{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,8]],"date-time":"2025-11-08T22:58:30Z","timestamp":1762642710433,"version":"3.40.5"},"reference-count":59,"publisher":"Wiley","license":[{"start":{"date-parts":[[2022,6,13]],"date-time":"2022-06-13T00:00:00Z","timestamp":1655078400000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Applied Computational Intelligence and Soft Computing"],"published-print":{"date-parts":[[2022,6,13]]},"abstract":"<jats:p>With the extensive use of Android applications, malware growth has been increasing drastically. The high popularity of Android devices has motivated malware developers to attack these devices. In recent times, most researchers and scholars have used deep learning approaches to detect Android malware. Although deep learning techniques provide good accuracy and efficiency, they require high computational cost to train huge and complex data sets. Hence, there is a need for an approach that can efficiently detect novel malware variants with a minimum computational cost. This paper proposes a novel framework for detecting and clustering Android malware using the transfer learning and the topic modelling approach. The transfer learning approach minimizes new training data by transferring well-known features from a qualified source model to a destination model, and hence, a high amount of computational power is not required. In addition, the proposed framework clusters the detected malware variants into their corresponding families with the help of Latent Dirichlet Allocation and hierarchical clustering techniques. For performance assessment, we performed several experiments with more than 50K Android application samples. In addition, we compared the performance of our framework with that of similar existing traditional machine learning and deep learning models. The proposed framework provides better accuracy of 98.3% during the classification stage by using the transfer learning approach as compared to other state-of-the-art Android malware detection techniques. The high precision value of 98.7% is obtained during the clustering stage while grouping the obtained malicious applications into their corresponding malware families.<\/jats:p>","DOI":"10.1155\/2022\/4119500","type":"journal-article","created":{"date-parts":[[2022,6,13]],"date-time":"2022-06-13T23:05:34Z","timestamp":1655161534000},"page":"1-22","source":"Crossref","is-referenced-by-count":6,"title":["A Low Computational Cost Method for Mobile Malware Detection Using Transfer Learning and Familial Classification Using Topic Modelling"],"prefix":"10.1155","volume":"2022","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3073-1926","authenticated-orcid":true,"given":"Saket","family":"Acharya","sequence":"first","affiliation":[{"name":"Department of Computer Science and Engineering, Manipal University Jaipur, Jaipur, Rajasthan, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1293-1836","authenticated-orcid":true,"given":"Umashankar","family":"Rawat","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Manipal University Jaipur, Jaipur, Rajasthan, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9098-3378","authenticated-orcid":true,"given":"Roheet","family":"Bhatnagar","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Manipal University Jaipur, Jaipur, Rajasthan, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"311","reference":[{"first-page":"1","article-title":"Understanding of a convolutional neural network","author":"S. Albawi","key":"1"},{"key":"2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23247"},{"key":"3","doi-asserted-by":"publisher","DOI":"10.1007\/s00500-014-1511-6"},{"key":"4","doi-asserted-by":"publisher","DOI":"10.1109\/comst.2014.2386139"},{"key":"5","doi-asserted-by":"publisher","DOI":"10.5220\/0006256706530662"},{"first-page":"500","article-title":"Android app behaviour classification using topic modeling techniques and outlier detection using app permissions","author":"M. Garg","key":"6"},{"key":"7","doi-asserted-by":"publisher","DOI":"10.1109\/access.2020.3022722"},{"key":"8","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23118"},{"first-page":"1","article-title":"Malware detection in android based on dynamic analysis","author":"T. Bhatia","key":"9"},{"key":"10","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2019.102423"},{"key":"11","doi-asserted-by":"publisher","DOI":"10.1016\/j.diin.2018.01.007"},{"key":"12","doi-asserted-by":"publisher","DOI":"10.1109\/tst.2016.7399288"},{"first-page":"11104","article-title":"A review of object detection based on convolutional neural network","author":"W. Zhiqiang","key":"13"},{"author":"T. Mu","key":"14","article-title":"An android malware detection method using deep learning based on api calls"},{"key":"15","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"16","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2018.2866319"},{"first-page":"5789","article-title":"Droid-nnet: deep learning neural network for android malware detection","author":"M. Masum","key":"17"},{"key":"18","doi-asserted-by":"publisher","DOI":"10.1109\/tsusc.2018.2809665"},{"key":"19","doi-asserted-by":"publisher","DOI":"10.1109\/access.2020.3008081"},{"key":"20","doi-asserted-by":"publisher","DOI":"10.1109\/access.2019.2951751"},{"first-page":"140","article-title":"Tuning