Optimizing Multiclass Android Malware Family Classification Using SMOTE-Tomek Links and XGBoost

Authors

  • Ali Nur Ikhsan Universitas Amikom Purwokerto, Indonesia
  • Adam Prayogo Kuncoro Universitas Amikom Purwokerto, Indonesia
  • Debby Ummul Hidayah Universitas Amikom Purwokerto, Indonesia
  • Fajar Ramadhan Universitas Amikom Purwokerto, Indonesia
Pages Icon

DOI:

https://doi.org/10.63158/journalisi.v8i4.1788

Keywords:

Android malware classification, SMOTE-Tomek Links, XGBoost, imbalanced learning, multiclass classification

Abstract

The increasing sophistication of Android malware attacks has created significant challenges for accurate malware family classification, particularly under highly imbalanced data distributions where minority malware families are frequently misclassified. This study presents a robust multiclass Android malware family classification framework by combining SMOTE-Tomek Links hybrid resampling with an optimized Extreme Gradient Boosting (XGBoost) classifier. The proposed framework addresses two critical issues in previous studies: ineffective handling of minority classes and potential data leakage during resampling and model validation. Experiments were conducted using the CCCS-CIC-AndMal-2020 After Reboot dataset containing 25,059 malware samples distributed across 14 malware families. The proposed approach applies stratified data partitioning, leakage-free SMOTE-Tomek Links integration within an imbalanced-learn pipeline, and RandomizedSearchCV-based hyperparameter optimization with 5-fold stratified cross-validation. Evaluation on an independent holdout test set demonstrates that the optimized framework achieves 80.09% accuracy, 79.85% weighted F1-score, 74.00% macro F1-score, and 97.48% OvR ROC-AUC, outperforming baseline XGBoost and Random Forest models. The results confirm that hybrid resampling combined with optimized gradient boosting improves classification reliability, especially in addressing severe class imbalance and enhancing recognition capability across diverse Android malware families.

Downloads

Download data is not yet available.

References

[1] C. Palma, A. Ferreira, and M. Figueiredo, “Explainable Machine Learning for Malware Detection on Android Applications †,” Information (Switzerland), vol. 15, no. 1, Jan. 2024, doi: 10.3390/info15010025.

[2] F. Taher, O. AlFandi, M. Al-kfairy, H. Al Hamadi, and S. Alrabaee, “DroidDetectMW: A Hybrid Intelligent Model for Android Malware Detection,” Applied Sciences (Switzerland), vol. 13, no. 13, Jul. 2023, doi: 10.3390/app13137720.

[3] P. Faruki, R. Bhan, V. Jain, S. Bhatia, N. El Madhoun, and R. Pamula, “A Survey and Evaluation of Android-Based Malware Evasion Techniques and Detection Frameworks,” Jul. 01, 2023, Multidisciplinary Digital Publishing Institute (MDPI). doi: 10.3390/info14070374.

[4] W. F. Elsersy, A. Feizollah, and N. B. Anuar, “The rise of obfuscated Android malware and impacts on detection methods,” PeerJ Comput. Sci., vol. 8, 2022, doi: 10.7717/PEERJ-CS.907.

[5] J. M. Arif, M. F. A. Razak, S. Awang, S. R. T. Mat, N. S. N. Ismail, and A. Firdaus, “A static analysis approach for Android permission-based malware detection systems,” PLoS One, vol. 16, no. 9 September, Sep. 2021, doi: 10.1371/journal.pone.0257968.

[6] D. Soi, A. Sanna, D. Maiorca, and G. Giacinto, “Enhancing android malware detection explainability through function call graph APIs,” Journal of Information Security and Applications, vol. 80, Feb. 2024, doi: 10.1016/j.jisa.2023.103691.

[7] B. T. Hammad, N. Jamil, I. T. Ahmed, Z. M. Zain, and S. Basheer, “Robust Malware Family Classification Using Effective Features and Classifiers,” Applied Sciences (Switzerland), vol. 12, no. 15, Aug. 2022, doi: 10.3390/app12157877.

[8] M. E. Eren, M. Bhattarai, R. J. Joyce, E. Raff, C. Nicholas, and B. S. Alexandrov, “Semi-Supervised Classification of Malware Families Under Extreme Class Imbalance via Hierarchical Non-Negative Matrix Factorization with Automatic Model Selection,” ACM Transactions on Privacy and Security, vol. 26, no. 4, Nov. 2023, doi: 10.1145/3624567.

