{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,25]],"date-time":"2026-06-25T12:57:02Z","timestamp":1782392222623,"version":"3.54.5"},"reference-count":83,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T00:00:00Z","timestamp":1770163200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T00:00:00Z","timestamp":1770163200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100000780","name":"European Union","doi-asserted-by":"crossref","award":["PE00000013"],"award-info":[{"award-number":["PE00000013"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100000780","name":"European Union","doi-asserted-by":"crossref","award":["PE00000014"],"award-info":[{"award-number":["PE00000014"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100000780","name":"European Union","doi-asserted-by":"crossref","award":["PE00000014"],"award-info":[{"award-number":["PE00000014"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100005362","name":"Universita degli Studi di Bari Aldo Moro","doi-asserted-by":"publisher","award":["H93C23000880005"],"award-info":[{"award-number":["H93C23000880005"]}],"id":[{"id":"10.13039\/501100005362","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Android OS is today the most used Operating System for mobile devices. However, it is susceptible to several malware attacks that may seriously compromise the privacy and security of individuals and organizations. This paper proposes an approach based on a static analysis of decompiled Android PacKages (APKs) to extract critical APIs and detect Android malware. The main contributions lie in the adoption of a graph-based data engineering schema to represent APIs taken from the Function Call Graphs of decompiled APKs and the formulation of a graph-based deep learning approach for explainable malware detection. In particular, the proposed approach, named , implements a Graph Neural Network (GNN) for binary classification (malware versus goodware), and integrates  algorithm to disclose how specific API classes and control-flow edges between API calls influence malware alerts. The proposed approach was evaluated by considering 26,527 Android APKs. The results of an extensive and in-depth evaluation show that the presented GNN model achieves higher accuracy than deep neural models trained with traditional API call sequence representations and publicly available related methods. On the other hand, it produces decision explanations that yield interesting insights into the malicious patterns of APKs and support root cause analysis of missed malware alarms.<\/jats:p>","DOI":"10.1186\/s42400-026-00552-z","type":"journal-article","created":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T08:42:21Z","timestamp":1770194541000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Anakin: explainable android malware detection with graph neural networks"],"prefix":"10.1186","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5272-644X","authenticated-orcid":false,"given":"Giuseppina","family":"Andresini","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Annalisa","family":"Appice","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vincenzo","family":"Belvedere","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giuseppe","family":"Fiameni","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Donato","family":"Malerba","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,2,4]]},"reference":[{"key":"552_CR1","doi-asserted-by":"publisher","unstructured":"Aafer Y, Du W, Yin H (2013) Droidapiminer: mining api-level features for robust malware detection in android. In: Zia T, Zomaya A, Varadharajan V, et\u00a0al (eds) Security and privacy in communication networks. Springer International Publishing, pp 86\u2013103. https:\/\/doi.org\/10.1007\/978-3-319-04283-1_6","DOI":"10.1007\/978-3-319-04283-1_6"},{"key":"552_CR2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2024.111535","volume":"289","author":"GJ Aguiar","year":"2024","unstructured":"Aguiar GJ, Cano A (2024) A comprehensive analysis of concept drift locality in data streams. Knowl-Based Syst 289:111535. https:\/\/doi.org\/10.1016\/j.knosys.2024.111535","journal-title":"Knowl-Based Syst"},{"issue":"8","key":"552_CR3","doi-asserted-by":"publisher","first-page":"5379","DOI":"10.1007\/s10994-023-06470-2","volume":"113","author":"M Al-Essa","year":"2024","unstructured":"Al-Essa