{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T16:17:08Z","timestamp":1783700228803,"version":"3.55.0"},"reference-count":89,"publisher":"Association for Computing Machinery (ACM)","issue":"7","license":[{"start":{"date-parts":[[2024,8,26]],"date-time":"2024-08-26T00:00:00Z","timestamp":1724630400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2024,9,30]]},"abstract":"<jats:p>\n            With the emergence of smartphones, Android has become a widely used mobile operating system. However, it is vulnerable when encountering various types of attacks. Every day, new malware threatens the security of users\u2019 devices and private data. Many methods have been proposed to classify malicious applications, utilizing static or dynamic analysis for classification. However, previous methods still suffer from unsatisfactory performance due to two challenges. First, they are unable to address the imbalanced data distribution problem, leading to poor performance for malware families with few members. Second, they are unable to address the zero-day malware (zero-day malware refers to malicious applications that exploit unknown vulnerabilities) classification problem. In this article, we introduce an innovative\n            <jats:bold>meta<\/jats:bold>\n            -learning approach for\n            <jats:bold>m<\/jats:bold>\n            ulti-family\n            <jats:bold>A<\/jats:bold>\n            ndroid\n            <jats:bold>m<\/jats:bold>\n            alware\n            <jats:bold>c<\/jats:bold>\n            lassification named\n            <jats:bold>Meta-MAMC<\/jats:bold>\n            , which uses meta-learning technology to learn meta-knowledge (i.e., the similarities and differences among different malware families) of few-family samples and combines new sampling algorithms to solve the above challenges.\n            <jats:monospace>Meta-MAMC<\/jats:monospace>\n            integrates (i) the meta-knowledge contained within the dataset to guide models in learning to identify unknown malware; and (ii) more accurate and diverse tasks based on novel sampling strategies, as well as directly adapting meta-learning to a new few-sample and zero-sample task to classify families. We have evaluated\n            <jats:monospace>Meta-MAMC<\/jats:monospace>\n            on two popular datasets and a corpus of real-world Android applications. The results demonstrate its efficacy in accurately classifying malicious applications belonging to certain malware families, even achieving 100% classification in some families.\n          <\/jats:p>","DOI":"10.1145\/3664806","type":"journal-article","created":{"date-parts":[[2024,5,13]],"date-time":"2024-05-13T11:34:28Z","timestamp":1715600068000},"page":"1-27","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["Meta-Learning for Multi-Family Android Malware Classification"],"prefix":"10.1145","volume":"33","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0474-0159","authenticated-orcid":false,"given":"Yao","family":"Li","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Macau University of Science and Technology, Taipa, Macao"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9469-5864","authenticated-orcid":false,"given":"Dawei","family":"Yuan","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Macau University of Science and Technology, Taipa, Macao"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6272-4069","authenticated-orcid":false,"given":"Tao","family":"Zhang","sequence":"additional","affiliation":[{"name":"Macau University of Science and Technology, Taipa, Macao"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5224-9970","authenticated-orcid":false,"given":"Haipeng","family":"Cai","sequence":"additional","affiliation":[{"name":"Washington State University, Pullman, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4367-7201","authenticated-orcid":false,"given":"David","family":"Lo","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4774-2434","authenticated-orcid":false,"given":"Cuiyun","family":"Gao","sequence":"additional","affiliation":[{"name":"Harbin Institute of Technology Shenzhen, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9082-3208","authenticated-orcid":false,"given":"Xiapu","family":"Luo","sequence":"additional","affiliation":[{"name":"Department of Computing, The Hong Kong Polytechnic University, Kowloon, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8674-4948","authenticated-orcid":false,"given":"He","family":"Jiang","sequence":"additional","affiliation":[{"name":"School of Software, Dalian University of Technology, Dalian China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,8,26]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2020.02.002"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-13278-0_39"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/2901739.2903508"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23247"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382222"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1723"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-020-05195-w"},{"key":"e_1_3_2_9_2","volume-title":"G DATA Mobile Malware Report: Harmful Android Apps Every Eight Seconds","author":"Beckert-Plewka Kathrin","year":"2020","unstructured":"Kathrin Beckert-Plewka, Hauke Gierow, Vera Haake, and Stefan Karpenstein. 