Skip to main navigation Skip to search Skip to main content

TIF: Learning Temporal Invariance in Android Malware Detectors

  • Xinran Zheng*
  • , Shuo Yang
  • , Edith C.H. Ngai
  • , Suman Jana
  • , Lorenzo Cavallaro
  • *Corresponding author for this work
  • University College London
  • The University of Hong Kong
  • Columbia University

Research output: Contribution to journalArticlepeer-review

Abstract

Learning-based Android malware detectors degrade over time due to natural distribution drift caused by malware variants and new families. This paper systematically investigates the challenges classifiers trained with empirical risk minimization (ERM) face against such distribution shifts and attributes their shortcomings to their inability to learn stable discriminative features. Invariant learning theory offers a promising solution by encouraging models to generate stable representations across environments that expose the instability of the training set. However, the lack of prior environment labels, the diversity of drift factors, and low-quality representations caused by diverse families make this task challenging. To address these issues, we propose TIF, the first temporal invariant training framework for malware detection, which aims to enhance the ability of detectors to learn stable representations across time. TIF organizes environments based on application observation dates to reveal temporal drift, integrating specialized multi-proxy contrastive learning and invariant gradient alignment to generate and align environments with high-quality, stable representations. TIF can be seamlessly integrated into any learning-based detector. Experiments on a decade-long dataset show that TIF excels, particularly in early deployment stages, addressing real-world needs and outperforming state-of-the-art methods.

Original languageEnglish
JournalIEEE Transactions on Software Engineering
DOIs
StateAccepted/In press - 2026
Externally publishedYes

Keywords

  • Concept Drift
  • Invariant Risk Minimization
  • Malware Detection

Fingerprint

Dive into the research topics of 'TIF: Learning Temporal Invariance in Android Malware Detectors'. Together they form a unique fingerprint.

Cite this