M, Andresini G, Appice A et al (2024) PANACEA: a neural model ensemble for cyber-threat detection. Mach Learn 113(8):5379\u20135422. https:\/\/doi.org\/10.1007\/s10994-023-06470-2","journal-title":"Mach Learn"},{"key":"552_CR4","doi-asserted-by":"publisher","unstructured":"Andresini G, Appice A, Malerba D (2020) Dealing with class imbalance in android malware detection by cascading clustering and classification. In: Complex pattern mining: new challenges, methods and applications. Springer International Publishing, pp 173\u2013187, https:\/\/doi.org\/10.1007\/978-3-030-36617-9_11","DOI":"10.1007\/978-3-030-36617-9_11"},{"key":"552_CR5","doi-asserted-by":"publisher","unstructured":"Andresini G, Appice A, Loglisci C, et\u00a0al (2021) A network intrusion detection system for concept drifting network traffic data. In: Soares C, Torgo L (eds) Discovery science. Springer International Publishing, pp 111\u2013121. https:\/\/doi.org\/10.1007\/978-3-030-88942-5_9","DOI":"10.1007\/978-3-030-88942-5_9"},{"key":"552_CR6","doi-asserted-by":"crossref","unstructured":"Arp D, Spreitzenbarth M, H\u00fcbner M, et al. (2014) Drebin: effective and explainable detection of android malware in your pocket. https:\/\/doi.org\/10.14722\/ndss.2014.23247","DOI":"10.14722\/ndss.2014.23247"},{"key":"552_CR7","doi-asserted-by":"publisher","unstructured":"Baahmed ARE, Andresini G, Robardet C, et\u00a0al (2023) Using graph neural networks for the detection and explanation of network intrusions. In: Machine learning and principles and practice of knowledge discovery in databases - international workshops of ECML PKDD 2023, Revised Selected Papers, Part III, Communications in Computer and Information Science, vol 2135. Springer, pp 201\u2013216, https:\/\/doi.org\/10.1007\/978-3-031-74633-8_13","DOI":"10.1007\/978-3-031-74633-8_13"},{"key":"552_CR8","unstructured":"Bergstra J, Yamins D, Cox DD (2013) Making a science of model search: hyperparameter optimization in hundreds of dimensions for vision architectures. In: Proceedings of the 30th international conference on machine learning, ICML 2013, JMLR Workshop and Conference Proceedings, vol\u00a028. JMLR.org, pp 115\u2013123"},{"key":"552_CR9","doi-asserted-by":"publisher","unstructured":"Bilot T, El\u00a0Madhoun N, Al\u00a0Agha K, et\u00a0al (2024) A survey on malware detection with graph representation learning. ACM Comput Surv 56(11). https:\/\/doi.org\/10.1145\/3664649","DOI":"10.1145\/3664649"},{"key":"552_CR10","doi-asserted-by":"crossref","unstructured":"Bojanowski P, Grave E, Joulin A, et\u00a0al (2016) Enriching word vectors with subword information. arXiv preprint arXiv:1607.04606","DOI":"10.1162\/tacl_a_00051"},{"key":"552_CR11","doi-asserted-by":"publisher","first-page":"101005","DOI":"10.1109\/ACCESS.2025.3577775","volume":"13","author":"F Bourebaa","year":"2025","unstructured":"Bourebaa F, Benmohammed M (2025) Evaluating lightweight transformers with local explainability for android malware detection. IEEE Access 13:101005\u2013101026. https:\/\/doi.org\/10.1109\/ACCESS.2025.3577775","journal-title":"IEEE Access"},{"issue":"4","key":"552_CR12","doi-asserted-by":"publisher","first-page":"3239","DOI":"10.1177\/14727978251318813","volume":"25","author":"J Chang","year":"2025","unstructured":"Chang J, Shi L, Li Z et al (2025) Security detection algorithm using CNN: anomaly detection for api call sequence. J Comput Methods Sci Eng 25(4):3239\u20133254. https:\/\/doi.org\/10.1177\/14727978251318813","journal-title":"J Comput Methods Sci Eng"},{"key":"552_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121617","volume":"237","author":"S Chen","year":"2024","unstructured":"Chen S, Lang B, Liu H et al (2024) Android malware detection method based on graph attention networks and deep fusion of multimodal features. Expert Syst Appl 237:121617. https:\/\/doi.org\/10.1016\/j.eswa.2023.121617","journal-title":"Expert Syst Appl"},{"issue":"20","key":"552_CR14","doi-asserted-by":"publisher","first-page":"12011","DOI":"10.1007\/s00521-024-09738-3","volume":"36","author":"VR Chiranjeevi","year":"2024","unstructured":"Chiranjeevi VR, Malathi D (2024) Anomaly graph: leveraging dynamic graph convolutional networks for enhanced video anomaly detection in surveillance and security applications. Neural Comput Appl 36(20):12011\u201312028. https:\/\/doi.org\/10.1007\/s00521-024-09738-3","journal-title":"Neural