ViTDroid and Hybrid Models for Effective Android and IoT Malware Detection
Research Article  ·  Published: 31 March 2025
Issue cover
ICCK Transactions on Advanced Computing and Systems
Volume 1, Issue 1, 2025: 32-47
Research Article Open Access

ViTDroid and Hybrid Models for Effective Android and IoT Malware Detection

1 Department of Computer Science, Qurtuba University of Science & Information Technology, Peshawar 25000, Pakistan
2 Department of Computer Science, Abbottabad University of Science and Technology, Abbottabad 22010, Pakistan
3 College of Mechatronics and Control Engineering, Shenzhen University, Shenzhen 518060, China
4 College of Computer Science and Software Engineering, Shenzhen University, Shenzhen 518060, China
* Corresponding Author: Asim Zeb, [email protected]
Volume 1, Issue 1

Abstract

This paper introduces ViTDroid, a novel hybrid model that combines Vision Transformers (ViTs) and recurrent neural networks (RNNs) to enhance Android and IoT malware detection. ViTDroid addresses critical challenges by leveraging ViTs to capture global spatial dependencies and RNNs (LSTM and GRU) to model temporal patterns, enabling comprehensive analysis of complex malware behaviors. Additionally, the model integrates explainability tools, such as LIME and SHAP, to enhance transparency and trustworthiness, essential for real-world cybersecurity applications. The study evaluates ViTDroid's performance against conventional models, including RNN, LSTM, and GRU, using accuracy, precision, recall, and F1 score as evaluation metrics. Results demonstrate that ViTDroid achieves superior performance with an accuracy of 99.1% for Android malware and 98% for IoT malware. Precision and recall values reach 0.99 and 0.98, respectively, for Android, and 0.97 and 0.98 for IoT, with F1 scores of 0.99 for Android and 0.97 for IoT. These findings underscore ViTDroid's potential as a robust, efficient, and explainable solution to combat evolving threats in mobile and IoT ecosystems, paving the way for future advancements in malware detection systems.

Graphical Abstract

ViTDroid and Hybrid Models for Effective Android and IoT Malware Detection

Keywords

Android malware IoT malware RNN LSTM GRU ViTDroid hybrid models malware detection deep learning

Data Availability Statement

Data will be made available on request.

Funding

This work was supported without any funding.

Conflicts of Interest

The authors declare no conflicts of interest.

Ethical Approval and Consent to Participate

Not applicable.

