{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T08:36:35Z","timestamp":1765528595539,"version":"3.48.0"},"reference-count":36,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2025,12,11]],"date-time":"2025-12-11T00:00:00Z","timestamp":1765411200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Ningxia Natural Science Foundation Project","award":["2025AAC030079"],"award-info":[{"award-number":["2025AAC030079"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61862001"],"award-info":[{"award-number":["61862001"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>In recent years, the frequent emergence of Android malware has posed a significant threat to user security. The redundancy of features in malicious software samples and the instability of individual model performance have also introduced numerous challenges to malware detection. To address these issues, this paper proposes a malware detection framework named Mass-Droid, based on Multi-feature and Multi-layer Screening for adaptive Stacking integration. First, three types of features are extracted from APK files: permission features, API call features, and opcode sequences. Then, a three-layer feature screening mechanism is designed to effectively eliminate feature redundancy, improve detection accuracy, and reduce the computational complexity of the model. To tackle the problem of high performance fluctuations and limited generalization ability in single models, this paper proposes an adaptive Stacking integration method (Adaptive-Stacking). By dynamically adjusting the weights of base classifiers, this method significantly enhances the stability and generalization performance of the ensemble model when dealing with complex and diverse malware samples. The experimental results demonstrate that the MaSS-Droid framework can effectively mitigate overfitting, improve the model\u2019s generalization capability, reduce feature redundancy, and significantly enhance the overall stability and accuracy of malware detection.<\/jats:p>","DOI":"10.3390\/e27121252","type":"journal-article","created":{"date-parts":[[2025,12,11]],"date-time":"2025-12-11T17:13:34Z","timestamp":1765473214000},"page":"1252","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["MaSS-Droid: Android Malware Detection Framework Using Multi-Layer Feature Screening and Stacking Integration"],"prefix":"10.3390","volume":"27","author":[{"given":"Zihao","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, North Minzu University, Yinchuan 750021, China"},{"name":"Key Laboratory of Intelligent Image and Graphic Processing of State Ethnic Affairs Commission, North Minzu University, Yinchuan 750021, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1436-2219","authenticated-orcid":false,"given":"Qiang","family":"Han","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, North Minzu University, Yinchuan 750021, China"},{"name":"Key Laboratory of Intelligent Image and Graphic Processing of State Ethnic Affairs Commission, North Minzu University, Yinchuan 750021, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhichao","family":"Shi","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, North Minzu University, Yinchuan 750021, China"},{"name":"Key Laboratory of Intelligent Image and Graphic Processing of State Ethnic Affairs Commission, North Minzu University, Yinchuan 750021, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2025,12,11]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3708500","article-title":"Characterization of Android Malwares and their families","volume":"57","author":"Sharma","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"128010","DOI":"10.1016\/j.neucom.2024.128010","article-title":"A review of deep learning based malware detection techniques","volume":"598","author":"Wang","year":"2024","journal-title":"Neurocomputing"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Bermejo Higuera, J., Morales Moreno, J., Bermejo Higuera, J.R., Sicilia Montalvo, J.A., Barreiro Martillo, G.J., and Sureda Riera, T.M. (2024). Benchmarking Android Malware Analysis Tools. Electronics, 13.","DOI":"10.3390\/electronics13112103"},{"key":"ref_4","first-page":"1","article-title":"Temporal-Incremental Learning for Android Malware Detection","volume":"34","author":"Sun","year":"2025","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.future.2021.11.030","article-title":"A study on malicious software behaviour analysis and detection techniques: Taxonomy, current trends and challenges","volume":"130","author":"Maniriho","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"2825","DOI":"10.1109\/LSP.2024.3475354","article-title":"Enhanced Dynamic Analysis for Malware Detection with Gradient Attack","volume":"31","author":"Yan","year":"2024","journal-title":"IEEE Signal Process. Lett."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Ili\u0107, S., Gnjatovi\u0107, M., Tot, I., Jovanovi\u0107, B., Ma\u010dek, N., and Gavrilovi\u0107 Bo\u017eovi\u0107, M. (2024). Going beyond API Calls in Dynamic Malware Analysis: A Novel Dataset. Electronics, 13.","DOI":"10.3390\/electronics13173553"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Aldhafferi, N. (2024). Android Malware Detection Using Support Vector Regression for Dynamic Feature Analysis. Information, 15.","DOI":"10.3390\/info15100658"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"122255","DOI":"10.1016\/j.eswa.2023.122255","article-title":"Detection approaches for android malware: Taxonomy and review analysis","volume":"238","author":"Manzil","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"97","DOI":"10.1007\/s10207-025-01013-3","article-title":"Malware classification method based on feature fusion","volume":"24","author":"Yan","year":"2025","journal-title":"Int. J. Inf. Secur."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"10","DOI":"10.1186\/s13635-025-00197-4","article-title":"Malicious software identification based on deep learning algorithms and API feature extraction","volume":"2025","author":"Sun","year":"2025","journal-title":"EURASIP J. Inf. Secur."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Hemalatha, J., Roseline, S.A., Geetha, S., Kadry, S., and Dama\u0161evi\u010dius, R. (2021). An Efficient DenseNet-Based Deep Learning Model for Malware Detection. Entropy, 23.","DOI":"10.3390\/e23030344"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"2789","DOI":"10.1007\/s10586-019-03045-6","article-title":"SysDroid: A dynamic ML-based android malware analyzer using system call traces","volume":"23","author":"Ananya","year":"2020","journal-title":"Clust. Comput."