An Optimized Stacking Ensemble of Deep Learning and Machine Learning Models with Boruta-Based Feature Selection for Android Malware Detection

Authors

DOI:

https://doi.org/10.62411/faith.3048-3719-356

Keywords:

Android Malware, Boruta, Class Weighting, Deep Learning, Ensemble Learning, Feature Selection, Machine Learning, Malware Detection

Abstract

Malware, particularly within the Android ecosystem, continues to evolve in complexity, rendering traditional signature-based detection techniques ineffective against new and obfuscated threats. This study addresses the challenge of achieving highly accurate and robust malware detection in the presence of high-dimensional and potentially noisy feature spaces. The objective is to develop a feature-optimized hybrid framework that leverages the complementary strengths of deep learning and machine learning models. To this end, a stacking-based hybrid model integrating TabNet, Deep Neural Network, and XGBoost as base learners, with Logistic Regression as the meta-learner, is proposed. The methodology incorporates Boruta-based feature selection to eliminate irrelevant and redundant features, thereby improving model generalization, efficiency, and robustness. Rather than relying on explicit data resampling or class balancing techniques, the proposed approach enhances detection stability under naturally imbalanced data distributions through feature optimization and heterogeneous ensemble learning. The model is evaluated on two benchmark datasets, TUANDROMD and CIC-AndMal2017, to ensure robustness and generalizability. Experimental results demonstrate that on the CIC-AndMal2017 dataset, the hybrid model achieved an accuracy of 0.978945, precision of 0.969766, recall of 0.970508, F1-score of 0.970137, and AUROC of 0.996030, outperforming all individual base models. Similarly, on the TUANDROMD dataset, the hybrid framework attained superior performance with an accuracy of 0.997760, precision of 0.997203, recall of 1.000000, F1-score of 0.998599, and AUROC of 0.999423, again surpassing the base learners. These results confirm that the proposed feature-optimized ensemble stacking approach improves malware detection performance and provides a robust and scalable solution for real-world cybersecurity applications.

Downloads

Download data is not yet available.

Author Biographies

Maiauduga Abdullahi Danladi, Air Force Institute of Technology

Department of Cybersecurity, Faculty of Computing, Air Force Institute of Technology, Kaduna 800001, Kaduna State, Nigeria

Maryam Sufiyanu Masari, Air Force Institute of Technology

Department of Cybersecurity, Faculty of Computing, Air Force Institute of Technology, Kaduna 800001, Kaduna State, Nigeria

Ubakaghinwa Paul Chigbu, National Office for Technology Acquisition and Promotion

Department of Information and Communication Technology, National Office for Technology Acquisition and Promotion, Abuja 900281, FCT Abuja, Nigeria

Abdulrashid Abdulrauf, Federal Polytechnic Kaltungo

Department of Computer Science, Federal Polytechnic Kaltungo, Kaltungo 770101, Gombe State. Nigeria

References

D. Elagina, “Number of smartphone users worldwide from 2016 to 2029,” Statista, 2026. https://www.statista.com/statistics/330695/number-of-smartphone-users-worldwide/

Statista Research Department, “Global market share held by mobile operating systems from 2009 to 2025,” Statista, 2026. https://www.statista.com/statistics/272698/global-market-share-held-by-mobile-operating-systems-since-2009/

M. Benmalek, “Ransomware on cyber-physical systems: Taxonomies, case studies, security gaps, and open challenges,” Internet Things Cyber-Physical Syst., vol. 4, pp. 186–202, 2024, doi: 10.1016/j.iotcps.2023.12.001.

M. Cen, F. Jiang, X. Qin, Q. Jiang, and R. Doss, “Ransomware early detection: A survey,” Comput. Networks, vol. 239, p. 110138, Feb. 2024, doi: 10.1016/j.comnet.2023.110138.

M. Baykara and E. Colak, “A review of cloned mobile malware applications for android devices,” in 2018 6th International Symposium on Digital Forensic and Security (ISDFS), Mar. 2018, pp. 1–5. doi: 10.1109/ISDFS.2018.8355388.

M. Conti, T. Dargahi, and A. Dehghantanha, “Cyber Threat Intelligence: Challenges and Opportunities,” in Advances in Information Security, 2018, pp. 1–6. doi: 10.1007/978-3-319-73951-9_1.

A. Pagan and K. Elleithy, “A Multi-Layered Defense Approach to Safeguard Against Ransomware,” in 2021 IEEE 11th Annual Computing and Communication Workshop and Conference (CCWC), Jan. 2021, pp. 0942–0947. doi: 10.1109/CCWC51732.2021.9375988.

B. Yamany, M. S. Elsayed, A. D. Jurcut, N. Abdelbaki, and M. A. Azer, “A Holistic Approach to Ransomware Classification: Leveraging Static and Dynamic Analysis with Visualization,” Information, vol. 15, no. 1, p. 46, Jan. 2024, doi: 10.3390/info15010046.

M. M. Raza et al., “Malware Detection and AI Integration: A Systematic Review of Current Trends and Future Directions,” Comput. Model. Eng. Sci., vol. 146, no. 3, pp. 1–10, 2026, doi: 10.32604/cmes.2025.074164.

