{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T14:56:54Z","timestamp":1787065014950,"version":"build-2736575974"},"reference-count":41,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2025,8,1]],"date-time":"2025-08-01T00:00:00Z","timestamp":1754006400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Centre National pour la Recherche Scientifique et Technique (CNRST)"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>As Android malware grows increasingly sophisticated, traditional detection methods struggle to keep pace, creating an urgent need for robust, interpretable, and real-time solutions to safeguard mobile ecosystems. This study introduces YoloMal-XAI, a novel deep learning framework that transforms Android application files into RGB image representations by mapping DEX (Dalvik Executable), Manifest.xml, and Resources.arsc files to distinct color channels. Evaluated on the CICMalDroid2020 dataset using YOLO11 pretrained classification models, YoloMal-XAI achieves 99.87% accuracy in binary classification and 99.56% in multi-class classification (Adware, Banking, Riskware, SMS, and Benign). Compared to ResNet-50, GoogLeNet, and MobileNetV2, YOLO11 offers competitive accuracy with at least 7\u00d7 faster training over 100 epochs. Against YOLOv8, YOLO11 achieves comparable or superior accuracy while reducing training time by up to 3.5\u00d7. Cross-corpus validation using Drebin and CICAndMal2017 further confirms the model\u2019s generalization capability on previously unseen malware. An ablation study highlights the value of integrating DEX, Manifest, and Resources components, with the full RGB configuration consistently delivering the best performance. Explainable AI (XAI) techniques\u2014Grad-CAM, Grad-CAM++, Eigen-CAM, and HiRes-CAM\u2014are employed to interpret model decisions, revealing the DEX segment as the most influential component. These results establish YoloMal-XAI as a scalable, efficient, and interpretable framework for Android malware detection, with strong potential for future deployment on resource-constrained mobile devices.<\/jats:p>","DOI":"10.3390\/jcp5030052","type":"journal-article","created":{"date-parts":[[2025,8,5]],"date-time":"2025-08-05T07:49:58Z","timestamp":1754380198000},"page":"52","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["YoloMal-XAI: Interpretable Android Malware Classification Using RGB Images and YOLO11"],"prefix":"10.3390","volume":"5","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-3822-0463","authenticated-orcid":false,"given":"Chaymae","family":"El Youssofi","sequence":"first","affiliation":[{"name":"Engineering Sciences Laboratory, Ibn Tofail University, Kenitra 14000, Morocco"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1072-0461","authenticated-orcid":false,"given":"Khalid","family":"Chougdali","sequence":"additional","affiliation":[{"name":"Engineering Sciences Laboratory, Ibn Tofail University, Kenitra 14000, Morocco"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,8,1]]},"reference":[{"key":"ref_1","unstructured":"(2025, July 15). What\u2019s Android\u2019s Market Share? (Updated Jan 2025). Available online: https:\/\/soax.com\/research\/android-market-share."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"100529","DOI":"10.1016\/j.cosrev.2022.100529","article-title":"A Comprehensive Survey on Deep Learning Based Malware Detection Techniques","volume":"47","author":"Sethuraman","year":"2023","journal-title":"Comput. Sci. Rev."},{"key":"ref_3","unstructured":"(2025, July 15). Si Tienes Esta Aplicaci\u00f3n en tu Android la Estafa ha Comenzado. ElHuffPost. Available online: https:\/\/www.huffingtonpost.es\/tecnologia\/si-tienes-aplicacion-android-estafa-comenzado.html."},{"key":"ref_4","unstructured":"(2025, July 15). New Android Spyware Warning\u2014Do Not Install This App on Your Phone. Available online: https:\/\/www.forbes.com\/sites\/zakdoffman\/2025\/01\/04\/new-android-spyware-warning-do-not-install-this-app-on-your-phone\/."},{"key":"ref_5","unstructured":"Catal\u00e1n, C.C. (2025, July 15). Descubren una Empresa que ha Distribuido Software Esp\u00eda a Trav\u00e9s de Aplicaciones Android Durante A\u00f1os. Meristation. Available online: https:\/\/as.com\/meristation\/betech\/descubren-una-empresa-que-ha-distribuido-software-espia-a-traves-de-aplicaciones-android-durante-anos-n\/."},{"key":"ref_6","unstructured":"Ruiz, D. (2025, July 15). Phishing Evolves Beyond Email to Become Latest Android App Threat. Malwarebytes. Available online: https:\/\/www.malwarebytes.com\/blog\/news\/2025\/02\/phishing-evolves-beyond-email-to-become-latest-android-app-threat."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"100365","DOI":"10.1016\/j.cosrev.2021.100365","article-title":"A Survey of Android Application and Malware Hardening","volume":"39","author":"Sihag","year":"2021","journal-title":"Comput. Sci. Rev."