{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T20:32:57Z","timestamp":1780518777180,"version":"3.54.1"},"reference-count":40,"publisher":"MDPI AG","issue":"13","license":[{"start":{"date-parts":[[2020,6,29]],"date-time":"2020-06-29T00:00:00Z","timestamp":1593388800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Grant No. 61902262, 458 U19A2066","award":["Grant No. 61902262, 458 U19A2066"],"award-info":[{"award-number":["Grant No. 61902262, 458 U19A2066"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Due to the openness of an Android system, many Internet of Things (IoT) devices are running the Android system and Android devices have become a common control terminal for IoT devices because of various sensors on them. With the popularity of IoT devices, malware on Android-based IoT devices is also increasing. People\u2019s lives and privacy security are threatened. To reduce such threat, many researchers have proposed new methods to detect Android malware. Currently, most malware detection products on the market are based on malware signatures, which have a fast detection speed and normally a low false alarm rate for known malware families. However, they cannot detect unknown malware and are easily evaded by malware that is confused or packaged. Many new solutions use syntactic features and machine learning techniques to classify Android malware. It has been known that analysis of the Function Call Graph (FCG) can capture behavioral features of malware well. This paper presents a new approach to classifying Android malware based on deep learning and OpCode-level FCG. The FCG is obtained through static analysis of Operation Code (OpCode), and the deep learning model we used is the Long Short-Term Memory (LSTM). We conducted experiments on a dataset with 1796 Android malware samples classified into two categories (obtained from Virusshare and AndroZoo) and 1000 benign Android apps. Our experimental results showed that our proposed approach with an accuracy of     97 %     outperforms the state-of-the-art methods such as those proposed by Nikola et al. and Hou et al. (IJCAI-18) with the accuracy of     97 %     and     91 %    , respectively. The time consumption of our proposed approach is less than the other two methods.<\/jats:p>","DOI":"10.3390\/s20133645","type":"journal-article","created":{"date-parts":[[2020,6,29]],"date-time":"2020-06-29T11:17:17Z","timestamp":1593429437000},"page":"3645","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":49,"title":["OpCode-Level Function Call Graph Based Android Malware Classification Using Deep Learning"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3235-3463","authenticated-orcid":false,"given":"Weina","family":"Niu","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Institute for Cyber Security, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rong","family":"Cao","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Institute for Cyber Security, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaosong","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Institute for Cyber Security, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"},{"name":"Cyberspace Security Research Center, Peng Cheng Laboratory, Shenzhen 518040, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kangyi","family":"Ding","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Institute for Cyber Security, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kaimeng","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Institute for Cyber Security, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ting","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Institute for Cyber Security, University of Electronic Science and Technology of China (UESTC), Chengdu 611731, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,6,29]]},"reference":[{"key":"ref_1","unstructured":"IDC (2020, June 18). The Number of Devices Connected to the INTERNET. Available online: https:\/\/www.idc.com\/getdoc.jsp?containerId=US45527219."},{"key":"ref_2","unstructured":"Stats, S.G. (2020, June 18). The Market Share of Android Smartphones. Available online: http:\/\/gs.statcounter.com\/os-market-share\/mobile\/worldwide."},{"key":"ref_3","unstructured":"Malware Evolution, K.M. (2020, June 18). The Number of Malicious Installation Packages Appeared per Day. Available online: https:\/\/securelist.com\/mobile-malware-evolution-2018\/89689\/."},{"key":"ref_4","unstructured":"Center, I.S. (2020, June 18). The Monetary Loss per Victim Caused by Fraud in China. Available online: http:\/\/zt.360.cn\/1101061855.php?dtid=1101061451&did=610100815."