Beyond Mean Aggregation: A Variance-Enhanced Graph Neural Network for Android Malware Detection

Main Article Content

Karfindo Karfindo
Muhammad Diponegoro
Yusril Eka Mahendra
Mohamad Arifin

Abstract

Android malware continues to pose a significant threat to mobile security, with millions of malicious applications detected annually. Graph Neural Networks (GNNs) applied to Function Call Graphs (FCGs) have emerged as a promising approach for malware detection. However, existing GNN-based methods rely predominantly on mean aggregation, capturing only the first-order statistical moment of neighborhood representations—insufficient for heterogeneous FCGs where malware classes exhibit fundamentally different connectivity patterns. We present an empirical analysis demonstrating that neighborhood degree variance differs significantly across malware classes (ANOVA, p < 0.001), motivating variance as an explicit aggregation signal. Based on this finding, we propose VE-GNN, a Variance-Enhanced Graph Neural Network incorporating mean and variance aggregation within a residual message-passing framework. Experiments on MalNet-Tiny with five independent runs show that VE-GNN achieves a macro F1-score of 0.9261 ± 0.0077, outperforming GIN by 4.57% (paired t-test, p < 0.001). Ablation studies confirm that mean-variance aggregation is optimal, as higher-order moments degrade performance without adaptive selection. The proposed method offers an effective and computationally efficient solution for GNN-based Android malware detection.

Article Details

How to Cite
[1]
K. Karfindo, M. Diponegoro, Y. Eka Mahendra, and M. Arifin, “Beyond Mean Aggregation: A Variance-Enhanced Graph Neural Network for Android Malware Detection”, ECTI-CIT Transactions, vol. 20, no. 4, pp. 631–642, Sep. 2026.
Section
Research Article

References

G. Srinivas and M. V. Rajesh, “A Comprehensive Review on Android Malware Detection: Techniques, Challenges, and Future Directions,” 2025 International Conference on Knowledge Engineering and Communication Systems (ICKECS), Chickballapur, India, pp. 1-6, 2025.

A. Razgallah, R. Khoury, S. Hall´e and K. Khanmohammadi, “A survey of malware detection in Android apps: Recommendations and perspectives for future research,” Computer Science Review, vol. 39, p. 100358, Feb. 2021.

Y. Liu, C. Tantithamthavorn, L. Li and Y. Liu, “Deep learning for Android malware defenses: A systematic literature review,” ACM Computing Surveys, vol. 55, no. 8, Aug. 2023.

Google, “How we fought bad apps and bad actors in 2023,” Google Online Security Blog, Apr. 2024. [Online]. Available: https: //security.googleblog.com/2024/04/ how-we-fought-bad-apps-and-bad-actors -in-2023.html. [Accessed: Jun. 20, 2026].

Y. Ye, T. Li, D. Adjeroh and S. S. Iyengar, “A survey on malware detection using data mining techniques,” ACM Computing Surveys, vol. 50, no. 3, May 2018.

M. K. Alzaylaee, S. Y. Yerima and S. Sezer, “DLDroid: Deep learning based Android malware detection using real devices,” Computers & Security, vol. 89, p. 101663, Feb. 2020.

H. Gascon, F. Yamaguchi, D. Arp and K. Rieck, “Structural detection of Android malware using embedded call graphs,” in Proceedings of the AISec ’13: Proceedings of the 2013 ACM workshop on Artificial intelligence and security, pp. 45–54, 2013.

J. Zhou et al., “Graph neural networks: A review of methods and applications,” AI Open, vol. 1, pp. 57–81, 2020.

S. Freitas, Y. Dong, J. Neil, and D. H. Chau, “A large-scale database for graph representation learning.” [Online]. Available: https:// mal-net.org/

T. N. Kipf and M. Welling, “Semi-supervised classification with graph convolutional networks,” arXiv preprint arXiv:1609.02907, 2016.

P. Veliˇckovi´c, G. Cucurull, A. Casanova, A. Romero, P. Li`o and Y. Bengio, “Graph attention networks,” in Proceedings of the International Conference on Learning Representations (ICLR), 2018.

W. L. Hamilton, R. Ying, and J. Leskovec, “Inductive representation learning on large graphs,” in Advances in Neural Information Processing Systems (NeurIPS), vol. 30, 2017.

K. Xu, W. Hu, J. Leskovec and S. Jegelka, “How powerful are graph neural networks?” in Proceedings of the International Conference on Learning Representations (ICLR), 2019.

G. Corso, L. Cavalleri, D. Beaini, P. Li`o and P. Veliˇckovi´c, “Principal neighbourhood aggregation for graph nets,” in Advances in Neural Information Processing Systems (NeurIPS), vol. 33, pp. 13260–13271, 2020.

Z. Wu, S. Pan, F. Chen, G. Long, C. Zhang and P. S. Yu, “A Comprehensive Survey on Graph Neural Networks,” in IEEE Transactions on Neural Networks and Learning Systems, vol. 32, no. 1, pp. 4-24, Jan. 2021.

