{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T11:13:47Z","timestamp":1784546027720,"version":"3.55.0"},"reference-count":51,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,9,16]],"date-time":"2025-09-16T00:00:00Z","timestamp":1757980800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,9,16]],"date-time":"2025-09-16T00:00:00Z","timestamp":1757980800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of Chin","doi-asserted-by":"crossref","award":["62106223"],"award-info":[{"award-number":["62106223"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Provincial Key R&D Program of Zhejiang","award":["2020C01038"],"award-info":[{"award-number":["2020C01038"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>Android malware is the major cyber threat to the popular Android platform which may influence millions of end users. To battle against the Android malware, a large number of machine learning methods either based on 1) traditional feature extraction using static and dynamic analysis, or 2) recently proposed image representations, have been developed, and have achieved promising results. However, the vast majority of the existing work rely on a large number of labeled samples which are unfortunately not available for the newly reported Android malware families. This poses a critical challenge to detect such <jats:italic>few-shot Android malware families<\/jats:italic>. In this paper, we propose a novel few-shot learning approach based on the image representation of an Android application to solve the problem. With an application file converted into an image representation, we preserve all the source code information. We then utilize self-supervised learning to obtain the pre-trained backbone from the <jats:italic>unlabeled<\/jats:italic> auxiliary data and employ a metric-based few-shot learning method for Android malware classification. Considering the impact of irrelevant information across samples on the family classification, we employ a multi-cropping strategy to capture family label-related information in the images. Extensive experimental results on the popular <jats:italic>CICInvesAndMal2019<\/jats:italic> dataset confirm the effectiveness of our approach in detecting few-shot Android malware families. We achieve at least 3.16% and 3.7% improvement on 5-way 1-shot and 5-way 5-shot scenarios respectively comparing to state-of-the-art baselines.<\/jats:p>","DOI":"10.1186\/s42400-025-00358-5","type":"journal-article","created":{"date-parts":[[2025,9,16]],"date-time":"2025-09-16T02:02:13Z","timestamp":1757988133000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Androfim: few-shot android malware family detection based on image representation"],"prefix":"10.1186","volume":"8","author":[{"given":"Fan","family":"Zhou","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9812-3911","authenticated-orcid":false,"given":"Dongxia","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanhai","family":"Xiong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kun","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenhai","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,9,16]]},"reference":[{"key":"358_CR1","doi-asserted-by":"crossref","unstructured":"Ale L, Li L, Kar D, et\u00a0al (2020) Few-shot learning to classify android malwares. In: 2020 IEEE 5th International Conference on Signal and Image Processing (ICSIP), IEEE, pp 1001\u20131007","DOI":"10.1109\/ICSIP49896.2020.9339429"},{"key":"358_CR2","doi-asserted-by":"crossref","unstructured":"Arp D, Spreitzenbarth M, Hubner M, et\u00a0al (2014) Drebin: Effective and explainable detection of android malware in your pocket. In: NDSS, pp 23\u201326","DOI":"10.14722\/ndss.2014.23247"},{"key":"358_CR3","doi-asserted-by":"crossref","unstructured":"Bai Y, Xing Z, Li X, et\u00a0al (2020) Unsuccessful story about few shot malware family classification and siamese network to the rescue. In: 2020 IEEE\/ACM 42nd International Conference on Software Engineering (ICSE), IEEE, pp 1560\u20131571","DOI":"10.1145\/3377811.3380354"},{"key":"358_CR4","doi-asserted-by":"crossref","unstructured":"Bendou Y, Hu Y, Lafargue R, et\u00a0al (2022) Easy: Ensemble augmented-shot y-shaped learning: State-of-the-art few-shot classification with simple ingredients. arXiv preprint arXiv:2201.09699","DOI":"10.3390\/jimaging8070179"},{"key":"358_CR5","first-page":"2445","volume":"33","author":"M Boudiaf","year":"2020","unstructured":"Boudiaf M, Ziko I, Rony J et al (2020) Information maximization for few-shot learning. Adv Neural Inf Process Syst 33:2445\u20132457","journal-title":"Adv Neural Inf Process Syst"},{"key":"358_CR6","first-page":"9912","volume":"33","author":"M Caron","year":"2020","unstructured":"Caron M, Misra I, Mairal J et al (2020) Unsupervised learning of visual features by contrasting cluster assignments. Adv Neural Inf Process Syst 33:9912\u20139924","journal-title":"Adv Neural Inf Process Syst"},{"key":"358_CR7","doi-asserted-by":"crossref","unstructured":"Caron M, Touvron H, Misra I, et\u00a0al (2021) Emerging properties in self-supervised vision transformers. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 9650\u20139660","DOI":"10.1109\/ICCV48922.2021.00951"},{"issue":"5","key":"358_CR8","first-page":"4754","volume":"35","author":"Y Chai","year":"2022","unstructured":"Chai Y, Du L, Qiu J et al (2022) Dynamic prototype network based on sample adaptation for few-shot malware detection. IEEE Trans Knowl Data Eng 35(5):4754\u20134766","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"358_CR9","unstructured":"Chen WY, Liu YC, Kira Z, et\u00a0al (2019) A closer look at few-shot classification. arXiv preprint arXiv:1904.04232"},{"key":"358_CR10","doi-asserted-by":"publisher","first-page":"102887","DOI":"10.1016\/j.cose.2022.102887","volume":"122","author":"M Conti","year":"2022","unstructured":"Conti M, Khandhar S, Vinod P (2022) A few-shot malware classification approach for unknown family recognition using malware feature visualization. Comput Secur 122:102887","journal-title":"Comput Secur"},{"issue":"3","key":"358_CR11","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1080\/15536548.2015.1073510","volume":"11","author":"M Damshenas","year":"2015","unstructured":"Damshenas M, Dehghantanha A, Choo KKR et al (2015) M0droid: an android behavioral-based malware detection model. J Inf Privacy Secur 11(3):141\u2013157","journal-title":"J Inf Privacy Secur"},{"key":"358_CR12","unstructured":"Dhillon GS, Chaudhari P, Ravichandran A, et\u00a0al (2019) A baseline for few-shot image classification. In: International Conference on Learning Representations"},{"issue":"8","key":"358_CR13","doi-asserted-by":"publisher","first-page":"1890","DOI":"10.1109\/TIFS.2018.2806891","volume":"13","author":"M Fan","year":"2018","unstructured":"Fan M, Liu J, Luo X et al (2018) Android malware familial classification and representative sample selection via frequent subgraph analysis. IEEE Trans Inf Forensics Secur 13(8):1890\u20131905","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"358_CR14","doi-asserted-by":"crossref","unstructured":"Fan Y, Ju M, Hou S, et\u00a0al (2021) Heterogeneous temporal graph transformer: An intelligent system for evolving android malware detection. In: Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining, pp 2831\u20132839","DOI":"10.1145\/3447548.3467168"},{"issue":"4","key":"358_CR15","doi-asserted-by":"publisher","first-page":"594","DOI":"10.1109\/TPAMI.2006.79","volume":"28","author":"L Fei-Fei","year":"2006","unstructured":"Fei-Fei L, Fergus R, Perona P (2006) One-shot learning of object categories. IEEE Trans Pattern Anal Mach Intell 28(4):594\u2013611","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"358_CR16","unstructured":"Finn C, Abbeel P, Levine S (2017) Model-agnostic meta-learning for fast adaptation of deep networks. In: International Conference on Machine Learning, PMLR, pp 1126\u20131135"},{"key":"358_CR17","doi-asserted-by":"crossref","unstructured":"Ganesh M, Pednekar P, Prabhuswamy P, et\u00a0al (2017) Cnn-based android malware detection. In: 2017 International Conference on Software Security and Assurance (ICSSA), IEEE, pp 60\u201365","DOI":"10.1109\/ICSSA.2017.18"},{"key":"358_CR18","unstructured":"Google (2019) Android security & privacy 2018 year in review. https:\/\/source.android.com\/security\/reports\/Google_Android_Security_2018_Report_Final.pdf"},{"key":"358_CR19","doi-asserted-by":"crossref","unstructured":"Gordon MI, Kim D, Perkins JH, et\u00a0al (2015) Information flow analysis of android applications in droidsafe. In: NDSS, p 110","DOI":"10.14722\/ndss.2015.23089"},{"key":"358_CR20","first-page":"21271","volume":"33","author":"JB Grill","year":"2020","unstructured":"Grill JB, Strub F, Altch\u00e9 F et al (2020) Bootstrap your own latent-a new approach to self-supervised learning. Adv Neural Inf Process Syst 33:21271\u201321284","journal-title":"Adv Neural Inf Process Syst"},{"key":"358_CR21","doi-asserted-by":"crossref","unstructured":"Guo Y, Codella NC, Karlinsky