Android malware detection collapses when the context stage comes out

Researchers have found that machine learning-based Android malware detectors often misidentify legitimate apps as malicious due to their broad permission requirements. The study highlights that 'deviation is not maliciousness,' as many benign tools require extensive access to function correctly.
Why it matters
This research exposes a critical flaw in current cybersecurity tools, which could lead to the mass rejection of legitimate software in app stores and enterprise environments.
Android malware detection collapses when the context stage comes out A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged.
Six Android detectors in wide research use, including Drebin, MalScan, and MaskDroid, produced that result on more than half the apps in a benign test set assembled from 49 Google Play categories. The worst performer, an LLM-based detector called LAMD, flagged 80% of them. Anyone gating an app store, an enterprise deployment, or a build pipeline on those verdicts is working a queue made mostly of legitimate software.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in