2020. G DATA Mobile Malware Report: Harmful Android Apps Every Eight Seconds. Retrieved from https:\/\/www.gdatasoftware.com\/news\/1970\/01\/-36401-g-data-mobile-malware-report-harmful-android-apps-every-eight-seconds"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/3371924"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2017.2739145"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1613\/jair.953"},{"key":"e_1_3_2_13_2","volume-title":"Mobile Malware Evolution 2020","author":"Chebyshev Victor","year":"2021","unstructured":"Victor Chebyshev. 2021. Mobile Malware Evolution 2020. Kaspersky. Retrieved from https:\/\/securelist.com\/mobile-malware-evolution-2020\/101029\/"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939785"},{"key":"e_1_3_2_15_2","volume-title":"Convolutional Neural Network for Sentence Classification","author":"Chen Yahui","year":"2015","unstructured":"Yahui Chen. 2015. Convolutional Neural Network for Sentence Classification. Master\u2019s Thesis. University of Waterloo. https:\/\/core.ac.uk\/reader\/144148500"},{"key":"e_1_3_2_16_2","volume-title":"Androguard, a Full Python Tool to Play with Android Files","author":"Desnos Anthony","year":"2023","unstructured":"Anthony Desnos. 2023. Androguard, a Full Python Tool to Play with Android Files. Retrieved from https:\/\/github.com\/androguard\/androguard"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1007\/s12652-020-01957-5"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2022.3143439"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2806891"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICECCS.2019.00014"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635869"},{"key":"e_1_3_2_22_2","doi-asserted-by":"crossref","unstructured":"Yu Feng Osbert Bastani Ruben Martins Isil Dillig and Saswat Anand. 2017. Automated synthesis of semantic malware signatures using maximum satisfiability. Network and Distributed System Security Symposium (NDSS\u201917). 1\u201316.","DOI":"10.14722\/ndss.2017.23379"},{"key":"e_1_3_2_23_2","first-page":"1126","volume-title":"34th International Conference on Machine Learning","author":"Finn Chelsea","year":"2017","unstructured":"Chelsea Finn, Pieter Abbeel, and Sergey Levine. 2017. Model-agnostic meta-learning for fast adaptation of deep networks. In 34th International Conference on Machine Learning. 1126\u20131135."},{"key":"e_1_3_2_24_2","volume-title":"VirusShare","author":"Forensics Corvus","year":"2023","unstructured":"Corvus Forensics. 2023. VirusShare. Retrieved from https:\/\/virusshare.com"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102264"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1975.10479865"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/2307636.2307663"},{"key":"e_1_3_2_28_2","first-page":"5149","article-title":"Meta-learning in neural networks: A survey","volume":"44","author":"Hospedales Timothy","year":"2022","unstructured":"Timothy Hospedales, Antreas Antoniou, Paul Micaelli, and Amos Storkey. 2022. Meta-learning in neural networks: A survey. IEEE Trans. Pattern Anal. Mach. Intell. 44 (2022), 5149\u20135169.","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"e_1_3_2_29_2","volume-title":"International Conference on Neural Information Processing Systems","author":"Jeong Taewon","year":"2020","unstructured":"Taewon Jeong and Heeyoung Kim. 2020. OOD-MAML: Meta-learning for few-shot out-of-distribution detection and classification. In International Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC47284.2019.8969656"},{"key":"e_1_3_2_31_2","first-page":"625","volume-title":"USENIX Security Symposium","author":"Jordaney Roberto","year":"2017","unstructured":"Roberto Jordaney, Kumar Sharad, Santanu K. Dash, Zhi Wang, Davide Papini, Ilia Nouretdinov, and Lorenzo Cavallaro. 2017. Transcend: Detecting concept drift in malware classification models. In USENIX Security Symposium. 625\u2013642."},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3055635.3056643"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecPODS.2016.7502343"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2866319"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102086"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2021.3051354"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-08760-8_33"},{"key":"e_1_3_2_38_2","article-title":"Ensemble framework combining family information for Android malware detection","author":"Li Yao","year":"2022","unstructured":"Yao Li, Zhi Xiong, Tao Zhang, Qinkun Zhang, Ming Fan, and Lei Xue. 2022. Ensemble framework combining family information for Android malware detection. Comput. J. 66, 11 (2022).","journal-title":"Comput. J."},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2020.2993293"},{"key":"e_1_3_2_40_2","first-page":"4061","volume-title":"36th International Conference on Machine Learning","author":"Liu Hao","year":"2019","unstructured":"Hao Liu, Richard Socher, and Caiming Xiong. 2019. Taming MAML: Efficient unbiased meta-reinforcement learning. In 36th International Conference on Machine Learning. 4061\u20134071."},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-020-00489-5"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2021.02.015"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/APSEC51365.2020.00027"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2896003"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10922-021-09634-4"},{"key":"e_1_3_2_46_2","unstructured":"Hadi Mansourifar and Weidong Shi. 2020. Deep synthetic minority over-sampling technique. arXiv preprint arXiv:2003.09788 (2020)."