IP Library › Granted Patent US 12,248,571
Granted Patent B2
US 12,248,571 · App. 17/888,983 · Granted Mar 11, 2025

On-device android malware detection method based on adaptive model through transfer learning, and recording medium and apparatus for performing the same

Inventors: Soohwan Jung (Seoul, KR); Hyunseok Shim (Seoul, KR); Songi Gwak (Seoul, KR)
Assignee: FOUNDATION OF SOONGSIL UNIVERSITY-INDUSTRY COOPERATION
G06F21/563G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,571
App. No.
17/888,983
Granted
Mar 11, 2025
Kind
B2
Abstract

Provided is an on-device Android malware detection method based on an adaptive model through transfer learning, including: determining whether an application is malicious or unfavorable from a list of applications installed on a device; decompiling, in the device, an Android package (APK) of the application installed on the device; transmitting the determined list and the decompiled APK file to a server in order to generate a head model in the server and use the generated head model for the transfer learning with a base model; performing malware analysis in the device using a transfer learning model received from the server for an application newly installed on the device; and providing a malware analysis result to a user through the device as a result, and since the malware analysis is performed on the device, it is possible to ensure the availability and real-time performance of enabling analysis outside of a network range.

Claims (30)

1. An on-device Android malware detection method based on an adaptive model through transfer learning, the on-device Android malware detection method comprising:

determining whether a list of applications installed on a device includes an application that is malicious or unfavorable;

decompiling, in the device, an Android package (APK) file of the application installed on the device;

transmitting the determined list and the decompiled APK file to a server, generating a head model in the server, and using the generated head model for the transfer learning with a base model;

performing malware analysis in the device using a transfer learning model received from the server for an application newly installed on the device; and

providing a malware analysis result to a user through the device,

wherein, in the determining whether the list of applications installed on the device includes an application that is malicious or unfavorable, the application is determined to be a malicious or unfavorable application when the application is selected by the user, and the application is determined to be normal and reflected in a transfer learning model when the application is not selected by the userz,

wherein the decompiling, in the device, of the APK file of the application installed on the device is run in an Android environment by removing branch processing for each operating system of APKTool.

2. The on-device Android malware detection method of claim 1 , wherein the base model is based on a convolutional neural network (CNN) using a two-dimensional (2D) matrix as input data.

3. The on-device Android malware detection method of claim 1 , wherein the base model is generated based on a permission of a manifest file or is generated based on application programming interface (API) signature information defined in the APK file.

4. The on-device Android malware detection method of claim 1 , further comprising generating a new transfer learning model by communicating with the server according to needs of the user.

5. A non-transitory computer-readable recording medium on which a computer program for performing an on-device Android malware detection method based on an adaptive model through transfer learning, wherein the on-device Android malware detection method comprises:

determining whether a list of applications installed on a device includes an application that is malicious or unfavorable;

decompiling, in the device, an Android package (APK) file of the application installed on the device;

transmitting the determined list and the decompiled APK file to a server, generating a head model in the server, and using the generated head model for the transfer learning with a base model;

performing malware analysis in the device using a transfer learning model received from the server for an application newly installed on the device; and

providing a malware analysis result to a user through the device,

wherein, in the determining whether the list of applications installed on the device includes an application that is malicious or unfavorable, the application is determined to be a malicious or unfavorable application when the application is selected by the user, and the application is determined to be normal and reflected in a transfer learning model when the application is not selected by the user,

wherein the decompiling, in the device, of the APK file of the application installed on the device is run in an Android environment by removing branch processing for each operating system of APKTool.

6. An on-device Android malware detection apparatus based on an adaptive model through transfer learning, the on-device Android malware detection apparatus comprising:

a user environment reflection unit determining whether a list of applications installed on a device includes an application that is malicious or unfavorable;

a decompilation unit decompiling, in the device, an Android package (APK) file of the application installed on the device;

a communication unit transmitting the determined list and the decompiled APK file to a server in order to generate a head model in the server and use the generated head model for the transfer learning with a base model;

an analysis unit performing malware analysis in the device using a transfer learning model received from the server for an application newly installed on the device; and

a result providing unit providing a malware analysis result to a user through the device,

wherein the user environment reflection unit determines the application to be a malicious or unfavorable application when the application is selected by the user, and the user environment reflection unit determines the application to be normal and reflects it in a transfer learning model when the application is not selected by the user,

wherein the decompilation unit decompiles in an Android environment by removing branch processing for each operating system of APKTool.

7. The on-device Android malware detection apparatus of claim 6 , wherein the base model is based on a convolutional neural network (CNN) using a two-dimensional (2D) matrix as input data.

8. The on-device Android malware detection apparatus of claim 6 , wherein the base model is generated based on a permission of a manifest file or generated based on API signature information defined in the APK file.

9. The on-device Android malware detection apparatus of claim 6 , wherein the communication unit communicates with the server to generate a new transfer learning model according to needs of the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2022
From: JUNG, SOOHWAN; SHIM, HYUNSEOK; GWAK, SONGI
To: FOUNDATION OF SOONGSIL UNIVERSITY-INDUSTRY COOPERATION
Reel/Frame 060822/0528 →
Priority Claims (1)
KR 10-2021-0073580 · Jun 7, 2021 · national
Continuity (2)
Continuation In Part PCTKR2022004665 · Mar 31, 2022
Related Publication 20230177156A1 · Jun 8, 2023
References Cited (20)
US 8844038B2 · Niemela · 2014 [cited by examiner]
US 10250617B1 · Gardner · 2019 [cited by examiner]
US 11526601B2 · Rouhani · 2022 [cited by examiner]
US 20120222120A1 · Rim · 2012 [cited by examiner]
US 20160057159A1 · Yin · 2016 [cited by examiner]
US 20180189489A1 · Zhang · 2018 [cited by examiner]
US 20190042743A1 · Chen · 2019 [cited by applicant]
US 20190230107A1 · De Sapio · 2019 [cited by examiner]
US 20190272375A1 · Chen · 2019 [cited by applicant]
US 20200344261A1 · Yi · 2020 [cited by examiner]
US 20210073377A1 · Coull et al. · 2021 [cited by applicant]
KR 101337215B1 · 2013 [cited by applicant]
KR 102168496B1 · 2020 [cited by applicant]
KR 102180098B1 · 2020 [cited by applicant]
Korean Office Action mailed Sep. 30, 2022, issued to Korean Application No. 10-2021-0073580. [cited by applicant]
Ruitao Feng et al., “MobiDroid: A Performance-Sensitive Malware Detection System on Mobile Platform” (Nov. 2019). [cited by applicant]
Pavel Senchanka, “Example on-device model personalization with TensorFlow Lite”(Apr. 2021), https://web.archive.org/web/20210414171249/https://blog.tensorflow.org/2019/12/example-on-device-modelpersonalization.html. [cited by applicant]
Martin Sweeney, “Decompile and Modify APKs on the go with APKTool for Android”(Nov. 2020), https://web.archive.org/web/20201112034032/https://www.xda-developers.com/decompile-and-modify-apks-on-the-go-with-apktool-for-a… [cited by applicant]
Hyunseok Shim et al. “Transfer Learning based Adaptive Model for Serverless On-Device Android Malware Detection”, Korea Institute of Information Security & Cryptology, Conference on Information Security and Cryptography… [cited by applicant]
Mohammad Al-Fawa'reh et al.“Malware Detection by Eating a Whole APK”. Published in: 2020 15th International Conference for Internet Technology and Secured Transactions (ICITST). Princess Sumaya University for Technology… [cited by applicant]