L, et\u00a0al (2020) A broader study of cross-domain few-shot learning. In: European Conference on Computer Vision, Springer, pp 124\u2013141","DOI":"10.1007\/978-3-030-58583-9_8"},{"key":"358_CR22","doi-asserted-by":"publisher","first-page":"3511","DOI":"10.1109\/TIFS.2020.2975932","volume":"15","author":"Q Han","year":"2020","unstructured":"Han Q, Subrahmanian V, Xiong Y (2020) Android malware detection via (somewhat) robust irreversible feature transformations. IEEE Trans Inf Forensics Secur 15:3511\u20133525","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"358_CR23","doi-asserted-by":"crossref","unstructured":"He K, Fan H, Wu Y, et\u00a0al (2020) Momentum contrast for unsupervised visual representation learning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 9729\u20139738","DOI":"10.1109\/CVPR42600.2020.00975"},{"key":"358_CR24","unstructured":"Hinton G, Vinyals O, Dean J (2015) Distilling the knowledge in a neural network. stat 1050:9"},{"key":"358_CR25","doi-asserted-by":"crossref","unstructured":"Hsien-De\u00a0Huang T, Kao HY (2018) R2-d2: Color-inspired convolutional neural network (CNN)-based android malware detections. In: 2018 IEEE International Conference on Big Data (Big Data), IEEE, pp 2633\u20132642","DOI":"10.1109\/BigData.2018.8622324"},{"key":"358_CR26","doi-asserted-by":"crossref","unstructured":"Hu SX, Li D, St\u00fchmer J, et\u00a0al (2022) Pushing the limits of simple pipelines for few-shot learning: External data and fine-tuning make a difference. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 9068\u20139077","DOI":"10.1109\/CVPR52688.2022.00886"},{"key":"358_CR27","unstructured":"Jiang Z, Kang B, Zhou K, et\u00a0al (2020) Few-shot classification via adaptive attention. arXiv preprint arXiv:2008.02465"},{"key":"358_CR28","doi-asserted-by":"crossref","unstructured":"Lashkari AH, Kadir AFA, Gonzalez H, et\u00a0al (2017) Towards a network-based framework for android malware detection and characterization. In: 2017 15th Annual Conference on Privacy, Security and Trust (PST), IEEE, pp 233\u201323309","DOI":"10.1109\/PST.2017.00035"},{"key":"358_CR29","doi-asserted-by":"crossref","unstructured":"Lazarou M, Stathaki T, Avrithis Y (2021) Iterative label cleaning for transductive and semi-supervised few-shot learning. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 8751\u20138760","DOI":"10.1109\/ICCV48922.2021.00863"},{"key":"358_CR30","doi-asserted-by":"crossref","unstructured":"Lee K, Maji S, Ravichandran A, et\u00a0al (2019) Meta-learning with differentiable convex optimization. In: Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition, pp 10657\u201310665","DOI":"10.1109\/CVPR.2019.01091"},{"key":"358_CR31","doi-asserted-by":"crossref","unstructured":"Li Y, Jang J, Hu X, et\u00a0al (2017) Android malware clustering through malicious payload mining. In: Research in Attacks, Intrusions, and Defenses: 20th International Symposium, RAID 2017, Atlanta, GA, USA, September 18\u201320, 2017, Proceedings, Springer, pp 192\u2013214","DOI":"10.1007\/978-3-319-66332-6_9"},{"key":"358_CR32","unstructured":"Loshchilov I, Hutter F (2016) Sgdr: Stochastic gradient descent with warm restarts. arXiv preprint arXiv:1608.03983"},{"issue":"1","key":"358_CR33","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10922-021-09634-4","volume":"30","author":"S Mahdavifar","year":"2022","unstructured":"Mahdavifar S, Alhadidi D, Ghorbani A et al (2022) Effective and efficient hybrid android malware classification using pseudo-label stacked auto-encoder. J Netw Syst Manag 30(1):1\u201334","journal-title":"J Netw Syst Manag"},{"key":"358_CR34","doi-asserted-by":"crossref","unstructured":"Mangla P, Kumari N, Sinha A, et\u00a0al (2020) Charting the right manifold: Manifold mixup for few-shot learning. In: Proceedings of the IEEE\/CVF winter conference on applications of computer vision, pp 2218\u20132227","DOI":"10.1109\/WACV45572.2020.9093338"},{"key":"358_CR35","unstructured":"Miyai A, Yu Q, Irie G, et\u00a0al (2023) Locoop: Few-shot out-of-distribution detection via prompt learning. arXiv preprint arXiv:2306.01293"},{"key":"358_CR36","unstructured":"Palmer D (2022) What is ransomware? everything you need to know about one of the biggest menaces on the web. https:\/\/www.zdnet.com\/article\/ransomware-an-executive-guide-to-one-of-t he-biggest-menaces-on-the-web\/, accessed on August 1, 2022"},{"key":"358_CR37","unstructured":"Paszke A, Gross S, Chintala S, et\u00a0al (2017) Automatic differentiation in pytorch"},{"key":"358_CR38","doi-asserted-by":"crossref","unstructured":"Rong C, Gou G, Hou C, et\u00a0al (2021) Umvd-fsl: Unseen malware variants detection using few-shot learning. In: 2021 International Joint Conference on Neural Networks (IJCNN), IEEE, pp 1\u20138","DOI":"10.1109\/IJCNN52387.2021.9533759"},{"key":"358_CR39","unstructured":"Snell J, Swersky K, Zemel R (2017) Prototypical networks for few-shot learning. Advances in Neural Information Processing Systems 30"},{"key":"358_CR40","doi-asserted-by":"crossref","unstructured":"Sung F, Yang Y, Zhang L, et\u00a0al (2018) Learning to compare: Relation network for few-shot learning. