-type":[{"value":"1573-7721","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,5,18]]},"assertion":[{"value":"23 November 2023","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 May 2024","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 May 2024","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"18 May 2024","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}]}}