{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T15:05:08Z","timestamp":1784041508017,"version":"3.55.0"},"reference-count":34,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2021,6,22]],"date-time":"2021-06-22T00:00:00Z","timestamp":1624320000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>With the rapid increase in the number of Android malware, the image-based analysis method has become an effective way to defend against symmetric encryption and confusing malware. At present, the existing Android malware bytecode image detection method, based on a convolution neural network (CNN), relies on a single DEX file feature and requires a large amount of computation. To solve these problems, we combine the visual features of the XML file with the data section of the DEX file for the first time, and propose a new Android malware detection model, based on a temporal convolution network (TCN). First, four gray-scale image datasets with four different combinations of texture features are created by combining XML files and DEX files. Then the image size is unified and input to the designed neural network with three different convolution methods for experimental validation. The experimental results show that adding XML files is beneficial for Android malware detection. The detection accuracy of the TCN model is 95.44%, precision is 95.45%, recall rate is 95.45%, and F1-Score is 95.44%. Compared with other methods based on the traditional CNN model or lightweight MobileNetV2 model, the method proposed in this paper, based on the TCN model, can effectively utilize bytecode image sequence features, improve the accuracy of detecting Android malware and reduce its computation.<\/jats:p>","DOI":"10.3390\/sym13071107","type":"journal-article","created":{"date-parts":[[2021,6,22]],"date-time":"2021-06-22T22:10:59Z","timestamp":1624399859000},"page":"1107","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":49,"title":["Android Malware Detection Using TCN with Bytecode Image"],"prefix":"10.3390","volume":"13","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6477-7781","authenticated-orcid":false,"given":"Wenhui","family":"Zhang","sequence":"first","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nurbol","family":"Luktarhan","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6008-7863","authenticated-orcid":false,"given":"Chao","family":"Ding","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bei","family":"Lu","sequence":"additional","affiliation":[{"name":"College of Information Science and Engineering, Xinjiang University, Urumqi 830000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2021,6,22]]},"reference":[{"key":"ref_1","unstructured":"National Internet Emergency Center (2020, October 01). Overview of China\u2019s Internet Network Security Situation in 2019. Available online: https:\/\/www.cert.org.cn\/publish\/main\/46\/2020\/20200811124544754595627\/20200811124544754595627_.html."},{"key":"ref_2","unstructured":"(2020, August 15). Google Play Protect. 2018. Android. Available online: https:\/\/www.android.com\/play-protect\/."},{"key":"ref_3","unstructured":"(2020, August 20). Android\u2019s Built-In Google Play Protect Protection Is Useless. Available online: https:\/\/www.cnbeta.com\/articles\/tech\/759727.htm."},{"key":"ref_4","unstructured":"Naway, A., and Li, Y. (2020). A Review on The Use of Deep Learning in Android Malware Detection. arXiv."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Ganesh, M., Pednekar, P., Prabhuswamy, P., Nair, D.S., Park, Y., and Jeon, H. (2017, January 24\u201325). CNN-based android malware detection. Proceedings of the 2017 International Conference on Software Security and Assurance (ICSSA), Altoona, PA, USA.","DOI":"10.1109\/ICSSA.2017.18"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Ding, Y., Zhao, W., Wang, Z., and Wang, L. (2018, January 15\u201318). Automaticlly Learning Featurs Of Android Apps Using CNN. Proceedings of the 2018 International Conference on Machine Learning and Cybernetics (ICMLC), Chengdu, China.","DOI":"10.1109\/ICMLC.2018.8526935"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"McLaughlin, N., del Rincon, J.M., Kang, B., Yerima, S., Miller, P., Sezer, S., Safaei, Y., Trickel, E., Zhao, Z., and Doup\u00e9, A. (2017, January 22\u201324). Deep Android Malware Detection. Proceedings of the Seventh ACM on Conference on Data and Application Security and Privacy\u2014CODASPY \u201917, Scottsdale, AZ, USA.","DOI":"10.1145\/3029806.3029823"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Salah, A., Shalabi, E., and Khedr, W. (2020). A Lightweight Android Malware Classifier Using Novel Feature Selection Methods. Symmetry, 12.","DOI":"10.3390\/sym12050858"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s40064-015-1356-1","article-title":"Accurate mobile malware detection and classification in the cloud","volume":"4","author":"Wang","year":"2015","journal-title":"Springerplus"},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"9","DOI":"10.1007\/s11416-014-0226-7","article-title":"Identifying Android malware using dynamically obtained features","volume":"11","author":"Afonso","year":"2015","journal-title":"J. Comput. Virol. Hack. Tech."},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Bagheri, H., Sadeghi, A., Jabbarvand, R., and Malek, S. (July, January 28). Practical, Formal Synthesis and Automatic Enforcement of Security Policies for Android. Proceedings of the 2016 46th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN), Toulouse, France.","DOI":"10.1109\/DSN.2016.53"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"4321","DOI":"10.1109\/ACCESS.2018.2792941","article-title":"SAMADroid: A novel 3-level hybrid malware detection model for Android operating system","volume":"6","author":"Arshad","year":"2018","journal-title":"IEEE Access"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Kouliaridis, V., Kambourakis, G., Geneiatakis, D., and Potha, N. (2020). Two Anatomists Are Better than One\u2014Dual-Level Android Malware Detection. Symmetry, 12.","DOI":"10.3390\/sym12071128"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"141","DOI":"10.1007\/s10207-014-0250-0","article-title":"Mobile-sandbox: Combining static and dynamic analysis with machine-learning techniques","volume":"14","author":"Spreitzenbarth","year":"2015","journal-title":"Int. J. Inf. Secur."