FALCON: Federated Active Learning-Based Concept Drift Adaptation for Malware Detection
Rattachement africain : cn, sg. Niveau de preuve : code pays fourni par la source.
Le résumé fourni par la source
Mobile malware detection faces critical challenges from concept drift, as evolving threat characteristics make static detection models ineffective. Active learning supports continual model adaptation to mitigate concept drift. However, it requires manual annotation. This limits scalability when drift samples grow rapidly. Federated learning is a promising alternative. It leverages distributed data and can reduce labeling demand. Nevertheless, existing federated malware detection methods still face challenges under concept drift. First, many prior approaches assume the availability of abundant, reliable labels for every client. In practice, each client observes only a partial and evolving drift. It also has a limited labeling budget. Second, statistical heterogeneity can lead to divergence between local and global models, complicating drift sample selection. Third, continual adaptation can keep expanding the training set. This increases storage overhead. We propose FALCON (FederatedActiveLearning-BasedCONcept Drift Adaptation for Malware Detection), the first federated active learning framework specifically designed for malware concept drift adaptation. FALCON integrates budget-aware federated active learning to cover drift patterns across clients. It also uses a diversity-enhanced selection strategy that combines local diversity with global uncertainty. In addition, it applies value-based data management to prune low-value samples, which bounds training-set growth and supports long-term scalability. Comprehensive experiments on two large-scale real-world datasets, APIGraph with over 300K samples spanning 7 years and AndroZoo with over 100K samples spanning 3 years, demonstrate consistent improvements of FALCON over prior methods. Compared with 14 baselines, FALCON achieves the best F1-AUT on both datasets. On APIGraph, it improves over the strongest baseline by 0.02, reaching 0.91. On AndroZoo, it improves by 0.05 and reaches 0.80. On the concept-drift-focused cumulative undetected malware metric, FALCON reduces the count by 7% on APIGraph and by 67% on AndroZoo relative to the strongest baseline. In addition, FALCON reduces storage overhead compared with existing baselines, with an average reduction of 8.62% across the two datasets.
Ce résumé expose les affirmations des auteurs. BNTIC ne l’interprète pas comme une validation indépendante des résultats.
Le contrôle bibliographique ouvert
DOI retrouvé dans Crossref DOI retrouvé ; titre concordant.
- Titre Crossref
- FALCON: Federated Active Learning-Based Concept Drift Adaptation for Malware Detection
- Date Crossref
- 01/10/2026
- Éditeur
- Institute of Electrical and Electronics Engineers (IEEE)
- Type
- journal-article
Ce recoupement confirme des métadonnées liées au DOI. Il ne confirme ni la méthode ni les conclusions de l’étude, et il ne compte pas comme une seconde source scientifique indépendante.
Où se fait cette recherche
-
Beijing Jiaotong University pays non établi dans la noticeUniversité ou école supérieure
-
Nanyang Technological University pays non établi dans la noticeUniversité ou école supérieure
Beijing Jiaotong University et Nanyang Technological University.
Une affiliation ne permet pas de déduire la nationalité d’un auteur.