Skip to main navigation Skip to search Skip to main content

Enhancing Android malware detection via knowledge distillation on homogenized function call graphs

  • Zhendong Wang
  • , Kaiyi Zhang*
  • , Shuxin Yang
  • , Daojing He
  • , Sammy Chan
  • *Corresponding author for this work
  • Jiangxi University of Science and Technology
  • Nanchang University
  • School of Computer Science and Technology, Harbin Institute of Technology
  • City University of Hong Kong

Research output: Contribution to journalArticlepeer-review

Abstract

Graph neural network (GNN)-based Android malware detection has demonstrated significant potential for accuracy enhancement. However, existing function call graph (FCG) classification methods face two critical limitations: (1) inherent incompatibility between graph heterogeneity and model homogeneity assumptions, and (2) performance degradation in conventional GNNs when processing large-scale FCGs. This paper introduces a novel Android malware detection method (SIGDroid) that addresses these challenges through two key contributions. First, we propose a heterogeneous-to-homogeneous graph transformation technique that simplifies the structural complexity of the graph by focusing on internal function nodes directly related to malicious behaviors while preserving critical malware-related features, including API calls, permissions, and semantic information. Second, we design a Student-Centered Knowledge Distillation framework on Graphs (SCKDG). Diverging from teacher-centric paradigms, SCKDG prioritizes the student model's learning requirements through a multi-stage adaptive distillation mechanism. The framework dynamically adjusts knowledge propagation strategies based on the student model's evolving capabilities, implementing a progressive learning process analogous to personalized educational methodologies. Extensive experiments were conducted on two large-scale datasets, simulating real-world scenarios with nearly 144k samples, and the results were compared against those of eight baseline methods. Compared to existing malware detection methods, our approach demonstrates superior performance over other methods that rely on heterogeneous function call graphs. Compared to standard GNN models, our SCKDG method achieves a maximum F1-score improvement of 2.91%.

Original languageEnglish
Article number113687
JournalKnowledge-Based Systems
Volume323
DOIs
StatePublished - 19 Jul 2025
Externally publishedYes

Keywords

  • Android malware detection
  • Graph classification
  • Graph neural networks
  • Knowledge distillation
  • Student-centered

Fingerprint

Dive into the research topics of 'Enhancing Android malware detection via knowledge distillation on homogenized function call graphs'. Together they form a unique fingerprint.

Cite this