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Manzhi, Y., and Qiaoyan, W. (2017, January 28\u201330). Detecting android malware by applying classification techniques on images patterns. Proceedings of the 2017 IEEE 2nd International Conference on Cloud Computing and Big Data Analysis (ICCCBDA), Chengdu, China.","DOI":"10.1109\/ICCCBDA.2017.7951936"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Orralba, A., Murphy, K.P., Freeman, W.T., and Rubin, M.A. (2003, January 13\u201316). Context-based vision systems for place and object recognition. Proceedings of the International Conference on Computer Vision (ICCV), Nice, France.","DOI":"10.1109\/ICCV.2003.1238354"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"145","DOI":"10.1023\/A:1011139631724","article-title":"Modeling the shape of a scene: A holistic representation of the spatial envelope","volume":"42","author":"Oliva","year":"2001","journal-title":"Int. J. Comput. Vis."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Xiao, X. (2019, January 11\u201315). An Image-Inspired and CNN-Based Android Malware Detection Approach. Proceedings of the 2019 34th IEEEACM International Conference on Automated Software Engineering (ASE), San Diego, CA, USA.","DOI":"10.1109\/ASE.2019.00155"},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1007\/s42452-019-1931-0","article-title":"Future developments in standardisation of cyber risk in the Internet of Things (IoT)","volume":"2","author":"Radanliev","year":"2020","journal-title":"SN Appl. Sci."},{"key":"ref_20","unstructured":"(2020, November 20). Dexparser (Pil Fork). Available online: https:\/\/pypi.org\/project\/dexparser\/0.0.1\/."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Nataraj, L., Karthikeyan, S., Jacob, G., and Manjunath, B. (2011, January 20). Malware images: Visualization and automatic classification. Proceedings of the 8th International Symposium on Visualization for Cyber Security, VizSec\u201911, Pittsburgh, PA, USA.","DOI":"10.1145\/2016904.2016908"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Jung, D.-S., Lee, S.-J., and Euom, I.-C. (2020). ImageDetox: Method for the Neutralization of Malicious Code Hidden in Image Files. Symmetry, 12.","DOI":"10.3390\/sym12101621"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Kumar, A., Sagar, K.P., Kuppusamy, K.S., and Aghila, G. (2016, January 7\u20138). Machine learning based malware classification for Android applications using multimodal image representations. Proceedings of the 2016 10th International Conference on Intelligent Systems and Control (ISCO), Coimbatore, India.","DOI":"10.1109\/ISCO.2016.7726949"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Darus, F.M., Ahmad, S.N.A., and Ariffin, A.F.M. (2018, January 13\u201315). Android Malware Detection Using Machine Learning on Image Patterns. Proceedings of the 2018 Cyber Resilience Conference (CRC), Putrajaya, Malaysia.","DOI":"10.1109\/CR.2018.8626828"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Huang, T.H., and Kao, H. (2018, January 10\u201313). R2-D2: ColoR-inspired Convolutional NeuRal Network (CNN)-based AndroiD Malware Detections. Proceedings of the 2018 IEEE International Conference on Big Data (Big Data), Seattle, WA, USA.","DOI":"10.1109\/BigData.2018.8622324"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Jung, I., Choi, J., Cho, S., Han, S., Park, M., and Hwang, Y.-S. (2018, January 9\u201312). Android malware detection using convolutional neural networks and data section images. Proceedings of the 2018 Conference on Research in Adaptive and Convergent Systems, Honolulu, HI, USA.","DOI":"10.1145\/3264746.3264780"},{"key":"ref_27","unstructured":"(2020, October 01). Pillow (Pil Fork). Available online: https:\/\/pillow.readthedocs.io\/en\/stable\/index.html."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Sandler, M., Howard, A., Zhu, M., Zhmoginov, A., and Chen, L.-C. (2018, January 18\u201323). MobileNetV2: Inverted Residuals and Linear Bottlenecks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), Salt Lake City, UT, USA.","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref_29","unstructured":"Bai, S., and Kolter, J.Z. (2018). Vladlen Koltun: An Empirical Evaluation of Generic Convolutional and Recurrent Networks for Sequence Modeling. arXiv."},{"key":"ref_30","unstructured":"(2020, January 20). Python. Available online: https:\/\/www.python.org\/."},{"key":"ref_31","unstructured":"(2020, January 20). TensorFlow. Available online: https:\/\/www.tensorflow.org\/."},{"key":"ref_32","unstructured":"(2020, January 01). Keras. Available online: https:\/\/keras.io\/."},{"key":"ref_33","unstructured":"(2020, January 20). Canandian Institute for Cybersecurity. Available online: https:\/\/www.unb.ca\/cic\/datasets."},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Ding, Y., Zhang, X., Hu, J., and Xu, W. (2020). Android malware detection method based on bytecode image. J. Ambient. Intell. Human Comput.","DOI":"10.1007\/s12652-020-02196-4"}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/7\/1107\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T06:20:45Z","timestamp":1760163645000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/13\/7\/1107"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,22]]},"references-count":34,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2021,7]]}},"alternative-id":["sym13071107"],"URL":"https:\/\/doi.org\/10.3390\/sym13071107","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,6,22]]}}}