References

  1. Feth, D., & Pretschner, A. (2012, June). Flexible data-driven security for android. In 2012 IEEE Sixth International Conference on Software Security and Reliability (pp. 41-50). IEEE.
    [CrossRef] [Google Scholar]
  2. Khokhlov, I., & Reznik, L. (2017, April). Data security evaluation for mobile android devices. In 2017 20th Conference of Open Innovations Association (FRUCT) (pp. 154-160). IEEE.
    [CrossRef] [Google Scholar]
  3. Aslan, Ö. A., & Samet, R. (2020). A comprehensive review on malware detection approaches. IEEE Access, 8, 6249-6271.
    [CrossRef] [Google Scholar]
  4. Qamar, A., Karim, A., & Chang, V. (2019). Mobile malware attacks: Review, taxonomy & future directions. Future Generation Computer Systems, 97, 887-909.
    [CrossRef] [Google Scholar]
  5. Senanayake, J., Kalutarage, H., & Al-Kadri, M. O. (2021). Android mobile malware detection using machine learning: A systematic review. Electronics, 10(13), 1606.
    [CrossRef] [Google Scholar]
  6. Yunmar, R. A., Kusumawardani, S. S., Widyawan, & Mohsen, F. (2024). Hybrid android malware detection: a review of heuristic-based approach. IEEE Access, 12, 41255-41286.
    [CrossRef] [Google Scholar]
  7. Ali, A. A., & H Abdul-Qawy, A. S. (2021). Static analysis of malware in android-based platforms: a progress study. International Journal of Computing and Digital Systems, 10(1), 321-331. http://doi.org/10.12785/ijcds/100132
    [Google Scholar]
  8. Halim, M. A., Abdullah, A., & Ariffin, K. A. Z. (2019). Recurrent neural network for malware detection. Int. J. Advance Soft Compu. Appl, 11(1), 43-63. https://www.academia.edu/download/87119101/4_page46-62_Recurrent-Neural-Network.pdf
    [Google Scholar]
  9. Rhode, M., Burnap, P., & Jones, K. (2018). Early-stage malware prediction using recurrent neural networks. Computers & security, 77, 578-594.
    [CrossRef] [Google Scholar]
  10. Vinayakumar, R., Soman, K. P., Poornachandran, P., & Sachin Kumar, S. (2018). Detecting Android malware using long short-term memory (LSTM). Journal of Intelligent & Fuzzy Systems, 34(3), 1277-1288.
    [CrossRef] [Google Scholar]
  11. Sun, G., & Qian, Q. (2018). Deep learning and visualization for identifying malware families. IEEE Transactions on Dependable and Secure Computing, 18(1), 283-295.
    [CrossRef] [Google Scholar]
  12. Muhuri, P. S., Chatterjee, P., Yuan, X., Roy, K., & Esterline, A. (2020). Using a long short-term memory recurrent neural network (LSTM-RNN) to classify network attacks. Information, 11(5), 243.
    [CrossRef] [Google Scholar]
  13. Seneviratne, S., Shariffdeen, R., Rasnayaka, S., & Kasthuriarachchi, N. (2022). Self-supervised vision transformers for malware detection. IEEE Access, 10, 103121-103135.
    [CrossRef] [Google Scholar]
  14. Jo, J., Cho, J., & Moon, J. (2023). A malware detection and extraction method for the related information using the ViT attention mechanism on android operating system. Applied Sciences, 13(11), 6839.
    [CrossRef] [Google Scholar]
  15. Capuano, N., Fenza, G., Loia, V., & Stanzione, C. (2022). Explainable artificial intelligence in cybersecurity: A survey. IEEE Access, 10, 93575-93600.
    [CrossRef] [Google Scholar]
  16. Alamro, H., Mtouaa, W., Aljameel, S., Salama, A. S., Hamza, M. A., & Othman, A. Y. (2023). Automated android malware detection using optimal ensemble learning approach for cybersecurity. IEEE Access, 11, 72509-72517.
    [CrossRef] [Google Scholar]
  17. Wright, J., Dawson Jr, M. E., & Omar, M. (2012). Cyber security and mobile threats: The need for antivirus applications for smart phones. Journal of Information Systems Technology and Planning, 5(14), 40-60. https://www.researchgate.net/publication/255965434
    [Google Scholar]
  18. Albakri, A., Alhayan, F., Alturki, N., Ahamed, S., & Shamsudheen, S. (2023). Metaheuristics with deep learning model for cybersecurity and Android malware detection and classification. Applied Sciences, 13(4), 2172.
    [CrossRef] [Google Scholar]
  19. Rodriguez-Mota, A., Escamilla-Ambrosio, P. J., Happa, J., & Nurse, J. R. (2016, November). Towards IoT cybersecurity modeling: From malware analysis data to IoT system representation. In 2016 8th IEEE Latin-American Conference on Communications (LATINCOM) (pp. 1-6). IEEE.
    [CrossRef] [Google Scholar]
  20. Faruki, P., Bharmal, A., Laxmi, V., Ganmoor, V., Gaur, M. S., Conti, M., & Rajarajan, M. (2014). Android security: a survey of issues, malware penetration, and defenses. IEEE communications surveys & tutorials, 17(2), 998-1022.
    [CrossRef] [Google Scholar]
  21. Shiri, F. M., Perumal, T., Mustapha, N., & Mohamed, R. (2024). A comprehensive overview and comparative analysis on deep learning models: CNN, RNN, LSTM, GRU. Journal on Artificial Intelligence, 6, 301-360.
    [CrossRef] [Google Scholar]
