{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T20:34:29Z","timestamp":1776976469863,"version":"3.51.4"},"reference-count":0,"publisher":"Slovenian Association Informatika","issue":"11","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IJCAI"],"abstract":"<jats:p>With the popularity of smartphones and mobile applications, the threat of Android malware is increasingly serious. To realize the efficient and accurate detection of Android malware, a detection method combining mean aggregator and long-term short-term memory (MLSTM) has been proposed. This method is based on the graph sample and aggregate framework. Construct an isomorphic graph of an application based on permission requests and third-party library call features. MLSTM first aggregates the average features of adjacent nodes, and then uses long-term short-term memory (LSTM) to process sequence information, generating the final node embeddings for classification. The test results on AndroZoo and VirusShare datasets show that compared with baseline models including average aggregator, LSTM aggregator, max pool aggregator, graph convolution network, and gated recurrent unit (GRU), MLSTM has the smallest average absolute error and root mean square error, which are 3.84 and 6.26, respectively. Its detection performance is the best. In terms of permission features and third-party library features, the accuracy of MLSTM is (98.85 \u00b1 0.12)% and (92.58 \u00b1 0.25)%, respectively, significantly higher than GRU under the same permission features. In addition, under the projected gradient descent attack, the success rate of MLSTM attack is 35.28%. This model exhibits good robustness against adversarial attacks. The proposed method has good detection performance, enhanced robustness and stability. Applied to actual Android devices can improve the security and privacy protection level of user data. This method ensures the enhanced efficiency and stability, and provides a certain reference direction for Android malware detection.<\/jats:p>","DOI":"10.31449\/inf.v50i11.10831","type":"journal-article","created":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T19:36:23Z","timestamp":1776972983000},"source":"Crossref","is-referenced-by-count":0,"title":["MLSTM: A GraphSAGE-based Android Malware Detection Method Integrating Mean Aggregation and LSTM"],"prefix":"10.31449","volume":"50","author":[{"given":"Yi","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Md Gapar Md","family":"Johar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jacquline","family":"Tham","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"16141","published-online":{"date-parts":[[2026,4,23]]},"container-title":["Informatica"],"original-title":[],"link":[{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/download\/10831\/6649","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/download\/10831\/6649","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T19:36:24Z","timestamp":1776972984000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.informatica.si\/index.php\/informatica\/article\/view\/10831"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,23]]},"references-count":0,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2026,4,23]]}},"URL":"https:\/\/doi.org\/10.31449\/inf.v50i11.10831","relation":{},"ISSN":["1854-3871","0350-5596"],"issn-type":[{"value":"1854-3871","type":"electronic"},{"value":"0350-5596","type":"print"}],"subject":[],"published":{"date-parts":[[2026,4,23]]}}}