Optimization of Android Malware Detection Based on Permissions Using LightGBM with Hyperparameter Tuning and Chi-Square Feature Selection
DOI:
https://doi.org/10.32664/j-intech.v14i02.2306Keywords:
android, LightGBM, MalwareAbstract
This study aims to develop an efficient Android malware detection framework using the LightGBM algorithm optimized through Chi-Square feature selection and hyperparameter tuning. Although machine learning techniques have been widely applied in Android malware detection, many previous studies primarily focus on classification accuracy while paying limited attention to feature reduction efficiency, computational complexity, and permission-based feature interpretability. Therefore, this study proposes a lightweight permission-based detection framework that integrates Chi-Square feature selection with optimized LightGBM classification to improve detection performance while reducing irrelevant features. The dataset used was obtained from Kaggle and consists of 29,300 Android applications, including 14,630 benign applications and 14,700 malware samples. Each application is represented using 86 binary permission-based features extracted from the AndroidManifest.xml file. The research stages include preprocessing, feature selection, training-testing data splitting, hyperparameter optimization, and model evaluation. Experimental results show that the proposed model achieves an accuracy of 0.96, precision of 0.95, recall of 0.96, F1-score of 0.96, and ROC-AUC of 0.9885. These findings indicate that the proposed framework effectively distinguishes malware from benign applications while maintaining computational efficiency and improving permission-based malware detection interpretability. The novelty of this study lies in the integration of Chi-Square feature selection and Grid Search-optimized LightGBM to develop a lightweight permission-based Android malware detection framework that reduces feature dimensionality while maintaining high detection performance and interpretability.
References
[1] A. L. Chandran, J. Samual, S. Safavi, and A. Ali, “A Comparative Analysis of Machine Learning Models on Detecting Malware in Android Devices,” Journal of Cyber Security and Risk Auditing, vol. 2025, no. 4, pp. 327–346, 2025, doi: 10.63180/jc sra.thestap.2025.4.10
[2] B. Urooj, M. A. L. I. Shah, C. Maple, M. K. Abbasi, and S. Riasat, “Malware Detection : A Framework for Reverse Engineered Android Applications Through Machine Learning Algorithms,” Computer Security and Reliability, vol. 10, no. 1, pp. 89031–89050, 2022.
[3] C. C. Obidiagha and M. Rahouti, “DeepImageDroid : A Hybrid Framework Leveraging Visual Transformers and Convolutional Neural Networks for Robust Android Malware Detection,” International Journal of Digital Crime and Forensics, vol. 12, no. November, pp. 156285–156306, 2024, doi: 10.1109/ACCESS.2024.3485593.
[4] H. Rafiq, N. Aslam, M. Aleem, and B. Issac, “AndroMalPack : enhancing the ML based malware classification by detection and removal of repacked apps for Android systems,” Scientific Reports, pp. 1–18, 2022, doi: 10.1038/s41598-022-23766-w.
[5] S. Bulut and A. Korkmaz, “Comparative Analysis of Machine Learning Models for Android Malware Detection Selma,” Sakarya University Journal of Science, vol. 28, no. 3, pp. 517–530, 2024, doi: 10.1016/j.procs.2023.03.101.
[6] A. Muzaffar, H. Ragab, M. A. Lones, and H. Zantout, “Computers & Security An in-depth review of machine learning based Android malware detection,” vol. 121, 2022.
[7] J. Kim, Y. Ban, E. Ko, and H. Cho, “MAPAS : a practical deep learning-based android malware detection system,” International Journal of Information Security, vol. 21, no. 4, pp. 725–738, 2022, doi: 10.1007/s10207-022-00579-6.
[8] S. Poornima and R. Mahalakshmi, “Automated malware detection using machine learning and deep learning approaches for android applications,” Measurement: Sensors journal, vol. 32, no. May 2023, pp. 1–8, 2024, doi: 10.1016/j.measen.2023.100955.
[9] M. Khalid, A. Sajid, M. Usman, M. Saeed, M. M. Nadeem, and I. Sharma, “Android Security Vulnerabilities, Malware, Anti-Malware Solutions, and Evasion Techniques,” vol. 4, no. 4, pp. 129–145, 2024.
[10] A. Banik and J. P. Singh, “Android Malware Detection by Correlated Real Permission Couples Using FP Growth Algorithm and Neural Networks,” IEEE Access, vol. 11, no. October, pp. 124996–125010, 2023, doi: 10.1109/ACCESS.2023.3323845.
[11] B. Mishra, A. Agarwal, A. Goel, D. Singh, and H. Lee, “Privacy Protection Framework for Android,” INTERNATIONAL JOURNAL OF NOVEL RESEARCH AND DEVELOPMENT, vol. 10, no. 2, pp. 7973–7988, 2022, doi: 10.1109/ACCESS.2022.3142345.
