Feature-Efficient Android Malware Family Classification: A SHAP-Driven Analysis of Dynamic Behavioral Indicators

Android Malware is on the rise, and it is getting
sophisticated, The need to include automated family classification
as a fundamental part of mobile security. Ensemble machine
learning models achieve high accuracy, these models are complex
and hard to explain. Typically, they are black-box systems, and
they rely upon high accuracy. the number of features is thousands
of which makes them computationally expensive. Unavailable
to security analysts. This paper proposes a framework An
ensemble model combining LightGBM-based malware family
classification and SHapley Additive exPlanations (SHAP) to find
minimal explanations. feature set driving model decisions, then
investigates robustness The masking is adversarial, which means
it is done through adversarial feature masking. Experiments on
the CCCS-CIC-AndMal-2020 was used for dynamics analysis
data, and the results of the analysis indicate that XGBoost This
concludes that this particular tool will achieve an F1 score of
76.22The SHAP values show that 50A 3.9× higher accuracy,
speedup compared to training. Adversarial masking At top
ranked SHAP, up to 12% drop in accuracy when compared to
only 4 Usable blind spots for enhancing the model.