Comput Appl"},{"issue":"1","key":"552_CR15","doi-asserted-by":"publisher","DOI":"10.1111\/exsy.13488","volume":"42","author":"A Dahiya","year":"2025","unstructured":"Dahiya A, Singh S, Shrivastava G (2025) Android malware analysis and detection: a systematic review. Expert Syst 42(1):e13488. https:\/\/doi.org\/10.1111\/exsy.13488","journal-title":"Expert Syst"},{"key":"552_CR16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103926","volume":"144","author":"L De Rose","year":"2024","unstructured":"De Rose L, Andresini G, Appice A et al (2024) Vincent: cyber-threat detection through vision transformers and knowledge distillation. Comput & Security 144:103926. https:\/\/doi.org\/10.1016\/j.cose.2024.103926","journal-title":"Comput & Security"},{"key":"552_CR17","doi-asserted-by":"publisher","unstructured":"Ding Y, Zhu S, Xia X (2016) Android malware detection method based on function call graphs. In: Neural information processing. Springer International Publishing, pp 70\u201377, https:\/\/doi.org\/10.1007\/978-3-319-46681-1_9","DOI":"10.1007\/978-3-319-46681-1_9"},{"issue":"1","key":"552_CR18","doi-asserted-by":"publisher","first-page":"5538841","DOI":"10.1155\/2021\/5538841","volume":"2021","author":"P Feng","year":"2021","unstructured":"Feng P, Ma J, Li T et al (2021) Android malware detection via graph representation learning. Mob Inf Syst 2021(1):5538841. https:\/\/doi.org\/10.1155\/2021\/5538841","journal-title":"Mob Inf Syst"},{"key":"552_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103788","volume":"140","author":"P Feng","year":"2024","unstructured":"Feng P, Gai L, Yang L et al (2024) Dawngnn: documentation augmented windows malware detection using graph neural network. Comput & Security 140:103788. https:\/\/doi.org\/10.1016\/j.cose.2024.103788","journal-title":"Comput & Security"},{"key":"552_CR20","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121977","volume":"238","author":"X Fu","year":"2024","unstructured":"Fu X, Pan Y, Zhang L (2024) A causal-temporal graphic convolutional network (CT-GCN) approach for TBM load prediction in tunnel excavation. Expert Syst Appl 238:121977. https:\/\/doi.org\/10.1016\/j.eswa.2023.121977","journal-title":"Expert Syst Appl"},{"key":"552_CR21","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102264","volume":"106","author":"H Gao","year":"2021","unstructured":"Gao H, Cheng S, Zhang W (2021) Gdroid: android malware detection and classification with graph convolutional network. Comput & Security 106:102264. https:\/\/doi.org\/10.1016\/j.cose.2021.102264","journal-title":"Comput & Security"},{"key":"552_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103807","volume":"140","author":"J Gu","year":"2024","unstructured":"Gu J, Zhu H, Han Z et al (2024) Gsedroid: Gnn-based android malware detection framework using lightweight semantic embedding. Comput& Security 140:103807. https:\/\/doi.org\/10.1016\/j.cose.2024.103807","journal-title":"Comput& Security"},{"key":"552_CR23","unstructured":"Hamilton WL, Ying R, Leskovec J (2017) Inductive representation learning on large graphs. In: Advances in neural information processing systems 30: annual conference on neural information processing systems, NeurIPS 2017, pp 1024\u20131034"},{"key":"552_CR24","doi-asserted-by":"publisher","unstructured":"Han D, Wang Z, Feng R, et\u00a0al (2024) Rules refine the riddle: global explanation for deep learning-based anomaly detection in security applications. In: Proceedings of the 2024 on ACM SIGSAC conference on computer and communications security, CCS 2024. ACM, pp 4509\u20134523, https:\/\/doi.org\/10.1145\/3658644.3670375","DOI":"10.1145\/3658644.3670375"},{"key":"552_CR25","doi-asserted-by":"publisher","unstructured":"He P, Xia Y, Zhang X, et\u00a0al (2023) Efficient query-based attack against ml-based android malware detection under zero knowledge setting. In: Proceedings of the 2023 ACM SIGSAC conference on computer and communications security, CCS 2023. ACM, pp 90\u2013104, https:\/\/doi.org\/10.1145\/3576915.3623117","DOI":"10.1145\/3576915.3623117"},{"key":"552_CR26","doi-asserted-by":"publisher","first-page":"1822","DOI":"10.1109\/TIFS.2025.3536280","volume":"20","author":"Q Hu","year":"2025","unstructured":"Hu Q, Wang W, Song H et al (2025) Asdroid: resisting evolving android malware with API clusters derived from source code. IEEE Trans Inf