},{"key":"ref_8","unstructured":"Chaurasia, P. (2015). Dynamic Analysis of Android Malware Using DroidBox. [Master\u2019s Thesis, Tennessee State University]."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"122255","DOI":"10.1016\/j.eswa.2023.122255","article-title":"Detection Approaches for Android Malware: Taxonomy and Review Analysis","volume":"238","year":"2024","journal-title":"Expert Syst. Appl."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"100130","DOI":"10.1016\/j.teler.2024.100130","article-title":"Android Malware Detection and Identification Frameworks by Leveraging the Machine and Deep Learning Techniques: A Comprehensive Review","volume":"14","author":"Smmarwar","year":"2024","journal-title":"Telemat. Inform. Rep."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., and Manjunath, B.S. (2011, January 20). Malware Images: Visualization and Automatic Classification. Proceedings of the 8th International Symposium on Visualization for Cyber Security, Pittsburgh, PA, USA. VizSec \u201911.","DOI":"10.1145\/2016904.2016908"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"181102","DOI":"10.1109\/ACCESS.2020.3028370","article-title":"Review of Android Malware Detection Based on Deep Learning","volume":"8","author":"Wang","year":"2020","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Gritzalis, D., Choo, K.-K.R., and Patsakis, C. (2025). Android Malware Detection Based on Novel Representations of Apps. Malware: Handbook of Prevention and Detection, Springer Nature.","DOI":"10.1007\/978-3-031-66245-4"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1016\/j.procs.2022.09.047","article-title":"On the Resilience of Shallow Machine Learning Classification in Image-Based Malware Detection","volume":"207","author":"Casolare","year":"2022","journal-title":"Procedia Comput. Sci."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Wang, G., Ciptadi, A., and Ahmadzadeh, A. (2021). DexRay: A Simple, yet Effective Deep Learning Approach to Android Malware Detection Based on Image Representation of Bytecode. Deployable Machine Learning for Security Defense, Springer International Publishing.","DOI":"10.1007\/978-3-030-87839-9"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Mercaldo, F., Martinelli, F., and Santone, A. (2024). Deep Convolutional Generative Adversarial Networks in Image-Based Android Malware Detection. Computers, 13.","DOI":"10.3390\/computers13060154"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1007\/s10044-024-01381-x","article-title":"A New Method for Tuning the CNN Pre-Trained Models as a Feature Extractor for Malware Detection","volume":"28","year":"2025","journal-title":"Pattern Anal. Appl."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"2646","DOI":"10.1109\/JIOT.2024.3477442","article-title":"DTDroid: Adversarial Packed Android Malware Detection Based on Traffic and Dynamic Behavioral","volume":"12","author":"Tang","year":"2025","journal-title":"IEEE Internet Things J."},{"key":"ref_19","first-page":"11","article-title":"Android Malware Detection Through CNN Ensemble Learning on Grayscale Images","volume":"16","author":"Chaymae","year":"2025","journal-title":"Int. J. Adv. Comput. Sci. Appl. (IJACSA)"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Chaymae, E.Y., and Khalid, C. (2025, January 15\u201316). Image-Based Approach for Android Malware Detection Using APK Component Fusion and Deep Learning. Proceedings of the 2025 5th International Conference on Innovative Research in Applied Science, Engineering and Technology (IRASET), Fez, Morocco.","DOI":"10.1109\/IRASET64571.2025.11008274"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"107138","DOI":"10.1016\/j.comnet.2020.107138","article-title":"IMCFN: Image-Based Malware Classification Using Fine-Tuned Convolutional Neural Network Architecture","volume":"171","author":"Vasan","year":"2020","journal-title":"Comput. Netw."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"102622","DOI":"10.1016\/j.cose.2022.102622","article-title":"EfficientNet Convolutional Neural Networks-Based Android Malware Detection","volume":"115","author":"Yadav","year":"2022","journal-title":"Comput. Secur."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"1748","DOI":"10.1111\/coin.12532","article-title":"A Two-Stage Deep Learning Framework for Image-Based Android Malware Detection and Variant Classification","volume":"38","author":"Yadav","year":"2022","journal-title":"Comput. Intell."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"7671967","DOI":"10.1155\/2022\/7671967","article-title":"Explainable Artificial Intelligence-Based IoT Device Malware Detection Mechanism Using Image Visualization and Fine-Tuned CNN-Based Transfer Learning Model","volume":"2022","author":"Naeem","year":"2022","journal-title":"Comput. Intell. Neurosci."