[9] N. T. Cam, T. M. Huy, and N. T. Tin, “Malware classification using deep neural networks with Deep Q-Learning and eXplainable artificial intelligence,” Eng. Appl. Artif. Intell., vol. 166, Feb. 2026, doi: 10.1016/j.engappai.2025.113622.

[10] P. Dominic Andrew, A. M. Jose, N. Jayapandian, C. N. Angel, and K. Brar, “Advanced Malware Analysis and Detection Using Deep Neural Networks,” in Conference Proceedings - 2025 IEEE 4th International Conference on Data, Decision and Systems, ICDDS 2025, Institute of Electrical and Electronics Engineers Inc., 2025, pp. 7–12. doi: 10.1109/ICDDS67737.2025.11344689.

[11] W. W. Y. Ng, Z. Liu, J. Zhang, and W. Pedrycz, “Maximizing minority accuracy for imbalanced pattern classification problems using cost-sensitive Localized Generalization Error Model,” Appl. Soft Comput., vol. 104, Jun. 2021, doi: 10.1016/j.asoc.2021.107178.

[12] S. Nemoto, S. Kitada, and H. Iyatomi, “Majority or Minority: Data Imbalance Learning Method for Named Entity Recognition,” IEEE Access, vol. 13, pp. 9902–9909, 2025, doi: 10.1109/ACCESS.2024.3522972.

[13] D. Elreedy, A. F. Atiya, and F. Kamalov, “A theoretical distribution analysis of synthetic minority oversampling technique (SMOTE) for imbalanced learning,” Mach. Learn., vol. 113, no. 7, pp. 4903–4923, Jul. 2024, doi: 10.1007/s10994-022-06296-4.

[14] N. Mohanty, B. K. Behera, C. Ferrie, and P. Dash, “A quantum approach to synthetic minority oversampling technique (SMOTE),” Quantum Mach. Intell., vol. 7, no. 1, Jun. 2025, doi: 10.1007/s42484-025-00248-6.

[15] H. Sun, J. Li, and X. Zhu, “A Novel Expandable Borderline Smote Over-Sampling Method for Class Imbalance Problem,” IEEE Trans. Knowl. Data Eng., vol. 37, no. 5, pp. 2183–2199, 2025, doi: 10.1109/TKDE.2025.3544284.

[16] G. Hou, D. L. Tong, S. Y. Liew, and P. Y. Choo, “Comparative Analysis of Resampling Techniques for Class Imbalance in Financial Distress Prediction Using XGBoost,” Mathematics, vol. 13, no. 13, Jul. 2025, doi: 10.3390/math13132186.

[17] M. Ilham, A. Winarno, M. Lutfi, and A. Indrasetianingsih, “Handling Imbalanced Fraudulent Transaction Data Using SMOTE-Tomek and Random Forest: A Classification Approach,” BEST Journal of Applied Electrical & Science Technology, 2025, doi: 10.36456/best.vol7.no1.10335.

[18] D. Yilmaz Eroglu and M. S. Pir, “Hybrid Oversampling and Undersampling Method (HOUM) via Safe-Level SMOTE and Support Vector Machine,” Applied Sciences (Switzerland), vol. 14, no. 22, Nov. 2024, doi: 10.3390/app142210438.

[19] E. H. Yulianti, O. Soesanto, and Y. Sukmawaty, “Penerapan Metode Extreme Gradient Boosting (XGBOOST) pada Klasifikasi Nasabah Kartu Kredit,” JOMTA Journal of Mathematics: Theory and Applications, vol. 4, no. 1, 2022, doi: 10.31605/jomta.v4i1.1792.

[20] M. Wiens, A. Verone-Boyle, N. Henscheid, J. T. Podichetty, and J. Burton, “A Tutorial and Use Case Example of the eXtreme Gradient Boosting (XGBoost) Artificial Intelligence Algorithm for Drug Development Applications,” Clin. Transl. Sci., vol. 18, no. 3, Mar. 2025, doi: 10.1111/cts.70172.

[21] M. Abdelhaq, S. K. Palanisamy, M. Gopinath, V. G. S. Manasa, M. A. Ram, and S. K. MD, “A hybrid XGBoost–SVM ensemble framework for robust cyber-attack detection in the internet of medical things (IoMT),” Sci. Rep., vol. 16, no. 1, Dec. 2026, doi: 10.1038/s41598-026-37832-0.