Forensics Secur 20:1822\u20131835. https:\/\/doi.org\/10.1109\/TIFS.2025.3536280","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"552_CR27","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102198","volume":"105","author":"G Iadarola","year":"2021","unstructured":"Iadarola G, Martinelli F, Mercaldo F et al (2021) Towards an interpretable deep learning model for mobile malware detection and family identification. Comput& Security 105:102198. https:\/\/doi.org\/10.1016\/j.cose.2021.102198","journal-title":"Comput& Security"},{"key":"552_CR28","doi-asserted-by":"publisher","unstructured":"Jiang J, Wu J, Ling X, et\u00a0al (2024) App-miner: detecting API misuses via automatically mining API path patterns. In: IEEE symposium on security and privacy, SP 2024. IEEE, pp 4034\u20134052, https:\/\/doi.org\/10.1109\/SP54263.2024.00043","DOI":"10.1109\/SP54263.2024.00043"},{"key":"552_CR29","doi-asserted-by":"publisher","unstructured":"Kinkead M, Millar S, McLaughlin N, et\u00a0al (2021) Towards explainable cnns for android malware detection. Procedia Computer Science 184:959\u2013965. https:\/\/doi.org\/10.1016\/j.procs.2021.03.118, the 12th International Conference on Ambient Systems, Networks and Technologies (ANT) \/ The 4th International Conference on Emerging Data and Industry 4.0 (EDI40) \/ Affiliated Workshops","DOI":"10.1016\/j.procs.2021.03.118"},{"key":"552_CR30","unstructured":"Kipf TN, Welling M (2017) Semi-supervised classification with graph convolutional networks. In: 5th International conference on learning representations, ICLR 2017, Toulon, France, April 24-26, 2017, Conference Track Proceedings. OpenReview.net"},{"key":"552_CR31","doi-asserted-by":"crossref","unstructured":"Li AS, Iyengar A, Kundu A, et\u00a0al (2025) Revisiting concept drift in windows malware detection: adaptation to real drifted malware with minimal samples. In: 32nd annual network and distributed system security symposium, NDSS 2025. The Internet Society","DOI":"10.14722\/ndss.2025.240830"},{"key":"552_CR32","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.121125","volume":"235","author":"Z Liu","year":"2024","unstructured":"Liu Z, Wang R, Japkowicz N et al (2024) Segdroid: an android malware detection method based on sensitive function call graph learning. Expert Syst Appl 235:121125. https:\/\/doi.org\/10.1016\/j.eswa.2023.121125","journal-title":"Expert Syst Appl"},{"issue":"4","key":"552_CR33","doi-asserted-by":"publisher","first-page":"3354","DOI":"10.1109\/TDSC.2025.3529119","volume":"22","author":"B Ma","year":"2025","unstructured":"Ma B, Zhou L, Liao C et al (2025) Ransomsentry: runtime detection of android ransomware with compiler-based instrumentation. IEEE Trans Dependable Secure Comput 22(4):3354\u20133370. https:\/\/doi.org\/10.1109\/TDSC.2025.3529119","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"552_CR34","unstructured":"Ma Z, Ge H, Wang Z, et\u00a0al (2020) Droidetec: android malware detection and malicious code localization through deep learning. ArXiv abs\/2002.03594. https:\/\/api.semanticscholar.org\/CorpusID:211069601"},{"key":"552_CR35","doi-asserted-by":"publisher","unstructured":"Mariconti E, Onwuzurike L, Andriotis P, et\u00a0al (2019) Mamadroid: detecting android malware by building markov chains of behavioral models. ACM Trans Priv Secur 22(2). https:\/\/doi.org\/10.1145\/3313391","DOI":"10.1145\/3313391"},{"key":"552_CR36","volume-title":"1st international conference on learning representations, ICLR 2013","author":"T Mikolov","year":"2013","unstructured":"Mikolov T, Chen K, Corrado G et al (2013) Efficient estimation of word representations in vector space. In: Bengio Y, LeCun Y (eds) 1st international conference on learning representations, ICLR 2013. Workshop Track Proceedings"},{"key":"552_CR37","doi-asserted-by":"crossref","unstructured":"Mohammadian H, Higgins G, Ansong S, et al. (2024) Explainable malware detection through integrated graph reduction and learning techniques. CoRR abs\/2412.03634.https:\/\/doi.org\/10.48550\/ARXIV.2412.03634","DOI":"10.1016\/j.bdr.2025.100555"},{"key":"552_CR38","doi-asserted-by":"publisher","DOI":"10.1016\/j.pmcj.2023.101849","volume":"96","author":"B Molina-Coronado","year":"2023","unstructured":"Molina-Coronado B, Mori U, Mendiburu A et al (2023) Efficient concept drift handling for batch android malware detection models. Pervasive Mob