{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T04:58:24Z","timestamp":1781067504367,"version":"3.54.1"},"reference-count":33,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T00:00:00Z","timestamp":1780531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Algorithms"],"abstract":"<jats:p>Traditional Android malware detection systems struggle to adapt to evolving threats without sacrificing performance on legacy families. To address this, we present ProtoMal, a dual-branch continual learning framework that achieves a fine-grained balance between stability and plasticity. The framework utilizes a frozen old branch for knowledge preservation and a trainable new branch for novel threat acquisition. A key contribution is our robust median-based prototype learning mechanism, which leverages centroids and outlier filtering to handle the high intra-class variability and label noise inherent in malware datasets. Experimental results across three large-scale benchmarks AMD, VirusShare, and VirusShareYears demonstrate that ProtoMal significantly curtails performance degradation and achieves highly competitive average accuracy. Most notably, the proposed framework demonstrates highly competitive model stability and yields robust anti-forgetting capabilities alongside current state-of-the-art incremental learning paradigms, maintaining particular resilience under severe concept drift.<\/jats:p>","DOI":"10.3390\/a19060456","type":"journal-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T17:11:04Z","timestamp":1780593064000},"page":"456","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["ProtoMal: Prototype-Guided Dual-Branch Continual Learning for Robust Android Malware Detection"],"prefix":"10.3390","volume":"19","author":[{"given":"Xuan","family":"Zhang","sequence":"first","affiliation":[{"name":"Department of Artificial Intelligence, Tianjin University of Science and Technology, Tianjin 300457, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aihua","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Artificial Intelligence, Tianjin University of Science and Technology, Tianjin 300457, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maode","family":"Ma","sequence":"additional","affiliation":[{"name":"Faculty of Computer Science and Artificial Intelligence, Shenzhen University of Advanced Technology, Shenzhen 518055, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuanjie","family":"Bo","sequence":"additional","affiliation":[{"name":"Department of Artificial Intelligence, Tianjin University of Science and Technology, Tianjin 300457, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yiying","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Artificial Intelligence, Tianjin University of Science and Technology, Tianjin 300457, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Artificial Intelligence, Tianjin University of Science and Technology, Tianjin 300457, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3605775","article-title":"Deep learning for zero-day malware detection and classification: A survey","volume":"56","author":"Deldar","year":"2023","journal-title":"ACM Comput. Surv."},{"key":"ref_2","unstructured":"(2026, May 25). What Is Malware?. Available online: https:\/\/www.microsoft.com\/zh-cn\/security\/business\/security-101\/what-is-malware."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"112527","DOI":"10.1016\/j.jss.2025.112527","article-title":"Incremental learning of code authors over time","volume":"230","author":"Gong","year":"2025","journal-title":"J. Syst. Softw."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Ganesan, S., Ravi, V., Krichen, M., V, S., Alroobaea, R., and KP, S. (2021, January 10\u201312). Robust Malware Detection using Residual Attention Network. Proceedings of the 2021 IEEE International Conference on Consumer Electronics (ICCE), Las Vegas, NV, USA.","DOI":"10.1109\/ICCE50685.2021.9427623"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Aboaoja, F.A., Zainal, A., Ghaleb, F.A., Al-rimy, B.A.S., Eisa, T.A.E., and Elnour, A.A.H. (2022). Malware Detection Issues, Challenges, and Future Directions: A Survey. Appl. Sci., 12.","DOI":"10.3390\/app12178482"},{"key":"ref_6","first-page":"4542","article-title":"A bio inspired hybrid optimization framework for efficient real time malware detection","volume":"16","author":"Abualhaj","year":"2026","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"122678","DOI":"10.1016\/j.eswa.2023.122678","article-title":"MIGAN: GAN for facilitating malware image synthesis with improved malware classification on novel dataset","volume":"241","author":"Sharma","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"110763","DOI":"10.1016\/j.compeleceng.2025.110763","article-title":"EnFeSTDroid: Ensembled feature selection techniques based Android malware detection","volume":"129","author":"Jain","year":"2026","journal-title":"Comput. Electr. Eng."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"7261","DOI":"10.1002\/int.22880","article-title":"Malware detection with dynamic evolving graph convolutional networks","volume":"37","author":"Zhang","year":"2022","journal-title":"Int. J. Intell. Syst."},{"key":"ref_10","first-page":"8398591","article-title":"Fgl_droid: An efficient android malware detection method based on hybrid analysis","volume":"2022","author":"Wang","year":"2022","journal-title":"Secur. Commun. Netw."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Taher, F., AlFandi, O., Al-kfairy, M., Al Hamadi, H., and Alrabaee, S. (2023). DroidDetectMW: A Hybrid Intelligent Model for Android Malware Detection. Appl. Sci., 13.","DOI":"10.20944\/preprints202305.0333.v1"},{"key":"ref_12","unstructured":"Jordaney, R., Sharad, K., Dash, S.K., Wang, Z., Papini, D., Nouretdinov, I., and Cavallaro, L. (2017, January 16\u201318). Transcend: Detecting Concept Drift in Malware Classification Models. Proceedings of the 26th USENIX Security Symposium (USENIX Security 17), Vancouver, BC, Canada."