[12] H. Manthena, S. Shajarian, and J. C. Kimmell, “Explainable Artificial Intelligence ( XAI ) for Malware Analysis : A Survey of Techniques , Applications , and Open Challenges,” IEEE Access, vol. 13, no. February, pp. 61611–61640, 2025, doi: 10.1109/ACCESS.2025.3555926.
[13] H. Alomari, Q. M. Yaseen, M. A. Al-betar, and H. Alomari, “A Comparative Analysis of Machine Learning Algorithms for Android Malware Detection,” Procedia Computer Science, vol. 2020, no. 2019, pp. 763–768, 2023, doi: 10.1016/j.procs.2023.03.101.
[14] S. Zhou, H. Li, X. Fu, D. Han, and X. He, “Novel Multi-Classification Dynamic Detection Model for Android Malware Based on Improved Zebra Optimization,” Sensors, vol. 24, no. 18, pp. 1–30, 2024, doi: 10.3390/s24185975.
[15] M. Dhalaria and E. Gandotra, “A Hybrid Approach for Android Malware Detection and Family Classification,” vol. 6, 2020, doi: 10.9781/ijimai.2020.09.001.
[16] E. Kavalcı Yılmaz and H. Bakır, “Hyperparameter Tunning and Feature Selection Methods for Malware Detection,” Politeknik Dergisi (Journal of Polytechnic), vol. 27, no. 1, pp. 343–353, 2024, doi: 10.2339/politeknik.1243881.
[17] Y. Sharma and A. Arora, “IPAnalyzer: A novel Android malware detection system using ranked Intents and Permissions,” Multimedia Tools and Applications, vol. 83, no. 33, pp. 78957–79008, 2024, doi: 10.1007/s11042-024-18511-6.
[18] G. Ahn, K. Kim, and W. Park, “applied sciences Malicious File Detection Method Using Machine Learning and Interworking with MITRE ATT & CK Framework,” Applied Sciences, vol. 12, no. 21, pp. 1–22, 2022, doi: 10.3390/app122110761.
[19] V. R. Joseph, “Optimal ratio for data splitting,” Statistical Analysis and Data Mining, vol. 15, no. 4, pp. 531–538, 2022, doi: 10.1002/sam.11583.
[20] W. Pannakkong, K. Thiwa-anont, K. Singthong, P. Parthanadee, and J. Buddhakulsomsiri, “Hyperparameter Tuning of Machine Learning Algorithms Using Response Surface Methodology : A Case Study of ANN , SVM , and DBN,” vol. 2022, 2022, doi: 10.1155/2022/8513719.
[21] A. Open, A. Journal, S. Samantaray, S. Mohapatra, and M. Mishra, “High-precision forecasting of Indian stock market indices using weighted ensemble of hyperparameter-tuned LightGBM models with diverse technical indicators,” vol. 2583, 2025, doi: 10.1080/21642583.2025.2567887.
[22] D. Demirtürk, Ö. Mintemur, and A. Arslan, “Optimizing LightGBM and XGBoost Algorithms for Estimating Compressive Strength in High-Performance Concrete,” Arabian Journal for Science and Engineering, vol. 51, no. 4, pp. 4401–4423, 2026, doi: 10.1007/s13369-025-10217-7.
[23] K.-H. J. Fahad Akbar, Mehdi Hussain, Rafia Mumtaz, Qaiser Riaz, Ainuddin Wahid Abdul Wahab, “Permissions-Based Detection of Android Malware Using Machine Learning,” Symmetry, vol. 14, no. 2, pp. 1–9, 2022, doi: 10.3390/sym14040718.
[24] J. Mohamad, A. Id, M. Faizal, A. Razak, S. Awang, and S. R. Tuan, “A static analysis approach for Android permission-based malware detection systems,” PLOS ONE, vol. 16, no. 9, pp. 1–23, 2021, doi: 10.1371/journal.pone.0257968.
[25] Y. Wu, M. Li, Q. Zeng, T. Yang, J. Wang, Z. Fang, and L. Cheng, “DroidRL: Feature selection for android malware detection with reinforcement learning,” Computers & Security, vol. 128, p. 103126, 2023, doi: 10.1016/j.cose.2023.103126.
[26] S. Sharma, R. Chhikara, and K. Khanna, “A novel feature selection technique : Detection and classification of Android malware,” Egyptian Informatics Journal, vol. 29, no. December 2024, p. 100618, 2025, doi: 10.1016/j.eij.2025.100618.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 J-INTECH

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.