  22. Pan, Y., Ge, X., Fang, C., & Fan, Y. (2020). A systematic literature review of android malware detection using static analysis. Ieee Access, 8, 116363-116379.
    [CrossRef] [Google Scholar]
  23. Taher, F., AlFandi, O., Al-kfairy, M., Al Hamadi, H., & Alrabaee, S. (2023). DroidDetectMW: a hybrid intelligent model for android malware detection. Applied Sciences, 13(13), 7720.
    [CrossRef] [Google Scholar]
  24. Hamza, A. A., Abdel Halim, I. T., Sobh, M. A., & Bahaa-Eldin, A. M. (2022). HSAS-MD analyzer: a hybrid security analysis system using model-checking technique and deep learning for malware detection in IoT apps. Sensors, 22(3), 1079.
    [CrossRef] [Google Scholar]
  25. Rodrigo, C., Pierre, S., Beaubrun, R., & El Khoury, F. (2021). BrainShield: a hybrid machine learning-based malware detection model for android devices. Electronics, 10(23), 2948.
    [CrossRef] [Google Scholar]
  26. Baek, S., Jeon, J., Jeong, B., & Jeong, Y. S. (2021). Two-stage hybrid malware detection using deep learning. Human-centric Computing and Information Sciences, 11(27), 10-22967.
    [CrossRef] [Google Scholar]
  27. Kumar, R., Zhang, X., Wang, W., Khan, R. U., Kumar, J., & Sharif, A. (2019). A multimodal malware detection technique for Android IoT devices using various features. IEEE access, 7, 64411-64430.
    [CrossRef] [Google Scholar]
  28. Ravi, A., Chaturvedi, V., & Shafique, M. (2023). Vit4mal: Lightweight vision transformer for malware detection on edge devices. ACM Transactions on Embedded Computing Systems, 22(5s), 1-26.
    [CrossRef] [Google Scholar]
  29. Alasmary, H., Anwar, A., Park, J., Choi, J., Nyang, D., & Mohaisen, A. (2018). Graph-based comparison of IoT and android malware. In Computational Data and Social Networks: 7th International Conference, CSoNet 2018, Shanghai, China, December 18--20, 2018, Proceedings 7 (pp. 259-272). Springer International Publishing.
    [CrossRef] [Google Scholar]
  30. Ngo, Q. D., Nguyen, H. T., Le, V. H., & Nguyen, D. H. (2020). A survey of IoT malware and detection methods based on static features. ICT express, 6(4), 280-286.
    [CrossRef] [Google Scholar]
  31. Ham, H. S., Kim, H. H., Kim, M. S., & Choi, M. J. (2014). Linear SVM‐based android malware detection for reliable IoT services. Journal of Applied Mathematics, 2014(1), 594501.
    [CrossRef] [Google Scholar]
  32. Liu, X., Du, X., Zhang, X., Zhu, Q., Wang, H., & Guizani, M. (2019). Adversarial samples on android malware detection systems for IoT systems. Sensors, 19(4), 974.
    [CrossRef] [Google Scholar]
  33. Jeon, J., Park, J. H., & Jeong, Y. S. (2020). Dynamic analysis for IoT malware detection with convolution neural network model. Ieee Access, 8, 96899-96911.
    [CrossRef] [Google Scholar]
  34. Liu, K., Xu, S., Xu, G., Zhang, M., Sun, D., & Liu, H. (2020). A review of android malware detection approaches based on machine learning. IEEE access, 8, 124579-124607.
    [CrossRef] [Google Scholar]
  35. Ravi, A., Chaturvedi, V., & Shafique, M. (2023). Vit4mal: Lightweight vision transformer for malware detection on edge devices. ACM Transactions on Embedded Computing Systems, 22(5s), 1-26.
    [CrossRef] [Google Scholar]
  36. Gong, R. H., Zulkernine, M., & Abolmaesumi, P. (2005, May). A software implementation of a genetic algorithm based approach to network intrusion detection. In Sixth International Conference on Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing and First ACIS International Workshop on Self-Assembling Wireless Network (pp. 246-253). IEEE.
    [CrossRef] [Google Scholar]
  37. Hammood, L., Doğru, İ. A., & Kılıç, K. (2023). Machine learning-based adaptive genetic algorithm for android malware detection in auto-driving vehicles. Applied Sciences, 13(9), 5403.
    [CrossRef] [Google Scholar]
  38. Lin, Y., & Chang, X. (2021). Towards interpreting ML-based automated malware detection models: A survey. arXiv preprint arXiv:2101.06232.
    [CrossRef] [Google Scholar]
  39. Lundberg, S. M., & Lee, S. I. (2017). A unified approach to interpreting model predictions. Advances in neural information processing systems, 30.
    [Google Scholar]
  40. García, D. E., DeCastro-García, N., & Castañeda, A. L. M. (2023). An effectiveness analysis of transfer learning for the concept drift problem in malware detection. Expert systems with Applications, 212, 118724.
    [CrossRef] [Google Scholar]
  41. Wong, W. K., Juwono, F. H., & Apriono, C. (2021). Vision-based malware detection: A transfer learning approach using optimal ecoc-svm configuration. Ieee Access, 9, 159262-159270.
    [CrossRef] [Google Scholar]
  42. Panda, P., CU, O. K., Marappan, S., Ma, S., S, M., & Veesani Nandi, D. (2023). Transfer learning for image-based malware detection for iot. Sensors, 23(6), 3253.
    [CrossRef] [Google Scholar]

