An Adaptive Dataset for the Evaluation of Android Malware Detection Techniques
Bibliographic record
Abstract
Android is currently the leading mobile operating system in the world. The huge number of Android devices attracts developers to create applications for it. However, it also attracts attackers that collect sensitive data or make money. This problem has led many researchers to propose malware detection systems and custom versions of Android that can help users against malicious activities. Evaluating these systems is a crucial part of malware prevention research. However, recent datasets that cover different kinds of benign and malicious applications to evaluate the malware detection techniques are often not available. With thousands of newly released applications every day and different new malicious activities discovered, it is difficult to keep malicious application datasets up to date. This paper introduces a recent and adaptive dataset that includes 5,000 applications from different malware categories that can be used by the research community. The applications are selected from more than 5 million applications. To show how the dataset can be used, we deploy a popular malware analysis platform and generate detailed reports on all the applications in an automated way. We also provide the steps to update the dataset and perform the analysis automatically on the updated set of samples. We believe that the adaptiveness of the dataset and the automatic analysis process will help researchers save time in preparing their datasets and focus more on the detection techniques.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.001 | 0.000 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.000 | 0.000 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.000 | 0.001 |
| Open science | 0.001 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".