基于敏感API上下文图的恶意应用检测
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:

国网江苏省电力有限公司科技项目 (J2025060)


Malware Detection Based on Sensitive API Context Graph
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    随着物联网的快速发展, 移动应用环境日益复杂, 安卓恶意应用的威胁与日俱增. 平台系统更新及恶意应用持续演化导致检测模型面临概念漂移问题, 在新样本上的性能显著下降, 同时现有方法缺乏直观的可解释性. 针对上述问题, 本文提出一种基于敏感API上下文图的恶意应用检测方法. 该方法以敏感API为核心构建局部上下文子图, 从上层调用场景、多路径汇聚模式与核心行为这3个维度刻画稳定行为模式. 同时, 采用图神经网络进行表示学习, 通过门控注意力多示例学习实现应用级特征聚合, 并结合注意力机制定位关键子图, 引入大语言模型生成自然语言解释. 基于该方法实现的SacDroid系统在42227个样本的数据集上进行实验, 同年测试平均F1值达97.88%, 跨年测试性能优于对比方法. 可解释性实验结果表明, 大语言模型仅基于关键子图即可进行独立判别, 准确率达到89.6%, 对恶意样本的识别率为91.2%. 实验结果验证了所提方法在检测性能与可解释性方面的有效性.

    Abstract:

    As the Internet of Things (IoT) rapidly develops, the mobile application environment has become increasingly complex, and the threat posed by malicious Android applications continues to grow. Platform system updates and the continuous evolution of malicious applications cause concept drift in detection models, significantly degrading their performance on new samples, while existing methods lack intuitive interpretability. To address these issues, this study proposes a malicious application detection method based on sensitive API context graphs. The method constructs local context subgraphs centered on sensitive APIs, characterizes stable behavioral patterns from three dimensions: upper-level calling scenarios, multi-path convergence, and core behaviors, and uses graph neural networks for representation learning. Gated attention-based multiple instance learning is used to aggregate application-level features, attention mechanisms are combined to locate key subgraphs, and large language models are introduced to generate natural language explanations. Experiments are conducted on a dataset of 42227 samples using the SacDroid system implemented based on this method. The average F1 score in same-year testing reaches 97.88%, and cross-year testing performance outperforms comparative methods. Interpretability experimental results show that large language models can perform independent discrimination based only on key subgraphs, achieving an accuracy of 89.6% and a recognition rate of 91.2% for malicious samples. The experimental results verify the effectiveness of the proposed method in terms of detection performance and interpretability.

    参考文献
    相似文献
    引证文献
引用本文

赵新建,王方圆,陈石,李千目,吴子成.基于敏感API上下文图的恶意应用检测.计算机系统应用,,():1-13

复制
分享
相关视频

文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2026-02-10
  • 最后修改日期:2026-03-02
  • 录用日期:
  • 在线发布日期: 2026-07-14
  • 出版日期:
文章二维码
您是第位访问者
版权所有:中国科学院软件研究所 京ICP备05046678号-3
地址:北京市海淀区中关村南四街4号,邮政编码:100190
电话:010-62661041 传真: Email:csa@iscas.ac.cn
技术支持:北京勤云科技发展有限公司

京公网安备 11040202500063号