deep learning performance for android malware detection","author":"J. Booz","key":"21"},{"key":"22","doi-asserted-by":"publisher","DOI":"10.1109\/access.2021.3090998"},{"key":"23","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2021.107234"},{"key":"24","doi-asserted-by":"publisher","DOI":"10.1109\/tc.2021.3082002"},{"key":"25","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2018.2879302"},{"first-page":"309","article-title":"Droidsieve: fast and accurate classification of obfuscated android malware","author":"G. Suarez-Tangil","key":"26"},{"article-title":"Eight years of rider measurement in the android malware ecosystem: evolution and lessons learned","year":"2018","author":"G. Suarez-Tangil","key":"27"},{"first-page":"31","article-title":"Embracing mobile app evolution via continuous ecosystem mining and characterization","author":"H. Cai","key":"28"},{"key":"29","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2020.106291"},{"key":"30","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2020.2975176"},{"first-page":"272","article-title":"On the deterioration of learning-based malware detectors for android","author":"X. Fu","key":"31"},{"first-page":"47","article-title":"Droidevolver: self-evolving android malware detection system","author":"K. Xu","key":"32"},{"article-title":"Mamadroid: detecting android malware by building Markov chains of behavioral models","year":"2016","author":"E. Mariconti","key":"33"},{"key":"34","doi-asserted-by":"publisher","DOI":"10.1145\/3371924"},{"first-page":"350","article-title":"Towards sustainable android malware detection","author":"H. Cai","key":"35"},{"first-page":"1","article-title":"Anastasia: android malware detection using static analysis of applications","author":"H. Fereidooni","key":"36"},{"article-title":"Andlantis: large-scale android dynamic analysis","year":"2014","author":"M. Bierma","key":"37"},{"key":"38","doi-asserted-by":"publisher","DOI":"10.3390\/s20247013"},{"key":"39","doi-asserted-by":"publisher","DOI":"10.1109\/access.2021.3063748"},{"key":"40","doi-asserted-by":"publisher","DOI":"10.1109\/access.2020.3006143"},{"key":"41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63095-9_14"},{"key":"42","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-016-0043-6"},{"first-page":"265","article-title":"Tensorflow: a system for large-scale machine learning","author":"M. Abadi","key":"43"},{"key":"44","first-page":"8026","article-title":"Pytorch: an imperative style, high-performance deep learning library","volume":"32","author":"A. Paszke","year":"2019","journal-title":"Advances in Neural Information Processing Systems"},{"key":"45","doi-asserted-by":"publisher","DOI":"10.1007\/s11042-017-5104-0"},{"first-page":"30","article-title":"Tfdroid: android malware detection by topics and sensitive data flows using machine learning techniques","author":"S. Lou","key":"46"},{"key":"47","doi-asserted-by":"publisher","DOI":"10.1016\/j.jpdc.2018.03.006"},{"key":"48","doi-asserted-by":"publisher","DOI":"10.3390\/electronics11050672"},{"first-page":"252","article-title":"Droidscribe: classifying android malware based on runtime behavior","author":"S. K. Dash","key":"49"},{"key":"50","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101663"},{"article-title":"A preliminary study on the sustainability of android malware detection","year":"2018","author":"H. Cai","key":"51"},{"key":"52","first-page":"993","article-title":"Latent dirichlet allocation","volume":"3","author":"D. M. Blei","year":"2003","journal-title":"The Journal of Machine Learning Research"},{"volume-title":"Clustering and Topic Modelling: A New Approach for Analysis of National Cyber Security Strategies","year":"2017","author":"F. Kolini","key":"53"},{"key":"54","doi-asserted-by":"publisher","DOI":"10.1109\/access.2020.2994516"},{"volume-title":"Machine Learning with SVM and Other Kernel Methods","year":"2009","author":"K. Soman","key":"55"},{"key":"56","doi-asserted-by":"publisher","DOI":"10.1186\/1471-2105-8-s7-s18"},{"key":"57","doi-asserted-by":"publisher","DOI":"10.1016\/j.jksuci.2018.07.004"},{"issue":"3","key":"58","first-page":"230","article-title":"An improved knn text classification algorithm based on clustering","volume":"4","author":"Z. Yong","year":"2009","journal-title":"Journal of Computers"},{"key":"59","doi-asserted-by":"publisher","DOI":"10.1016\/j.ipl.2007.07.002"}],"container-title":["Applied Computational Intelligence and Soft Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/acisc\/2022\/4119500.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/acisc\/2022\/4119500.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/acisc\/2022\/4119500.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,13]],"date-time":"2022-06-13T23:05:43Z","timestamp":1655161543000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.hindawi.com\/journals\/acisc\/2022\/4119500\/"}},"subtitle":[],"editor":[{"given":"Shyi-Ming","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2022,6,13]]},"references-count":59,"alternative-id":["4119500","4119500"],"URL":"https:\/\/doi.org\/10.1155\/2022\/4119500","relation":{},"ISSN":["1687-9732","1687-9724"],"issn-type":[{"type":"electronic","value":"1687-9732"},{"type":"print","value":"1687-9724"}],"subject":[],"published":{"date-parts":[[2022,6,13]]}}}