[22] H. Elwahsh et al., “Hyperparameter optimization of XGBoost and hybrid CnnSVM for cyber threat detection using modified Harris hawks algorithm,” PeerJ Comput. Sci., vol. 11, Sep. 2025, doi: 10.7717/peerj-cs.3169.

[23] M. Maghanaki, S. Keramati, F. F. Chen, and M. Shahin, “Systematic Evaluation of Machine Learning and Deep Learning Models for IoT Malware Detection Across Ransomware, Rootkit, Spyware, Trojan, Botnet, Worm, Virus, and Keylogger,” Sensors, vol. 26, no. 6, Mar. 2026, doi: 10.3390/s26061750.

[24] P. Anand, P. Nandhini, J. J. Christy, and K. Shiyamala, “Cyber threat estimation and prevention using xgboost,” in ViTECoN 2023 - 2nd IEEE International Conference on Vision Towards Emerging Trends in Communication and Networking Technologies, Proceedings, Institute of Electrical and Electronics Engineers Inc., 2023. doi: 10.1109/ViTECoN58111.2023.10157276.

[25] I. Singh Makkar, A. Kumar Sinha, T. Pratap, and A. Midhun Kumar, “Optimizing Android Malware Detection for Resource-Constrained Devices via a Two-Stage ML Pipeline,” in 2025 International Conference on Intelligent Computing and Knowledge Extraction, ICICKE 2025, Institute of Electrical and Electronics Engineers Inc., 2025. doi: 10.1109/ICICKE65317.2025.11136486.

[26] Z. Khalid, M. Zeeshan, and I. Ullah, “FGSM-CW Hardened Static Android-Malware Detection with Incremental PCA on the CCCS-CIC AndMal-2020 Corpus,” in 2025 IEEE 22nd International Conference on Smart Communities: Improving Quality of Life using AI, Robotics and IoT, HONET 2025, Institute of Electrical and Electronics Engineers Inc., 2025, pp. 122–127. doi: 10.1109/HONET67928.2025.11318437.

[27] D. F. Duarte and A. A. Bortoli, “Empirical Evaluation of SMOTE in Android Malware Detection with Machine Learning: Challenges and Performance in CICMalDroid 2020,” Feb. 2026, doi: 10.5281/zenodo.15620300.

[28] N. A. Azhar, M. S. Mohd Pozi, A. M. Din, and A. Jatowt, “An investigation of SMOTE based methods for imbalanced datasets with data complexity analysis,” IEEE Trans. Knowl. Data Eng., vol. 35, no. 7, pp. 6651–6672, Jul. 2023, doi: 10.1109/TKDE.2022.3179381.

[29] N. A. Azhar, M. S. Mohd Pozi, A. M. Din, and A. Jatowt, “An investigation of SMOTE based methods for imbalanced datasets with data complexity analysis,” IEEE Trans. Knowl. Data Eng., vol. 35, no. 7, pp. 6651–6672, Jul. 2023, doi: 10.1109/TKDE.2022.3179381.

[30] A. Rahali, A. H. Lashkari, G. Kaur, L. Taheri, F. Gagnon, and F. Massicotte, “DIDroid: Android malware classification and characterization using deep image learning,” in ACM International Conference Proceeding Series, Association for Computing Machinery, Nov. 2020, pp. 70–82. doi: 10.1145/3442520.3442522.

[31] N. V Chawla, K. W. Bowyer, L. O. Hall, and W. P. Kegelmeyer, “SMOTE: Synthetic Minority Over-sampling Technique,” Journal of Artificial Intelligence Research, vol. 16, pp. 321–357, 2002, doi: 10.1613/jair.953.

[32] I. Tomek, “Two Modifications of CNN,” IEEE Transactions on Systems Man and Communications, pp. 769–772, 1976, doi: 10.1109/TSMC.1976.4309452.

[33] G. Lemaitre, F. Nogueira, and C. K. Aridas, “Imbalanced-learn: A Python Toolbox to Tackle the Curse of Imbalanced Datasets in Machine Learning,” Sep. 2016, [Online]. Available: http://arxiv.org/abs/1609.06570

[34] T. Chen and C. Guestrin, “XGBoost: A scalable tree boosting system,” in Proceedings of the ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Association for Computing Machinery, Aug. 2016, pp. 785–794. doi: 10.1145/2939672.2939785.

[35] S. Lundberg and S.-I. Lee, “A Unified Approach to Interpreting Model Predictions,” Nov. 2017, [Online]. Available: http://arxiv.org/abs/1705.07874

Downloads

Published

2026-08-30

Issue

Section

Articles

Most read articles by the same author(s)