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"55","DOI":"10.1007\/s11554-023-01311-w","article-title":"RT-Droid: A Novel Approach for Real-Time Android Application Analysis with Transfer Learning-Based CNN Models","volume":"20","author":"Tasyurek","year":"2023","journal-title":"J. Real-Time Image Process."},{"key":"ref_26","first-page":"4093","article-title":"Deep Convolution Neural Networks for Image-Based Android Malware Classification","volume":"82","author":"Ksibi","year":"2025","journal-title":"Comput. Mater. Contin."},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"102662","DOI":"10.1016\/j.inffus.2024.102662","article-title":"Detecting Android Malware: A Multimodal Fusion Method with Fine-Grained Feature","volume":"114","author":"Li","year":"2025","journal-title":"Inf. Fusion"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"110039","DOI":"10.1016\/j.compeleceng.2024.110039","article-title":"CNN-ViT Synergy: An Efficient Android Malware Detection Approach through Deep Learning","volume":"123","author":"Wasif","year":"2025","journal-title":"Comput. Electr. Eng."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Ehsan, A., Catal, C., and Mishra, A. (2022). Detecting Malware by Analyzing App Permissions on Android Platform: A Systematic Literature Review. Sensors, 22.","DOI":"10.3390\/s22207928"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Yerima, S.Y., Sezer, S., and Muttik, I. (2014, January 10\u201312). Android Malware Detection Using Parallel Machine Learning Classifiers. Proceedings of the 2014 Eighth International Conference on Next Generation Mobile Apps, Services and Technologies, Oxford, UK.","DOI":"10.1109\/NGMAST.2014.23"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Afonso, V., Bianchi, A., Fratantonio, Y., Doupe, A., Polino, M., De Geus, P., Kruegel, C., and Vigna, G. (2016, January 21\u201324). Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing Policy. Proceedings of the 2016 Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2016.23384"},{"key":"ref_32","unstructured":"(2025, July 15). Ultralytics. Computer Vision Tasks Supported by Ultralytics YOLOv11. Available online: https:\/\/docs.ultralytics.com\/tasks."},{"key":"ref_33","unstructured":"Khanam, R., and Hussain, M. (2024). YOLOv11: An Overview of the Key Architectural Enhancements. arXiv."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"e1366","DOI":"10.7717\/peerj-cs.1366","article-title":"Artificial Intelligence-Driven Malware Detection Framework for Internet of Things Environment","volume":"9","author":"Alsubai","year":"2023","journal-title":"PeerJ Comput. Sci."},{"key":"ref_35","unstructured":"(2025, July 15). Ultralytics. Classify. Available online: https:\/\/docs.ultralytics.com\/tasks\/classify."},{"key":"ref_36","unstructured":"Gildenblat, J. (2025, July 14). Jacobgil\/Pytorch-Grad-Cam. Available online: https:\/\/github.com\/jacobgil\/pytorch-grad-cam."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"102303","DOI":"10.1016\/j.inffus.2024.102303","article-title":"Adversarial Attacks and Defenses in Explainable Artificial Intelligence: A Survey","volume":"107","author":"Baniecki","year":"2024","journal-title":"Inf. Fusion"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Mahdavifar, S., Abdul Kadir, A.F., Fatemi, R., Alhadidi, D., and Ghorbani, A.A. (2020, January 17\u201322). Dynamic Android Malware Category Classification Using Semi-Supervised Deep Learning. Proceedings of the 2020 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC\/PiCom\/CBDCom\/CyberSciTech), Calgary, AB, Canada.","DOI":"10.1109\/DASC-PICom-CBDCom-CyberSciTech49142.2020.00094"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Arp, D., Spreitzenbarth, M., H\u00fcbner, M., Gascon, H., and Rieck, K. (2014, January 23\u201326). Drebin: Effective and Explainable Detection of Android Malware in Your Pocket. Proceedings of the 2014 Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2014.23247"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Lashkari, A.H., Kadir, A.F.A., Taheri, L., and Ghorbani, A.A. (2018, January 22\u201325). Toward Developing a Systematic Approach to Generate Benchmark Android Malware Datasets and Classification. Proceedings of the 2018 International Carnahan Conference on Security Technology (ICCST), Montreal, QC, Canada.","DOI":"10.1109\/CCST.2018.8585560"},{"key":"ref_41","unstructured":"Loshchilov, I., and Hutter, F. (2019, January 6\u20139). Decoupled Weight Decay Regularization. Proceedings of the 7th International Conference on Learning Representations (ICLR 2019), New Orleans, LA, USA."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/52\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:20:42Z","timestamp":1760034042000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/3\/52"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,1]]},"references-count":41,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2025,9]]}},"alternative-id":["jcp5030052"],"URL":"https:\/\/doi.org\/10.3390\/jcp5030052","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,8,1]]}}}