Comput 96:101849. https:\/\/doi.org\/10.1016\/j.pmcj.2023.101849","journal-title":"Pervasive Mob Comput"},{"key":"552_CR39","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102833","volume":"121","author":"A Muzaffar","year":"2022","unstructured":"Muzaffar A, Ragab Hassen H, Lones MA et al (2022) An in-depth review of machine learning based android malware detection. Comput& Security 121:102833. https:\/\/doi.org\/10.1016\/j.cose.2022.102833","journal-title":"Comput& Security"},{"key":"552_CR40","doi-asserted-by":"publisher","unstructured":"Ngamwitroj S, Limthanmaphon B (2018) Adaptive android malware signature detection. In: Proceedings of the 2018 International conference on communication engineering and technology. Association for Computing Machinery, New York, NY, USA, ICCET \u201918, p 22\u201325, https:\/\/doi.org\/10.1145\/3194244.3194257","DOI":"10.1145\/3194244.3194257"},{"issue":"6","key":"552_CR41","doi-asserted-by":"publisher","first-page":"4111","DOI":"10.1109\/TSC.2024.3463487","volume":"17","author":"V Pasquadibisceglie","year":"2024","unstructured":"Pasquadibisceglie V, Scaringi R, Appice A et al (2024) PROPHET: explainable predictive process monitoring with heterogeneous graph neural networks. IEEE Trans Serv Comput 17(6):4111\u20134124. https:\/\/doi.org\/10.1109\/TSC.2024.3463487","journal-title":"IEEE Trans Serv Comput"},{"key":"552_CR42","doi-asserted-by":"publisher","unstructured":"Pennington J, Socher R, Manning C (2014) GloVe: global vectors for word representation. In: 2014 Conference on empirical methods in natural language processing, EMNLP 2014. Association for Computational Linguistics, pp 1532\u20131543, https:\/\/doi.org\/10.3115\/v1\/D14-1162","DOI":"10.3115\/v1\/D14-1162"},{"key":"552_CR43","doi-asserted-by":"publisher","unstructured":"Pfeifer B, Saranti A, Holzinger A (2022) Gnn-subnet: disease subnetwork detection with explainable graph neural networks. Bioinformatics 38(Supplement_2):ii120\u2013ii126. https:\/\/doi.org\/10.1093\/bioinformatics\/btac478","DOI":"10.1093\/bioinformatics\/btac478"},{"key":"552_CR44","doi-asserted-by":"publisher","unstructured":"Pierazzi F, Pendlebury F, Cortellazzi J, et\u00a0al (2020) Intriguing properties of adversarial ML attacks in the problem space. In: 2020 IEEE symposium on security and privacy, SP 2020. IEEE, pp 1332\u20131349, https:\/\/doi.org\/10.1109\/SP40000.2020.00073","DOI":"10.1109\/SP40000.2020.00073"},{"key":"552_CR45","doi-asserted-by":"crossref","unstructured":"Sak H, Senior AW, Beaufays F (2014) Long short-term memory based recurrent neural network architectures for large vocabulary speech recognition. ArXiv:1402.1128","DOI":"10.21437\/Interspeech.2014-80"},{"key":"552_CR46","doi-asserted-by":"publisher","unstructured":"Sammut C, Webb GI (2010) TF\u2013IDF. In: Encyclopedia of machine learning. Springer US, pp 986\u2013987, https:\/\/doi.org\/10.1007\/978-0-387-30164-8_832","DOI":"10.1007\/978-0-387-30164-8_832"},{"key":"552_CR47","unstructured":"Severi G, Meyer J, Coull SE, et\u00a0al (2021) Explanation-guided backdoor poisoning attacks against malware classifiers. In: Bailey MD, Greenstadt R (eds) 30th USENIX security symposium, USENIX Security 2021,. USENIX Association, pp 1487\u20131504"},{"key":"552_CR48","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103846","volume":"141","author":"L Shen","year":"2024","unstructured":"Shen L, Fang M, Xu J (2024) Ghgdroid: global heterogeneous graph-based android malware detection. Comput& Security 141:103846. https:\/\/doi.org\/10.1016\/j.cose.2024.103846","journal-title":"Comput& Security"},{"key":"552_CR49","unstructured":"Shokouhinejad H, Razavi-Far R, Mohammadian H, et\u00a0al (2025) Recent advances in malware detection: graph learning and explainability. arXiv:2502.10556"},{"issue":"4","key":"552_CR50","doi-asserted-by":"publisher","first-page":"3165","DOI":"10.1109\/TDSC.2023.3324265","volume":"21","author":"Z Shu","year":"2024","unstructured":"Shu Z, Yan G (2024) Eagle: evasion attacks guided by local explanations against android malware classification. IEEE Trans Dependable Secure Comput 21(4):3165\u20133182. https:\/\/doi.org\/10.1109\/TDSC.2023.3324265","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"552_CR51","doi-asserted-by":"publisher","unstructured":"Siow JK, Liu S, Xie X, et\u00a0al (2022) Learning program semantics with code representations: an