V. Kouliaridis and G. Kambourakis, “A Comprehensive Survey on Machine Learning Techniques for Android Malware Detection,” Information, vol. 12, no. 5, p. 185, Apr. 2021, doi: 10.3390/info12050185.

D. Gibert, C. Mateu, and J. Planes, “The rise of machine learning for detection and classification of malware: Research developments, trends and challenges,” J. Netw. Comput. Appl., vol. 153, p. 102526, Mar. 2020, doi: 10.1016/j.jnca.2019.102526.

M. A. Rahman, G. A. Francia, and H. Shahriar, “Leveraging GANs for Synthetic Data Generation to Improve Intrusion Detection Systems,” J. Futur. Artif. Intell. Technol., vol. 1, no. 4, pp. 429–439, Feb. 2025, doi: 10.62411/faith.3048-3719-52.

M. S. Masari, M. A. Danladi, I. L. Onyinye, and L. K. Tohomdet, “Android Malware Detection Using Machine Learning with SMOTE-Tomek Data Balancing,” J. Comput. Theor. Appl., vol. 3, no. 3, pp. 302–313, Jan. 2026, doi: 10.62411/jcta.15084.

A. K. Jilani and S. Samreen, “Ensemble Based Android Malware Detection Using a Bio-Inspired Meta-Heuristic Feature Engineering Approach,” in 2024 International Conference on Computing, Internet of Things and Microwave Systems (ICCIMS), Jul. 2024, pp. 1–6. doi: 10.1109/ICCIMS61672.2024.10690649.

M. Ibadullah, S. A. Amalina, W. Ghozi, and F. A. Rafrastara, “Machine Learning-based Malware Detection on Android Operating System using AdaBoost Algorithm and ReliefF Feature Selection Method,” in 2024 International Seminar on Application for Technology of Information and Communication (iSemantic), Sep. 2024, pp. 359–364. doi: 10.1109/iSemantic63362.2024.10762096.

Y. Pristyanto, A. F. Nugraha, B. Wulansari, M. Sulistiyono, and A. Sunyoto, “Enhancement of Machine Learning Models Using Intersection Filtering Model Based on Recursive Feature Elimination on Specified Android Malware Classification,” Int. J. Intell. Eng. Syst., vol. 18, no. 3, pp. 836–852, Apr. 2025, doi: 10.22266/ijies2025.0430.56.

T. Etem, “Comparative Analysis of Principle Component Analysis and Anova Feature Selection in Malware Detection,” Firat Univ. J. Exp. Comput. Eng., vol. 5, no. 1, pp. 299–315, Feb. 2026, doi: 10.62520/fujece.1635121.

A. Fenjan, D. J. Md Desa, D. S. Elaskari, A. Theeb, and A. S. Alsayafi, “Addressing Data Imbalance in Malware Detection: A Comparison Analysis of Machine Learning Models for Malware Detection on Balanced and Imbalanced Datasets,” in Proceedings of the Sixth International Conference on Digital Age & Technological Advances for Sustainable Development, May 2025, pp. 1–5. doi: 10.1145/3747897.3747898.

S. Al Ali et al., “Android Malware Detection Using Machine Learning,” in 2024 IEEE International Conference on Internet of Things and Intelligence Systems (IoTaIS), Nov. 2024, pp. 79–84. doi: 10.1109/IoTaIS64014.2024.10799339.

E. S. Akkaya and E. V. Altay, “Investigating the Performance of Machine Learning Methods for Malware Detection,” in EAI/Springer Innovations in Communication and Computing, 2025, pp. 329–340. doi: 10.1007/978-3-031-88999-8_25.

H. Abdulla, “Android Malware Detection: A Machine Leaning Approach,” arXiv. Nov. 02, 2025. [Online]. Available: http://arxiv.org/abs/2511.00894

M. K. Shah, “AI-Based Framework for Ransomware Detection in Android Systems: Enhancing Mobile Security,” in 2025 5th International Conference on Artificial Intelligence and Signal Processing (AISP), Nov. 2025, pp. 1–8. doi: 10.1109/AISP68263.2025.11396254.

N. G. Ambekar, N. N. Devi, S. Thokchom, and Yogita, “TabLSTMNet: enhancing android malware classification through integrated attention and explainable AI,” Microsyst. Technol., vol. 31, no. 3, pp. 695–713, Mar. 2025, doi: 10.1007/s00542-024-05615-0.

Haris Mehmood, Muhammad Kamran Abid, Muhammad Fuzail, Ahmad Naeem, and Naeem Aslam, “Enhancing Real-time Android Malware Detection using Deep Learning and Fuzzy Logic-based Hybrid Models,” Kashf J. Multidiscip. Res., vol. 2, no. 06, pp. 161–170, Jun. 2025, doi: 10.71146/kjmr494.

A. K. J, N. Das Patel, S. D, and A. Patel, “Behavioral Malware Detection via API Call Sequences: A Comparative Study of LSTM and Transformer Architectures Using NLP-Inspired Representations,” J. Comput. Theor. Appl., vol. 3, no. 4, pp. 443–456, Apr. 2026, doi: 10.62411/jcta.15811.

