Aller au contenu principal
2026 article

FALCON: Federated Active Learning-Based Concept Drift Adaptation for Malware Detection

0Citations signalées, ce qui n’est pas une note de qualité
2Institutions déclarées
2Pays d’affiliation déclarés

Rattachement africain : cn, sg. Niveau de preuve : code pays fourni par la source.

Le résumé fourni par la source

Mobile malware detection faces critical challenges from concept drift, as evolving threat characteristics make static detection models ineffective. Active learning supports continual model adaptation to mitigate concept drift. However, it requires manual annotation. This limits scalability when drift samples grow rapidly. Federated learning is a promising alternative. It leverages distributed data and can reduce labeling demand. Nevertheless, existing federated malware detection methods still face challenges under concept drift. First, many prior approaches assume the availability of abundant, reliable labels for every client. In practice, each client observes only a partial and evolving drift. It also has a limited labeling budget. Second, statistical heterogeneity can lead to divergence between local and global models, complicating drift sample selection. Third, continual adaptation can keep expanding the training set. This increases storage overhead. We propose FALCON (FederatedActiveLearning-BasedCONcept Drift Adaptation for Malware Detection), the first federated active learning framework specifically designed for malware concept drift adaptation. FALCON integrates budget-aware federated active learning to cover drift patterns across clients. It also uses a diversity-enhanced selection strategy that combines local diversity with global uncertainty. In addition, it applies value-based data management to prune low-value samples, which bounds training-set growth and supports long-term scalability. Comprehensive experiments on two large-scale real-world datasets, APIGraph with over 300K samples spanning 7 years and AndroZoo with over 100K samples spanning 3 years, demonstrate consistent improvements of FALCON over prior methods. Compared with 14 baselines, FALCON achieves the best F1-AUT on both datasets. On APIGraph, it improves over the strongest baseline by 0.02, reaching 0.91. On AndroZoo, it improves by 0.05 and reaches 0.80. On the concept-drift-focused cumulative undetected malware metric, FALCON reduces the count by 7% on APIGraph and by 67% on AndroZoo relative to the strongest baseline. In addition, FALCON reduces storage overhead compared with existing baselines, with an average reduction of 8.62% across the two datasets.

Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.

Le contrôle bibliographique ouvert

DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.

Titre Crossref
FALCON: Federated Active Learning-Based Concept Drift Adaptation for Malware Detection
Date Crossref
01/10/2026
Éditeur
Institute of Electrical and Electronics Engineers (IEEE)
Type
journal-article

Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.

Où se fait cette recherche

  • Beijing Jiaotong University pays non établi dans la notice
    Université ou école supérieure
  • Nanyang Technological University pays non établi dans la notice
    Université ou école supérieure

Beijing Jiaotong University et Nanyang Technological University.

Une affiliation ne permet pas de déduire la nationalité d’un auteur.

Les sujets associés

Data Stream Mining TechniquesAdvanced Malware Detection TechniquesAnomaly Detection Techniques and Applications

BNTIC News n’est pas le producteur de ces données. Les publications sont interrogées à la demande dans Crossref, OpenAIRE, DOAJ, Europe PMC, HAL, DataCite, AfricArXiv, ROR et la Banque mondiale, sans clé d’accès. OpenAlex reste optionnel. Aucun service payant n’est nécessaire et aucune donnée externe n’est enregistrée en base. Consulter les sources et leurs limites.