empirical study. In: 2022 IEEE international conference on software analysis, evolution and reengineering (SANER), pp 554\u2013565, https:\/\/doi.org\/10.1109\/SANER53432.2022.00073","DOI":"10.1109\/SANER53432.2022.00073"},{"key":"552_CR52","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2023.103691","volume":"80","author":"D Soi","year":"2024","unstructured":"Soi D, Sanna A, Maiorca D et al (2024) Enhancing android malware detection explainability through function call graph APIs. J Inf Secur Appl 80:103691. https:\/\/doi.org\/10.1016\/j.jisa.2023.103691","journal-title":"J Inf Secur Appl"},{"key":"552_CR53","unstructured":"Statista S (2025) Market share of mobile operating systems worldwide from 2009 to 2025, by quarter. retrieved from statista. https:\/\/www.statista.com\/statistics\/272698\/global-market-share-held-by-mobile-operating-systems-since-2009\/"},{"key":"552_CR54","doi-asserted-by":"crossref","unstructured":"Sun T, Daoudi N, Kim K, et\u00a0al (2024) Detectbert: Towards full app-level representation learning to detect android malware. In: Proceedings of the 18th ACM\/IEEE international symposium on empirical software engineering and measurement, pp 420\u2013426","DOI":"10.1145\/3674805.3690745"},{"key":"552_CR55","doi-asserted-by":"publisher","first-page":"141958","DOI":"10.1109\/ACCESS.2025.3597575","volume":"13","author":"M Tanha","year":"2025","unstructured":"Tanha M, Kafaie S (2025) A review of explainable AI for android malware detection and analysis. IEEE Access 13:141958\u2013141974. https:\/\/doi.org\/10.1109\/ACCESS.2025.3597575","journal-title":"IEEE Access"},{"key":"552_CR56","doi-asserted-by":"publisher","unstructured":"Thomas DR, Beresford AR, Rice AC (2015) Security metrics for the android ecosystem. In: Lie D, Wurster G (eds) Proceedings of the 5th Annual ACM CCS workshop on security and privacy in smartphones and mobile devices, SPSM 2015. ACM, pp 87\u201398, https:\/\/doi.org\/10.1145\/2808117.2808118","DOI":"10.1145\/2808117.2808118"},{"key":"552_CR57","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2024.101320","volume":"27","author":"S Ullah","year":"2024","unstructured":"Ullah S, Li J, Ullah F et al (2024) The revolution and vision of explainable ai for android malware detection and protection. Int Things 27:101320. https:\/\/doi.org\/10.1016\/j.iot.2024.101320","journal-title":"Int Things"},{"key":"552_CR58","unstructured":"Vaswani A, Shazeer N, Parmar N, et\u00a0al (2017) Attention is all you need. In: Proceedings of the 31st international conference on neural information processing systems, NeurIPS 2017. Curran Associates Inc., p 6000\u20136010"},{"key":"552_CR59","unstructured":"Velickovic P, Cucurull G, Casanova A, et\u00a0al (2018) Graph attention networks. In: 6th International conference on learning representations, ICLR 2018, Conference Track Proceedings. OpenReview.net"},{"key":"552_CR60","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2025.113687","volume":"323","author":"Z Wang","year":"2025","unstructured":"Wang Z, Zhang K, Yang S et al (2025) Enhancing android malware detection via knowledge distillation on homogenized function call graphs. Knowl-Based Syst 323:113687. https:\/\/doi.org\/10.1016\/j.knosys.2025.113687","journal-title":"Knowl-Based Syst"},{"key":"552_CR61","doi-asserted-by":"publisher","unstructured":"Warmsley D, Waagen A, Xu J, et\u00a0al (2022) A survey of explainable graph neural networks for cyber malware analysis. In: 2022 IEEE international conference on big data (Big Data), pp 2932\u20132939, https:\/\/doi.org\/10.1109\/BigData55660.2022.10020943","DOI":"10.1109\/BigData55660.2022.10020943"},{"key":"552_CR62","doi-asserted-by":"publisher","unstructured":"Wu B, Chen S, Gao C, et\u00a0al (2021) Why an android app is classified as malware: toward malware classification interpretation. ACM Trans Softw Eng Methodol 30(2). https:\/\/doi.org\/10.1145\/3423096","DOI":"10.1145\/3423096"},{"key":"552_CR63","doi-asserted-by":"publisher","unstructured":"Wu L, Cui P, Pei J, et\u00a0al (2023) Graph neural networks: Foundation, frontiers and applications. In: Proceedings of the 29th ACM SIGKDD conference on knowledge discovery and data mining. Association for Computing Machinery, p 5831\u20135832, https:\/\/doi.org\/10.1145\/3580305.3599560","DOI":"10.1145\/3580305.3599560"},{"key":"552_CR64","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2025.103509","volume":"102","author":"J