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Yuan, Z., Lu, Y., Wang, Z., and Xue, Y. (2014, January 17\u201322). Droid-Sec: Deep Learning in Android Malware Detection. Proceedings of the 2014 ACM Conference on SIGCOMM, Chicago, IL, USA.","DOI":"10.1145\/2619239.2631434"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"773","DOI":"10.1109\/TIFS.2018.2866319","article-title":"A multimodal deep learning method for Android malware detection using various features","volume":"14","author":"Kim","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Wang, Z., Cai, J., Cheng, S., and Li, W. (2016, January 19\u201321). DroidDeepLearner: Identifying Android malware using deep learning. Proceedings of the 2016 IEEE 37th Sarnoff Symposium, Newark, NJ, USA.","DOI":"10.1109\/SARNOF.2016.7846747"},{"key":"ref_8","unstructured":"Arzt, S. (2020, June 18). FlowDroid. Available online: https:\/\/github.com\/secure-software-engineering\/FlowDroid."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","article-title":"Long short term memory","volume":"9","author":"Hochreiter","year":"1997","journal-title":"Neural comput."},{"key":"ref_10","unstructured":"AVTEST (2020, June 18). AVTEST: One of the world\u2019s Leading Third-Party Inde-Pendent Testing Organizations. Available online: https:\/\/www.av-test.org\/en\/antivirus\/mobile-devices\/."},{"key":"ref_11","unstructured":"VirusTotal (2020, June 18). VirusTotal: Free Online Virus, Malware and URL Scanner. Available online: https:\/\/www.virustotal.com\/."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"492","DOI":"10.1109\/TSE.2016.2615307","article-title":"A taxonomy and qualitative comparison of program analysis techniques for security assessment of Android software","volume":"43","author":"Sadeghi","year":"2016","journal-title":"IEEE Trans. Software Eng."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Wu, D.J., Mao, C.H., Wei, T.E., Lee, H.M., and Wu, K.P. (2012, January 9\u201310). Droidmat: Android malware detection through manifest and api calls tracing. Proceedings of the 2012 Seventh Asia Joint Conference on Information Security, Tokyo, Japan.","DOI":"10.1109\/AsiaJCIS.2012.18"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Burguera, I., Zurutuza, U., and Nadjm-Tehrani, S. (2011, January 17\u201321). Crowdroid: Behavior-based malware detection system for Android. Proceedings of the 1st ACM workshop on Security and privacy in smartphones and mobile devices, Chicago, IL, USA.","DOI":"10.1145\/2046614.2046619"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Sanz, B., Santos, I., Laorden, C., Ugarte-Pedrero, X., and Bringas, P.G. (2012, January 14\u201317). On the automatic categorisation of Android applications. Proceedings of the 2012 IEEE Consumer Communications and Networking Conference (CCNC), Las Vegas, NV, USA.","DOI":"10.1109\/CCNC.2012.6181075"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Arp, D., Spreitzenbarth, M., Hubner, M., Gascon, H., Rieck, K., and Siemens, C. (2014, January 23\u201326). Drebin: Effective and explainable detection of Android malware in your pocket. Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA.","DOI":"10.14722\/ndss.2014.23247"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Hou, S., Saas, A., Ye, Y., and Chen, L. (2016, January 3\u20135). Droiddelver: An Android malware detection system using deep belief network based on api call blocks. Proceedings of the International Conference on Web-Age Information Management, Nanchang, China.","DOI":"10.1007\/978-3-319-47121-1_5"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"266","DOI":"10.1016\/j.compeleceng.2017.02.013","article-title":"Machine learning aided Android malware classification","volume":"61","author":"Milosevic","year":"2017","journal-title":"Comput. Electr. Eng."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"S48","DOI":"10.1016\/j.diin.2018.01.007","article-title":"MalDozer: Automatic framework for Android malware detection using deep learning","volume":"24","author":"Karbab","year":"2018","journal-title":"Digital Investig."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Wu, W.C., and Hung, S.H. (2014, January 5\u20138). DroidDolphin: A dynamic Android malware detection framework using big data and machine learning. Proceedings of the 2014 Conference on Research in Adaptive and Convergent Systems, Towson, MD, USA.","DOI":"10.1145\/2663761.2664223"},{"key":"ref_21","unstructured":"Desnos, A., and Lantz, P. (2011). Droidbox: An Android Application Sandbox for Dynamic Analysis, Lund University. Technical Report."},{"key":"ref_22","unstructured":"Chang, S. (2013). APE: A Smart Automatic Testing Environment for Android Malware, Department of Computer Science and Information Engineering, National Taiwan University."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Tam, K., Khan, S.J., Fattori, A., and Cavallaro, L. (2015, January 8\u201311). CopperDroid: Automatic Reconstruction of Android Malware Behaviors. Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA.","DOI":"10.14722\/ndss.2015.23145"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Wong, M.Y., and Lie, D. (2016, January 21\u201324). IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android Malware. Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA.","DOI":"10.14722\/ndss.2016.23118"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Zhauniarovich, Y., Ahmad, M., Gadyatskaya, O., Crispo, B., and Massacci, F. (2015, January 2\u20134). Stadyna: Addressing the problem of dynamic code updates in the security analysis of Android applications. Proceedings of the 5th ACM Conference on Data and Application Security and Privacy, San Antonio, TX, USA.","DOI":"10.1145\/2699026.2699105"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"114","DOI":"10.1109\/TST.2016.7399288","article-title":"Droiddetector: Android malware characterization and detection using deep learning","volume":"21","author":"Yuan","year":"2016","journal-title":"Tsinghua Sci. Technol."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Hou, S., Ye, Y., Song, Y., and Abdulhayoglu, M. (2018, January 13\u201319). Make Evasion Harder: An Intelligent Android Malware Detection System. Proceedings of the 27th International Joint Conference on Artificial Intelligence (IJCAI), Stockholm, Sweden.","DOI":"10.24963\/ijcai.2018\/737"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Rumelhart, D., Hinton, G., and Williams, R. (1988). Learning Internal Representations by Error Propagation. Readings in Cognitive Science, California Univ San Diego La Jolla Inst for Cognitive Science.","DOI":"10.1016\/B978-1-4832-1446-7.50035-2"},{"key":"ref_29","unstructured":"Lab, T.M.S. (2020, June 18). 2018 Mobile Security Report. Available online: https:\/\/m.qq.com\/security_lab\/news_detail_489.html."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Hurier, M., Suarez-Tangil, G., Dash, S.K., Bissyand\u00e9, T.F., Le Traon, Y., Klein, J., and Cavallaro, L. (2017, January 20\u201321). Euphony: Harmonious Unification of Cacophonous Anti-Virus Vendor Labels for Android Malware. Proceedings of the 2017 IEEE\/ACM 14th International Conference on Mining Software Repositories (MSR), Buenos Aires, Argentina.","DOI":"10.1109\/MSR.2017.57"},{"key":"ref_31","unstructured":"Dedexer (2020, June 18). Dedexer: A Disassembler Tool for DEX Files. Available online: http:\/\/dedexer.sourceforge.net\/."},{"key":"ref_32","unstructured":"Drissi, M., Watkins, O., Khant, A., Ojha, V., Sandoval, P., Segev, R., Weiner, E., and Keller, R. (2018). Program language translation using a grammar-driven tree-to-tree model. arXiv."},{"key":"ref_33","unstructured":"VirusShare (2020, June 18). VirusShare.com. Available online: https:\/\/virusshare.com\/."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Allix, K., Bissyand\u00e9, T.F., Klein, J., and Le Traon, Y. (2016, January 14\u201315). Androzoo: Collecting millions of Android apps for the research community. Proceedings of the 13th Working Conference on Mining Software Repositories (MSR), Austin, TX, USA.","DOI":"10.1145\/2901739.2903508"},{"key":"ref_35","unstructured":"Scikit Learn (2020, June 18). Scikit-Learn: Machine Learning in Python. Available online: http:\/\/scikit-learn.org\/stable\/."},{"key":"ref_36","unstructured":"TensorFlow (2020, June 18). TensorFlow: An Open Source Software Library for Machine intelligence. Available online: https:\/\/www.tensorflow.org\/."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"531","DOI":"10.3233\/IDA-130592","article-title":"ROC analysis of classifiers in machine learning: A survey","volume":"17","author":"Majnik","year":"2013","journal-title":"Intell. Data Anal."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Rasthofer, S., Arzt, S., and Bodden, E. (2014, January 23\u201326). A Machine-learning Approach for Classifying and Categorizing Android Sources and Sinks. Proceedings of the Network and Distributed System Security Symposium (NDSS), San Diego, CA, USA.","DOI":"10.14722\/ndss.2014.23039"},{"key":"ref_39","first-page":"1799","article-title":"The SHOGUN machine learning toolbox","volume":"11","author":"Sonnenburg","year":"2010","journal-title":"J. Mach. Learn. Res."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Ross, A.S., and Doshi-Velez, F. (2018, January 2\u20137). Improving the Adversarial Robustness and Interpretability of Deep Neural Networks by Regularizing their Input Gradients. Proceedings of the Thirty-Second AAAI Conference on Artificial Intelligence, New Orleans, LA, USA.","DOI":"10.1609\/aaai.v32i1.11504"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/13\/3645\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:44:35Z","timestamp":1760175875000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/13\/3645"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,6,29]]},"references-count":40,"journal-issue":{"issue":"13","published-online":{"date-parts":[[2020,7]]}},"alternative-id":["s20133645"],"URL":"https:\/\/doi.org\/10.3390\/s20133645","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,6,29]]}}}