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"5183","DOI":"10.1007\/s00521-020-05309-4","article-title":"MLDroid\u2014Framework for Android malware detection using machine learning techniques","volume":"33","author":"Mahindru","year":"2021","journal-title":"Neural Comput. Appl."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Arif, J.M., Razak, M.F.A., Awang, S., Mat, S.R.T., Ismail, N.S.N., and Firdaus, A. (2021). A static analysis approach for Android permission-based malware detection systems. PLoS ONE, 16.","DOI":"10.1371\/journal.pone.0257968"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"3216","DOI":"10.1109\/TII.2017.2789219","article-title":"Significant Permission Identification for Machine-Learning-Based Android Malware Detection","volume":"14","author":"Li","year":"2018","journal-title":"IEEE Trans. Ind. Inform."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"33","DOI":"10.1186\/s13635-024-00182-3","article-title":"Static analysis framework for permission-based dataset generation and android malware detection using machine learning","volume":"2024","author":"Pathak","year":"2024","journal-title":"EURASIP J. Inf. Secur."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1968","DOI":"10.1109\/TIFS.2019.2950134","article-title":"PermPair: Android Malware Detection Using Permission Pairs","volume":"15","author":"Arora","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"599","DOI":"10.1016\/j.neucom.2018.09.102","article-title":"Learning to detect Android malware via opcode sequences","volume":"396","author":"Acarman","year":"2020","journal-title":"Neurocomputing"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1199","DOI":"10.1109\/TIFS.2023.3330337","article-title":"Attention-Based API Locating for Malware Techniques","volume":"19","author":"Wong","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"1518","DOI":"10.1002\/spe.2971","article-title":"Mutual Information and Feature Importance Gradient Boosting: Automatic byte n-gram feature reranking for Android malware detection","volume":"51","author":"Varadharajan","year":"2021","journal-title":"Softw. Pract. Exp."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"9464","DOI":"10.1016\/j.jksuci.2021.11.004","article-title":"A multi-tiered feature selection model for android malware detection based on Feature discrimination and Information Gain","volume":"34","author":"Bhat","year":"2022","journal-title":"J. King Saud Univ.-Comput. Inf. Sci."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"AlJarrah, M.N., Yaseen, Q.M., and Mustafa, A.M. (2022). A Context-Aware Android Malware Detection Approach Using Machine Learning. Information, 13.","DOI":"10.3390\/info13120563"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"420","DOI":"10.1016\/j.ins.2020.08.082","article-title":"AI-HydRa: Advanced hybrid approach using random forest and deep learning for malware classification","volume":"546","author":"Yoo","year":"2021","journal-title":"Inf. Sci."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"5558","DOI":"10.1109\/TKDE.2021.3067658","article-title":"A Hybrid Deep Network Framework for Android Malware Detection","volume":"34","author":"Zhu","year":"2022","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3162625","article-title":"Lightweight, Obfuscation-Resilient Detection and Family Identification of Android Malware","volume":"26","author":"Garcia","year":"2018","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"114971","DOI":"10.1016\/j.eswa.2021.114971","article-title":"Identifying meaningful clusters in malware data","volume":"177","year":"2021","journal-title":"Expert Syst. Appl."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"107168","DOI":"10.1016\/j.engappai.2023.107168","article-title":"Feature selection using a sinusoidal sequence combined with mutual information","volume":"126","author":"Yuan","year":"2023","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"984","DOI":"10.1109\/TNSE.2020.2996379","article-title":"SEDMDroid: An Enhanced Stacking Ensemble Framework for Android Malware Detection","volume":"8","author":"Zhu","year":"2021","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"241","DOI":"10.1016\/S0893-6080(05)80023-1","article-title":"Stacked generalization","volume":"5","author":"Wolpert","year":"1992","journal-title":"Neural Netw."},{"key":"ref_31","first-page":"2907","article-title":"Stacking-based ensemble model for malware detection in android devices","volume":"15","author":"Joshi","year":"2023","journal-title":"Int. J. Inf. Technol."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"104320","DOI":"10.1016\/j.compind.2025.104320","article-title":"Autonomous vehicle crash risk modeling by integrating data augmentation and two-layer stacking","volume":"171","author":"Zhu","year":"2025","journal-title":"Comput. Ind."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"113338","DOI":"10.1016\/j.asoc.2025.113338","article-title":"Malware detection model based on stacking ensemble technique","volume":"180","author":"Li","year":"2025","journal-title":"Appl. Soft Comput."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"3977","DOI":"10.1109\/TIFS.2023.3287395","article-title":"Comprehensive Android Malware Detection Based on Federated Learning Architecture","volume":"18","author":"Fang","year":"2023","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"101873","DOI":"10.1016\/j.cose.2020.101873","article-title":"HYDRA: A multimodal deep learning framework for malware classification","volume":"95","author":"Gibert","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Wu, Y., Li, X., Zou, D., Yang, W., Zhang, X., and Jin, H. (2019, January 11\u201315). MalScan: Fast Market-Wide Mobile Malware Scanning by Social-Network Centrality Analysis. Proceedings of the 2019 34th IEEE\/ACM International Conference on Automated Software Engineering (ASE), San Diego, CA, USA.","DOI":"10.1109\/ASE.2019.00023"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/12\/1252\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,12]],"date-time":"2025-12-12T08:32:43Z","timestamp":1765528363000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/27\/12\/1252"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,11]]},"references-count":36,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["e27121252"],"URL":"https:\/\/doi.org\/10.3390\/e27121252","relation":{},"ISSN":["1099-4300"],"issn-type":[{"type":"electronic","value":"1099-4300"}],"subject":[],"published":{"date-parts":[[2025,12,11]]}}}