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp 1199\u20131208","DOI":"10.1109\/CVPR.2018.00131"},{"key":"358_CR41","doi-asserted-by":"crossref","unstructured":"Taheri L, Kadir AFA, Lashkari AH (2019) Extensible android malware detection and family classification using network-flows and api-calls. In: 2019 International Carnahan Conference on Security Technology (ICCST), IEEE, pp 1\u20138","DOI":"10.1109\/CCST.2019.8888430"},{"key":"358_CR42","doi-asserted-by":"crossref","unstructured":"Tian L, Feng J, Chai X, et\u00a0al (2023) Prototypes-oriented transductive few-shot learning with conditional transport. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 16317\u201316326","DOI":"10.1109\/ICCV51070.2023.01495"},{"key":"358_CR43","doi-asserted-by":"crossref","unstructured":"Tian Y, Wang Y, Krishnan D, et\u00a0al (2020) Rethinking few-shot image classification: a good embedding is all you need? In: European Conference on Computer Vision, Springer, pp 266\u2013282","DOI":"10.1007\/978-3-030-58568-6_16"},{"key":"358_CR44","unstructured":"Tripp O, Rubin J (2014) A bayesian approach to privacy enforcement in smartphones. In: 23rd USENIX Security Symposium (USENIX Security 14), pp 175\u2013190"},{"key":"358_CR45","unstructured":"Verma V, Lamb A, Beckham C, et\u00a0al (2019) Manifold mixup: Better representations by interpolating hidden states. In: International Conference on Machine Learning, PMLR, pp 6438\u20136447"},{"key":"358_CR46","unstructured":"Vinyals O, Blundell C, Lillicrap T, et\u00a0al (2016) Matching networks for one shot learning. Advances in Neural Information Processing Systems 29"},{"key":"358_CR47","unstructured":"Wang Y, Chao WL, Weinberger KQ, et\u00a0al (2019) Simpleshot: Revisiting nearest-neighbor classification for few-shot learning. arXiv preprint arXiv:1911.04623"},{"key":"358_CR48","doi-asserted-by":"publisher","first-page":"3979","DOI":"10.1007\/s11042-017-5104-0","volume":"78","author":"X Xiao","year":"2019","unstructured":"Xiao X, Zhang S, Mercaldo F et al (2019) Android malware detection based on system call sequences and LSTM. Multimed Tools Appl 78:3979\u20133999","journal-title":"Multimed Tools Appl"},{"key":"358_CR49","doi-asserted-by":"crossref","unstructured":"Xiao X, Yang S (2019) An image-inspired and cnn-based android malware detection approach. In: 2019 34th IEEE\/ACM International Conference on Automated Software Engineering (ASE), IEEE, pp 1259\u20131261","DOI":"10.1109\/ASE.2019.00155"},{"key":"358_CR50","unstructured":"Xue L, Zhou Y, Chen T, et\u00a0al (2017) Malton: Towards $$\\{$$On-Device$$\\}$$$$\\{$$Non-Invasive$$\\}$$ mobile malware analysis for $$\\{$$ART$$\\}$$. In: 26th USENIX Security Symposium (USENIX Security 17), pp 289\u2013306"},{"key":"358_CR51","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1016\/j.cose.2018.10.001","volume":"80","author":"L Zhang","year":"2019","unstructured":"Zhang L, Thing VL, Cheng Y (2019) A scalable and extensible framework for android malware detection and family attribution. Comput Secur 80:120\u2013133","journal-title":"Comput Secur"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00358-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00358-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00358-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,16]],"date-time":"2025-09-16T02:02:34Z","timestamp":1757988154000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-025-00358-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,16]]},"references-count":51,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["358"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00358-5","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,16]]},"assertion":[{"value":"8 February 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 January 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 September 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"69"}}