Xia","year":"2025","unstructured":"Xia J, Chan YH, Girish D et al (2025) Interpretable modality-specific and interactive graph convolutional network on brain functional and structural connectomes. Med Image Anal 102:103509. https:\/\/doi.org\/10.1016\/j.media.2025.103509","journal-title":"Med Image Anal"},{"key":"552_CR65","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2023.107280","volume":"127","author":"J Xu","year":"2024","unstructured":"Xu J, Li K, Li Z et al (2024) Fuzzy graph convolutional network for hyperspectral image classification. Eng Appl Artif Intell 127:107280. https:\/\/doi.org\/10.1016\/j.engappai.2023.107280","journal-title":"Eng Appl Artif Intell"},{"key":"552_CR66","unstructured":"Xu K, Hu W, Leskovec J, et\u00a0al (2018) How powerful are graph neural networks? CoRR arXiv: 1810.00826"},{"key":"552_CR67","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104061","volume":"146","author":"J Yang","year":"2024","unstructured":"Yang J, Li H, He L et al (2024) Mdadroid: a novel malware detection method by constructing functionality-api mapping. Comput& Security 146:104061. https:\/\/doi.org\/10.1016\/j.cose.2024.104061","journal-title":"Comput& Security"},{"key":"552_CR68","unstructured":"Ying Z, Bourgeois D, You J, et\u00a0al (2019) Gnnexplainer: generating explanations for graph neural networks. In: Advances in neural information processing systems 32: annual conference on neural information processing systems 2019, NeurIPS 2019, pp 9240\u20139251"},{"issue":"5","key":"552_CR69","doi-asserted-by":"publisher","first-page":"5782","DOI":"10.1109\/TPAMI.2022.3204236","volume":"45","author":"H Yuan","year":"2023","unstructured":"Yuan H, Yu H, Gui S et al (2023) Explainability in graph neural networks: a taxonomic survey. IEEE Trans Pattern Anal Mach Intell 45(5):5782\u20135799. https:\/\/doi.org\/10.1109\/TPAMI.2022.3204236","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"552_CR70","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104262","volume":"150","author":"S Zhang","year":"2025","unstructured":"Zhang S, Su H, Liu H et al (2025) Mpdroid: a multimodal pre-training android malware detection method with static and dynamic features. Comput. & Security 150:104262. https:\/\/doi.org\/10.1016\/j.cose.2024.104262","journal-title":"Comput. & Security"},{"key":"552_CR71","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-94463-0","author":"CC Aggarwal","year":"2018","unstructured":"Aggarwal CC (2018) Neural networks and deep learning - a textbook. Springer. https:\/\/doi.org\/10.1007\/978-3-319-94463-0","journal-title":"Springer"},{"issue":"1","key":"552_CR72","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/S10844-020-00598-6","volume":"55","author":"A Appice","year":"2020","unstructured":"Appice A, Andresini G, Malerba D (2020) Clustering-aided multi-view classification: a case study on android malware detection. J Intell Inf Syst 55(1):1\u201326. https:\/\/doi.org\/10.1007\/S10844-020-00598-6","journal-title":"J Intell Inf Syst"},{"key":"552_CR73","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1007\/978-3-642-05224-8_4","volume-title":"Advances in machine learning","author":"A Bifet","year":"2009","unstructured":"Bifet A, Holmes G, Pfahringer B et al (2009) Improving adaptive bagging methods for evolving data streams. In: Zhou ZH, Washio T (eds) Advances in machine learning. Springer, Berlin Heidelberg, Berlin, Heidelberg, pp 23\u201337. https:\/\/doi.org\/10.1007\/978-3-642-05224-8_4"},{"issue":"3","key":"552_CR74","doi-asserted-by":"publisher","first-page":"655","DOI":"10.1007\/S11219-022-09602-4","volume":"31","author":"X Chen","year":"2023","unstructured":"Chen X, Yu H, Yu D et al (2023) Predicting android malware combining permissions and API call sequences. Softw Qual J 31(3):655\u2013685. https:\/\/doi.org\/10.1007\/S11219-022-09602-4","journal-title":"Softw Qual J"},{"key":"552_CR75","doi-asserted-by":"publisher","first-page":"121","DOI":"10.1016\/j.cose.2016.11.007","volume":"65","author":"A Feizollah","year":"2017","unstructured":"Feizollah A, Anuar NB, Salleh R et al (2017) Androdialysis: analysis of android intent effectiveness in malware detection. Comput & Security 65:121\u2013134. https:\/\/doi.org\/10.1016\/j.cose.2016.11.007","journal-title":"Comput & Security"},{"key":"552_CR76","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1609\/aaaiss.v6i1.36036","volume":"6","author":"M Hussain","year":"2025","unstructured":"Hussain M, Muzaffar A (2025) Online learning-based android malware detection using API call graphs and drift detection: a comparative study. Proc AAAI Symp Series 6:87\u201389. https:\/\/doi.org\/10.1609\/aaaiss.v6i1.36036","journal-title":"Proc AAAI Symp Series"},{"issue":"2","key":"552_CR77","doi-asserted-by":"publisher","first-page":"711","DOI":"10.1007\/S13198-024-02643-X","volume":"16","author":"A Joomye","year":"2025","unstructured":"Joomye A, Ling MH, Yau KA (2025) A brief survey of deep learning methods for android malware detection. Int J Syst Assur Eng Manag 16(2):711\u2013733. https:\/\/doi.org\/10.1007\/S13198-024-02643-X","journal-title":"Int J Syst Assur Eng Manag"},{"issue":"1","key":"552_CR78","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/S41060-024-00620-Y","volume":"19","author":"D Lukats","year":"2025","unstructured":"Lukats D, Zielinski O, Hahn A et al (2025) A benchmark and survey of fully unsupervised concept drift detectors on real-world data streams. Int J Data Sci Anal 19(1):1\u201331. https:\/\/doi.org\/10.1007\/S41060-024-00620-Y","journal-title":"Int J Data Sci Anal"},{"key":"552_CR79","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.future.2021.11.030","volume":"130","author":"P Maniriho","year":"2022","unstructured":"Maniriho P, Mahmood AN, Chowdhury MJM (2022) A study on malicious software behaviour analysis and detection techniques: taxonomy, current trends and challenges. Futur Gener Comput Syst 130:1\u201318. https:\/\/doi.org\/10.1016\/j.future.2021.11.030","journal-title":"Futur Gener Comput Syst"},{"issue":"1","key":"552_CR80","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/S10618-024-01073-4","volume":"39","author":"SY Moon","year":"2025","unstructured":"Moon SY, Kerr G, Silavong F et al (2025) A probabilistic model for API contract specification retrieval focusing on the openapi standard. Data Min Knowl Discov 39(1):1\u201324. https:\/\/doi.org\/10.1007\/S10618-024-01073-4","journal-title":"Data Min Knowl Discov"},{"issue":"1\/2","key":"552_CR81","doi-asserted-by":"publisher","first-page":"100","DOI":"10.2307\/2333009","volume":"41","author":"ES Page","year":"1954","unstructured":"Page ES (1954) Continuous inspection schemes. Biometrika 41(1\/2):100\u2013115","journal-title":"Biometrika"},{"issue":"1","key":"552_CR82","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1007\/S44163-025-00318-5","volume":"5","author":"S Reynaud","year":"2025","unstructured":"Reynaud S, Roxin A (2025) Review of explainable artificial intelligence for cybersecurity systems. Discov Artif Intell 5(1):78. https:\/\/doi.org\/10.1007\/S44163-025-00318-5","journal-title":"Discov Artif Intell"},{"issue":"2","key":"552_CR83","doi-asserted-by":"publisher","first-page":"902","DOI":"10.1109\/TDSC.2022.3144697","volume":"20","author":"X Zhang","year":"2023","unstructured":"Zhang X, Zhang M, Zhang Y et al (2023) Slowing down the aging of learning-based malware detectors with API knowledge. IEEE Trans Dependable Secure Comput 20(2):902\u2013916. https:\/\/doi.org\/10.1109\/TDSC.2022.3144697","journal-title":"IEEE Trans Dependable Secure Comput"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00552-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-026-00552-z","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00552-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T08:52:23Z","timestamp":1772095943000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-026-00552-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,4]]},"references-count":83,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["552"],"URL":"https:\/\/doi.org\/10.1186\/s42400-026-00552-z","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,4]]},"assertion":[{"value":"1 May 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 January 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 February 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 February 2026","order":5,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Update","order":6,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The code in Footnote 1 has been corrected, and DOIs have been added to some references in the reference list.","order":7,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"116"}}