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Xu, K., Li, Y., Deng, R., Chen, K., and Xu, J. (2019, January 17\u201319). DroidEvolver: Self-Evolving Android Malware Detection System. Proceedings of the 2019 IEEE European Symposium on Security and Privacy (EuroS&P), Stockholm, Sweden.","DOI":"10.1109\/EuroSP.2019.00014"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Kan, Z., Pendlebury, F., Pierazzi, F., and Cavallaro, L. (2021, January 15). Investigating Labelless Drift Adaptation for Malware Detection. Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, AISec\u201921, Virtual Event.","DOI":"10.1145\/3474369.3486873"},{"key":"ref_15","first-page":"5995","article-title":"OMD-RAS: Optimizing Malware Detection through Comprehensive Approach to Real-Time and Adaptive Security","volume":"84","author":"Mohammad","year":"2025","journal-title":"Comput. Mater. Contin."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Chen, Z., Zhang, Z., Kan, Z., Yang, L., Cortellazzi, J., Pendlebury, F., Pierazzi, F., Cavallaro, L., and Wang, G. (2023, January 25). Is It Overkill? Analyzing Feature-Space Concept Drift in Malware Detectors. Proceedings of the 2023 IEEE Security and Privacy Workshops (SPW), San Francisco, CA, USA.","DOI":"10.1109\/SPW59333.2023.00007"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"21816","DOI":"10.1109\/JIOT.2024.3376635","article-title":"Advancing Malware Detection in Network Traffic With Self-Paced Class Incremental Learning","volume":"11","author":"Xu","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"ref_18","unstructured":"Rahman, M.S., Coull, S., Yu, Q., and Wright, M. (2025). MADAR: Efficient continual learning for malware analysis with diversity-aware replay. arXiv."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"11867","DOI":"10.1038\/s41598-025-96392-x","article-title":"GEAAD: Generating evasive adversarial attacks against android malware defense","volume":"15","author":"Ahmad","year":"2025","journal-title":"Sci. Rep."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Gao, Z., Jia, W., Zhang, X., Zhou, D., Xu, K., Dawei, F., Dou, Y., Mao, X., and Wang, H. (2025, January 11\u201315). Knowledge Memorization and Rumination for Pre-trained Model-based Class-Incremental Learning. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Nashville, TN, USA.","DOI":"10.1109\/CVPR52734.2025.01911"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"1337","DOI":"10.1109\/TIP.2026.3657170","article-title":"A Few-Shot Class Incremental Learning Method Using Graph Neural Networks","volume":"35","author":"Ma","year":"2026","journal-title":"IEEE Trans. Image Process."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"113207","DOI":"10.1016\/j.patcog.2026.113207","article-title":"PSR: Proactive soft-orthogonal regulation for long-tailed class-incremental learning","volume":"176","author":"Fu","year":"2026","journal-title":"Pattern Recognit."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"He, J. (2024, January 17\u201321). Gradient Reweighting: Towards Imbalanced Class-Incremental Learning. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Seattle, WA, USA.","DOI":"10.1109\/CVPR52733.2024.01577"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Chen, H., Wang, P., Zhou, Z., Zhang, X., Wu, Z., and Jiang, Y.G. (2025, January 19\u201320). Achieving More with Less: Additive Prompt Tuning for Rehearsal-Free Class-Incremental Learning. Proceedings of the IEEE\/CVF International Conference on Computer Vision (ICCV), Honolulu, HI, USA.","DOI":"10.1109\/ICCV51701.2025.00039"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"3240","DOI":"10.1109\/TKDE.2025.3550809","article-title":"Complementary Learning Subnetworks Towards Parameter-Efficient Class-Incremental Learning","volume":"37","author":"Li","year":"2025","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_26","first-page":"22967","article-title":"BOFA: Bridge-Layer Orthogonal Low-Rank Fusion for CLIP-Based Class-Incremental Learning","volume":"40","author":"Li","year":"2026","journal-title":"Proc. AAAI Conf. Artif. Intell."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"115417","DOI":"10.1016\/j.knosys.2026.115417","article-title":"DCCIL: Mitigating class conflicts in incremental learning through dynamic isolation for intelligent fault diagnosis","volume":"337","author":"Wang","year":"2026","journal-title":"Knowl.-Based Syst."},{"key":"ref_28","unstructured":"Zhou, D.W., Wang, Q.W., Ye, H.J., Zhan, D.C., and Liu, Z.H. (2023, January 20\u201325). SimpleCIL: Simple Class-Incremental Learning for Seeing New Classes. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Nashville, TN, USA."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Rebuffi, S.A., Kolesnikov, A., Sperl, G., and Lampert, C.H. (2017, January 21\u201326). iCaRL: Incremental Classifier and Representation Learning. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.587"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Wu, Y., Chen, Y., Wang, L., Ye, Y., Liu, Z., Guo, Y., and Fu, Y. (2019, January 15\u201320). Large Scale Incremental Learning. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), Long Beach, CA, USA.","DOI":"10.1109\/CVPR.2019.00046"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Wang, F.Y., Zhou, D.W., Ye, H.J., and Zhan, D.C. (2022). FOSTER: Feature Boosting and Compression for Class-Incremental Learning. Proceedings of the European Conference on Computer Vision (ECCV), Springer.","DOI":"10.1007\/978-3-031-19806-9_23"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Li, Z., and Hoiem, D. (2016). Learning without forgetting. Proceedings of the European Conference on Computer Vision (ECCV), Springer.","DOI":"10.1007\/978-3-319-46493-0_37"},{"key":"ref_33","unstructured":"Schaul, T., Quan, J., Antonoglou, I., and Silver, D. (2015). Prioritized experience replay. arXiv."}],"container-title":["Algorithms"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-4893\/19\/6\/456\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T04:13:47Z","timestamp":1781064827000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-4893\/19\/6\/456"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,4]]},"references-count":33,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2026,6]]}},"alternative-id":["a19060456"],"URL":"https:\/\/doi.org\/10.3390\/a19060456","relation":{},"ISSN":["1999-4893"],"issn-type":[{"value":"1999-4893","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,4]]}}}