T. Kacem and S. Tossou, “Trandroid: An Android Mobile Threat Detection System Using Transformer Neural Networks,” Electronics, vol. 14, no. 6, p. 1230, Mar. 2025, doi: 10.3390/electronics14061230.

M. Arya, S. Arya, and S. Arya, “H2O AutoML for Malware Detection: A Signal Processing Perspective on Accuracy, Efficiency, and Interpretability,” in 2025 IEEE International Conference on Signals and Systems (ICSigSys), Nov. 2025, pp. 77–83. doi: 10.1109/ICSigSys67277.2025.11269166.

M. R. Abdellah et al., “Enhanced Federated Learning Framework Based on Deep Learning and Neutrosophic Set for Android Malware Classification,” Neutrosophic Sets Syst., vol. 82, no. 1, 2025, [Online]. Available: https://digitalrepository.unm.edu/cgi/viewcontent.cgi?article=3189&context=nss_journal

A. Daulay, K. Ramli, R. Harwahyu, T. Hidayat, and B. Pranggono, “Novel Federated Graph Contrastive Learning for IoMT Security: Protecting Data Poisoning and Inference Attacks,” Mathematics, vol. 13, no. 15, p. 2471, Jul. 2025, doi: 10.3390/math13152471.

D. Mughole Kalimumbalo et al., “SecFedMDM-1: A Federated Learning-Based Malware Detection Model for Interconnected Cloud Infrastructures,” IEEE Access, vol. 13, pp. 101246–101261, 2025, doi: 10.1109/ACCESS.2025.3577706.

R. B. Coulibaly, T. F. Bissyandé, R. Kafando, A. Sabané, and A. K. Kabore, “Privacy-Preserving Android Malware Detection Using Deep Federated Learning,” in 2025 Cybersecurity4D (C4D), Aug. 2025, pp. 1–7. doi: 10.1109/C4D65382.2025.11306458.

P. Borah, D. Bhattacharyya, and J. Kalita, “Malware Dataset Generation and Evaluation,” in 2020 IEEE 4th Conference on Information & Communication Technology (CICT), Dec. 2020, pp. 1–6. doi: 10.1109/CICT51604.2020.9312053.

M. S. Haque, M. S. Hossain, R. A. Robin, A. S. Tarisha, S. Ahmmed, and J. N. Mukta, “Android Malware Analysis.” Mendeley Data, 2026. doi: 10.17632/bpkksc9v5s.5.

M. B. Kursa and W. R. Rudnicki, “Feature Selection with the Boruta Package,” J. Stat. Softw., vol. 36, no. 11, 2010, doi: 10.18637/jss.v036.i11.

A. Wajahat et al., “An effective deep learning scheme for android malware detection leveraging performance metrics and computational resources,” Intell. Decis. Technol., vol. 18, no. 1, pp. 33–55, Feb. 2024, doi: 10.3233/IDT-230284.

A. Wajahat et al., “Outsmarting Android Malware with Cutting-Edge Feature Engineering and Machine Learning Techniques,” Comput. Mater. Contin., vol. 79, no. 1, pp. 651–673, 2024, doi: 10.32604/cmc.2024.047530.

T. Palabaş, “Android malware classification using basic machine learning methods,” Adıyaman Üniversitesi Mühendislik Bilim. Derg., vol. 11, no. 23, pp. 190–202, Aug. 2024, doi: 10.54365/adyumbd.1462488.

A. Museeb, Y. Hamed, Y. Baashar, A. M. Jamal Kanaan-Jebna, A. Amazigh Hamza, and R. Sokkalingam, “Android Malware Detection Using API Calls and Permissions With Random Forest Classifier,” IEEE Access, vol. 14, pp. 6464–6480, 2026, doi: 10.1109/ACCESS.2026.3651861.

A. Museeb, Y. Hamed, and H. Louis Tan, “Hybrid Random Forest and XGBoost Approach for Android Malware Detection,” Res. J. Maaref Univ. Appl. Sci., vol. 2, no. 1, p. 6, Feb. 2026, doi: 10.66422/wh0h4a90.

S. Rekik, S. Mehmood, and M. Alkhonaini, “AdaptivePixGuard: Attention-Enhanced Temporal Convolutions for Robust Mobile Pixnapping Detection,” IEEE Access, vol. 14, pp. 34072–34095, 2026, doi: 10.1109/ACCESS.2026.3669496.

Downloads

Published

2026-04-30

How to Cite

[1]
M. A. Danladi, M. S. Masari, U. P. Chigbu, and A. Abdulrauf, “An Optimized Stacking Ensemble of Deep Learning and Machine Learning Models with Boruta-Based Feature Selection for Android Malware Detection”, J. Fut. Artif. Intell. Tech., vol. 3, no. 1, pp. 67–83, Apr. 2026.

Issue

Section

Articles

Similar Articles

<< < 1 2 3 4 5 6 7 8 9 10 > >> 

You may also start an advanced similarity search for this article.