Cited By (9)

  1. Zeeshan Ali Haider, Asim Zeb, A.K.M.Muzahidul Islam, Taj Rahman, Ali Arishi, Inam Ullah. Enhancing IoT security with resource-efficient cryptography: A comprehensive review of lightweight and hybrid algorithms. Computer Science Review, 2026 , 59 .
    [CrossRef]
  2. Lin Xia, Yuanhe Chen, Lin Han. A deep learning-based IoT malware detection approach for electric vehicle charging stations. Scientific Reports, 2026 , 16 (1).
    [CrossRef]
  3. Fida Muhammad Khan, Asim Zeb, Taj Rahman, Inam Ullah, Nazik Alturki, Ali Kashif Bashir, Yamen El Touati, Nidhal Ben Khedher, Khalid Mahmood Awan. Federated Deep Learning for Collision Avoidance in IoV With Digital Twin Integration. Expert Systems, 2026 , 43 (1).
    [CrossRef]
  4. Muhammad Shoaib Khan, Hongsong Chen, XinJian Ma. Resource-efficient anomaly detection in social media accounts using lightweight LLM models: a review of methods, challenges, and future trends. Cluster Computing, 2026 , 29 (5).
    [CrossRef]
  5. Nasser A. Alsadhan, Inam Ullah Khan, Zeeshan Ali Haider, Fida Muhammad Khan, Inam Ullah. CFSL-BC: Compression-enabled federated split learning with blockchain for robust android malware detection. Computer Networks, 2026 , 287 .
    [CrossRef]
  6. Fida Muhammad Khan, Asim Zeb, Taj Rahman, Mahmoud Ahmad Al-Khasawneh, Yousef Ibrahim Daradkeh, Isma Farah Siddiqui, Ali Kashif Bashir, Inam Ullah. XAI-driven Data Mining for Self-defending IoT Systems: Enhancing Cybersecurity Transparency in the Age of Smart Cities. Cognitive Computation, 2026 , 18 (1).
    [CrossRef]
  7. Jiayin Feng, Limin Shen, Shuxia Liu, Hui Li, Zhen Chen. Dynamic Android Malware Detection Using Hierarchical Graph Attention Neural Networks on Traffic Flow Node Interactions. IEEE Transactions on Consumer Electronics, 2025 , 71 (4).
    [CrossRef]
  8. Inam Ullah Khan, Fida Muhammad Khan, Zeeshan Ali Haider, Fahad Alturise. Integrating AI, Blockchain, and Edge Computing for Zero-Trust IoT Security: A Comprehensive Review of Advanced Cybersecurity Framework. Computers, Materials & Continua, 2025 , 85 (3).
    [CrossRef]
  9. Mohammad Sarwar Hossain Mollah, Mohd Fadzli Bin Marhusin, Syaril Nizam Omar. . 2025 IEEE International Conference on Artificial Intelligence in Engineering and Technology (IICAIET), 2025 .
    [CrossRef]
* Citation data provided by Crossref Cited-by.