F. Scarselli, M. Gori, A. C. Tsoi, M. Hagenbuchner and G. Monfardini, “The Graph Neural Network Model,” in IEEE Transactions on Neural Networks, vol. 20, no. 1, pp. 61-80, Jan. 2009.

V. P. Dwivedi, C. K. Joshi, A. T. Luu, T. Laurent, Y. Bengio and X. Bresson, “Benchmarking graph neural networks,” The Journal of Machine Learning Research, vol. 24, no. 1, pp. 1730-1777, 2023.

C. Morris et al., “Weisfeiler and Leman go neural: Higher-order graph neural networks,” in Proceedings of the Thirty-Third AAAI Conference on Artificial Intelligence and Thirty-First Innovative Applications of Artificial Intelligence Conference and Ninth AAAI Symposium on Educational Advances in Artificial Intelligence, vol. 33, no. 1, pp. 4602–4609, 2019,

D. Arp, M. Spreitzenbarth, M. H¨ubner, H. Gascon and K. Rieck, “DREBIN: Effective and explainable detection of Android malware in your pocket,” in Proceedings of the Network and Distributed System Security (NDSS), 2014.

E. Mariconti, L. Onwuzurike, P. Andriotis, E. De Cristofaro, G. Ross and G. Stringhini, “MaMaDroid: Detecting Android malware by building Markov chains of behavioral models,” in Proceedings of the Network and Distributed System Security (NDSS), 2017.

J. Tang et al., “Android malware detection based on a novel mixed bytecode image combined with attention mechanism,” Journal of Information Security and Applications, vol. 82, p. 103721, May 2024

N. Zhang, Y. Tan, C. Yang and Y. Li, “Deep learning feature exploration for Android malware detection,” Applied Soft Computing, vol. 102, p. 107069, Apr. 2021.

X. Wang and C. Li, “Android malware detection through machine learning on kernel task structures,” Neurocomputing, vol. 435, pp. 126–150, May 2021.

H. Cai, N. Meng, B. Ryder and D. Yao, “DroidCat: Effective Android Malware Detection and Categorization via App-Level Profiling,” in IEEE Transactions on Information Forensics and Security, vol. 14, no. 6, pp. 14551470, June 2019.

M. Fan, J. Liu, W. Wang, H. Li, Z. Tian and T. Liu, “DAPASA: Detecting Android Piggybacked Apps Through Sensitive Subgraph Analysis,” in IEEE Transactions on Information Forensics and Security, vol. 12, no. 8, pp. 1772-1785, Aug. 2017.

A. Arora, S. K. Peddoju and M. Conti, “PermPair: Android Malware Detection Using Permission Pairs,” in IEEE Transactions on Information Forensics and Security, vol. 15, pp. 1968-1982, 2020.

H. Gao, S. Cheng and W. Zhang, “GDroid: Android malware detection and classification with graph convolutional network,” Computers & Security, vol. 106, p. 102264, Jul. 2021

Z. Liu, R. Wang, N. Japkowicz, H. M. Gomes, B. Peng and W. Zhang, “SeGDroid: An Android malware detection method based on sensitive function call graph learning,” Expert Systems with Applications, vol. 235, p. 121125, Jan. 2024.

R. Surendran, T. Thomas and S. Emmanuel, “GSDroid: Graph signal based compact feature representation for Android malware detection,” Expert Systems with Applications, vol. 159, p. 113581, Nov. 2020.

J. Gu, H. Zhu, Z. Han, X. Li and J. Zhao, “GSEDroid: GNN-based Android malware detection framework using lightweight semantic embedding,” Computers & Security, vol. 140, p. 103807, May 2024.

L. Shen, M. Fang and J. Xu, “GHGDroid: Global heterogeneous graph-based Android malware detection,” Computers & Security, vol. 141, p. 103846, Jun. 2024.

A. Tekin, A. S. Bozkir and M. Aydosa, “AndroMesh: Android malware detection using graph neural networks with function-aware localglobal topology,” Procedia Computer Science, vol. 269, pp. 1012–1021, 2025.

W. Guo et al., “MalHAPGNN: An enhanced call graph-based malware detection framework using hierarchical attention pooling graph neural network,” Sensors, vol. 25, no. 2, p. 374, Jan. 2025.

N. N. Tran, A. Said, W. Abbas, T. Derr and X. D. Koutsoukos, “Quantifying the generalization gap: A new benchmark for out-of-distribution graph-based Android malware classification,” arXiv preprint arXiv:2508.06734, 2026.

W. Zhang, H. Wang, H. He and P. Liu, “DAMBA: Detecting Android Malware by ORGB Analysis,” in IEEE Transactions on Reliability, vol. 69, no. 1, pp. 55-69, March 2020.

R. Mogg, S. Enoch and D. S. Kim, “A framework for generating evasion attacks for machine learning-based network intrusion detection systems,” in Information Security Applications, Springer, pp. 51-63, 2021.