},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3313391"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2018.06.006"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.3390\/info11060326"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897856"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICICS49469.2020.239556"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","unstructured":"Van L. Parsons. 2017. Stratified sampling. Wiley StatsRef: Statistics Reference Online 1\u201311. DOI:10.1002\/9781118445112.stat05999.pub2","DOI":"10.1002\/9781118445112.stat05999.pub2"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.3390\/app10144966"},{"key":"e_1_3_2_54_2","volume-title":"Android - Statistics & Facts","author":"O\u2019Dea S.","year":"2020","unstructured":"S. O\u2019Dea. 2020. Android - Statistics & Facts. Statista. Retrieved from https:\/\/www.statista.com\/topics\/876\/android\/"},{"key":"e_1_3_2_55_2","first-page":"1","article-title":"Stratified sampling","author":"Parsons Van L.","year":"2014","unstructured":"Van L. Parsons. 2014. Stratified sampling. Wiley StatsRef: Stat. Refer. Online (2014), 1\u201311.","journal-title":"Wiley StatsRef: Stat. Refer. Online"},{"key":"e_1_3_2_56_2","volume-title":"VIRUSTOTAL","author":"products Antivirus","year":"2023","unstructured":"Antivirus products. 2023. VIRUSTOTAL. Retrieved from https:\/\/www.virustotal.com"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/TENCON.2019.8929620"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.3390\/sym12050858"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2016.2536605"},{"key":"e_1_3_2_60_2","doi-asserted-by":"crossref","unstructured":"Marcos Sebasti\u00e1n Richard Rivera Platon Kotzias and Juan Caballero. 2016. AVclass: A tool for massive malware labeling. Research in Attacks Intrusions and Defenses: 19th International Symposium (RAID\u201916) Vol. 9854. 230\u2013253.","DOI":"10.1007\/978-3-319-45719-2_11"},{"key":"e_1_3_2_61_2","volume-title":"Malware Datasets from 2021 to 2022","year":"2023","unstructured":"sk3ptre. 2023. Malware Datasets from 2021 to 2022. Retrieved from https:\/\/github.com\/sk3ptre"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2982635"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2013.07.106"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2020.2982537"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-020-04831-9"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2017.2778147"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4615-5529-2_1"},{"key":"e_1_3_2_68_2","volume-title":"APKtool","author":"Tumbleson Connor","year":"2023","unstructured":"Connor Tumbleson and RyszardWi\u015bniewski. 2023. APKtool. Retrieved from https:\/\/ibotpeaches.github.io\/Apktool\/"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.micpro.2020.103115"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/2591971.2592003"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3379530"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2018.11.021"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102273"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_12"},{"key":"e_1_3_2_75_2","doi-asserted-by":"crossref","unstructured":"Jason Wei and Kai Zou. 2019. EDA: Easy data augmentation techniques for boosting performance on text classification tasks. arXiv preprint arXiv:1901.11196 (2019).","DOI":"10.18653\/v1\/D19-1670"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11704-017-6493-y"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2019.00014"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-02450-5_11"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/TASE.2019.00-20"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1201\/9781420089653.ch3"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2017.40"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3124725"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2018.2886875"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24177-7_15"},{"key":"e_1_3_2_85_2","first-page":"411","volume-title":"International Conference on Network and System Security","author":"Zhi X.","year":"2018","unstructured":"X. Zhi, T. Guo, Q. Zhang, C. Yu, and X. Kai. 2018. Android malware detection methods based on the combination of clustering and classification. In International Conference on Network and System Security. 411\u2013422."},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-018-6498-z"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2020.2996379"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-017-2914-y"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.3390\/fi15060214"},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102691"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664806","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3664806","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:17:29Z","timestamp":1750295849000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3664806"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,8,26]]},"references-count":89,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2024,9,30]]}},"alternative-id":["10.1145\/3664806"],"URL":"https:\/\/doi.org\/10.1145\/3664806","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,8,26]]},"assertion":[{"value":"2023-07-03","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-05-04","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-08-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}