Cite This Article

APA Style
Khan, U. I., Zeb, A., Rahman, T., Khan, F. M., Haider, Z. A., & Bilal, H. (2025). ViTDroid and Hybrid Models for Effective Android and IoT Malware Detection. ICCK Transactions on Advanced Computing and Systems, 1(1), 32-47. https://doi.org/10.62762/TACS.2024.521915
Export Citation
RIS Format
Compatible with EndNote, Zotero, Mendeley, and other reference managers
TY  - JOUR
AU  - Khan, Inam Ullah
AU  - Zeb, Asim
AU  - Rahman, Taj
AU  - Khan, Fida Muhammad
AU  - Haider, Zeeshan Ali
AU  - Bilal, Hazrat
PY  - 2025
DA  - 2025/03/31
TI  - ViTDroid and Hybrid Models for Effective Android and IoT Malware Detection
JO  - ICCK Transactions on Advanced Computing and Systems
T2  - ICCK Transactions on Advanced Computing and Systems
JF  - ICCK Transactions on Advanced Computing and Systems
VL  - 1
IS  - 1
SP  - 32
EP  - 47
DO  - 10.62762/TACS.2024.521915
UR  - https://www.icck.org/article/abs/TACS.2024.521915
KW  - Android malware
KW  - IoT malware
KW  - RNN
KW  - LSTM
KW  - GRU
KW  - ViTDroid
KW  - hybrid models
KW  - malware detection
KW  - deep learning
AB  - This paper introduces ViTDroid, a novel hybrid model that combines Vision Transformers (ViTs) and recurrent neural networks (RNNs) to enhance Android and IoT malware detection. ViTDroid addresses critical challenges by leveraging ViTs to capture global spatial dependencies and RNNs (LSTM and GRU) to model temporal patterns, enabling comprehensive analysis of complex malware behaviors. Additionally, the model integrates explainability tools, such as LIME and SHAP, to enhance transparency and trustworthiness, essential for real-world cybersecurity applications. The study evaluates ViTDroid's performance against conventional models, including RNN, LSTM, and GRU, using accuracy, precision, recall, and F1 score as evaluation metrics. Results demonstrate that ViTDroid achieves superior performance with an accuracy of 99.1% for Android malware and 98% for IoT malware. Precision and recall values reach 0.99 and 0.98, respectively, for Android, and 0.97 and 0.98 for IoT, with F1 scores of 0.99 for Android and 0.97 for IoT. These findings underscore ViTDroid's potential as a robust, efficient, and explainable solution to combat evolving threats in mobile and IoT ecosystems, paving the way for future advancements in malware detection systems.
SN  - 3068-7969
PB  - Institute of Central Computation and Knowledge
LA  - English
ER  - 
BibTeX Format
Compatible with LaTeX, BibTeX, and other reference managers
@article{Khan2025ViTDroid,
  author = {Inam Ullah Khan and Asim Zeb and Taj Rahman and Fida Muhammad Khan and Zeeshan Ali Haider and Hazrat Bilal},
  title = {ViTDroid and Hybrid Models for Effective Android and IoT Malware Detection},
  journal = {ICCK Transactions on Advanced Computing and Systems},
  year = {2025},
  volume = {1},
  number = {1},
  pages = {32-47},
  doi = {10.62762/TACS.2024.521915},
  url = {https://www.icck.org/article/abs/TACS.2024.521915},
  abstract = {This paper introduces ViTDroid, a novel hybrid model that combines Vision Transformers (ViTs) and recurrent neural networks (RNNs) to enhance Android and IoT malware detection. ViTDroid addresses critical challenges by leveraging ViTs to capture global spatial dependencies and RNNs (LSTM and GRU) to model temporal patterns, enabling comprehensive analysis of complex malware behaviors. Additionally, the model integrates explainability tools, such as LIME and SHAP, to enhance transparency and trustworthiness, essential for real-world cybersecurity applications. The study evaluates ViTDroid's performance against conventional models, including RNN, LSTM, and GRU, using accuracy, precision, recall, and F1 score as evaluation metrics. Results demonstrate that ViTDroid achieves superior performance with an accuracy of 99.1\% for Android malware and 98\% for IoT malware. Precision and recall values reach 0.99 and 0.98, respectively, for Android, and 0.97 and 0.98 for IoT, with F1 scores of 0.99 for Android and 0.97 for IoT. These findings underscore ViTDroid's potential as a robust, efficient, and explainable solution to combat evolving threats in mobile and IoT ecosystems, paving the way for future advancements in malware detection systems.},
  keywords = {Android malware, IoT malware, RNN, LSTM, GRU, ViTDroid, hybrid models, malware detection, deep learning},
  issn = {3068-7969},
  publisher = {Institute of Central Computation and Knowledge}
}

Article Metrics

Citations
Views
3641
PDF Downloads
935

Publisher's Note

ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and Permissions

CC BY Copyright © 2025 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
ICCK Transactions on Advanced Computing and Systems
ICCK Transactions on Advanced Computing and Systems
ISSN: 3068-7969 (Online)
Portico
Preserved at
Portico