Team Ai
Apppublic

Adit-11/android-malware-detection

sourceHugging Faceupdated 4mo agoView on Hugging Face
1likes
App README

๐Ÿ›ก๏ธ Android Malware Detection System

![Python Version](https://www.python.org/) ![Flask Version](https://flask.palletsprojects.com/) ![scikit--learn](https://scikit-learn.org/) ![License](LICENSE)

An advanced, full-stack Machine Learning application for static Android APK analysis and malware classification. The system extracts application permissions, evaluates risk indicators using a normalized risk engine, and classifies the application as Benign or Malware using a Multi-Classifier Voting Ensemble.

It features a modern, responsive Cyber-Glass UI with dark mode support, an interactive simulated behavioral sandbox, and a developer API testing console.


๐ŸŒŸ Key Features

  • โ€”๐Ÿงช Multi-Model Machine Learning Voting Ensemble: Combines predictions from Random Forest, Gradient Boosting, and Logistic Regression classifiers, returning classification outputs with calculated model confidence levels.
  • โ€”๐Ÿฉบ Normalized Threat Risk Engine: Dynamically calculates a risk score (0-100) based on permission danger weights, permission categories, and known malware permission combination heuristics (e.g., SMS interception or spyware clusters).
  • โ€”๐Ÿ”Ž Static APK Scanner: Extracts manifest permissions directly from uploaded .apk files using signature scan fallbacks.
  • โ€”๐Ÿ’ป Interactive Sandbox Simulator: Step-by-step console visualization of simulated runtime execution events and system registry tracking (regIP, regSP, Accumulators) driven by active permissions. Features a sticky header design and edge-aligned auto-scrolling console window.
  • โ€”๐Ÿ—‚๏ธ Compact Tabbed Results UI: Groups manual analysis outputs into dedicated results tabs (Overview, Sandbox, SHAP Explainer, and Threats & Alternatives) for single-screen visibility and zero layout-shifting.
  • โ€”๐Ÿš€ Performance-Tuned Rendering: Uses lazy-loading for charts (SHAP and Dashboard stats) and optimized targeted CSS transitions (replacing wildcard rules) to eliminate all lag.
  • โ€”๐Ÿ“ˆ Compliance Auditor PDF Export: Clean, print-friendly report stylesheets tailored for exporting complete security audits to PDF files. Automatically compiles the full vertical audit report (selected permissions list, risk gauge, model voting table, sandbox logs, SHAP charts, and alternative code recommendations) across clean page breaks.

๐Ÿ—๏ธ System Architecture

mermaid
graph TD
    A[APK Upload / Manual Selection] --> B[Feature Extraction & Categorization]
    B --> C[Normalized Risk Scoring Engine]
    B --> D[Ensemble Model Inference]
    C --> E[Risk Level Classifier: Low/Med/High/Critical]
    D --> F[Multi-Model Consensus & Confidence %]
    E --> G[Cyber-Glass Web Interface & Sandbox simulation]
    F --> G
    G --> H[Auditing PDF Report Generation]

๐Ÿ“Š Model Performance Comparison

The classifiers were trained on the TUANDROMD dataset containing over 4,460 annotated malware and benign apps:

Classifier ModelTrain AccuracyTest AccuracyPrecisionRecallF1-Score
Voting Ensemble (Consensus)97.19%97.42%97.0%97.0%97.0%
Random Forest Classifier97.19%97.42%97.0%97.0%97.0%
Gradient Boosting96.85%96.88%96.0%97.0%96.0%
Logistic Regression93.88%94.17%94.0%94.0%94.0%

๐Ÿš€ Quick Start Guide

1. Clone & Set Up Directory

bash
git clone <your-repository-url>
cd Andriod-Malware-Detection

2. Configure Virtual Environment & Dependencies

bash
# Create virtual environment
python -m venv venv

# Activate on macOS/Linux
source venv/bin/activate

# Install requirements
pip install -r requirements.txt

3. Launch the Server

bash
python app.py
  • โ€”Access the application in your browser at: http://localhost:5005
  • โ€”Demo Credentials: Username: admin / Password: admin123

๐Ÿ› ๏ธ API Documentation

POST /api/predict

Executes manual predictions based on selected permission arrays.

Request Payload:

json
{
  "app_name": "Calculator",
  "model": "Voting Ensemble",
  "permissions": ["SEND_SMS", "READ_SMS", "RECEIVE_SMS"]
}

Response Payload:

json
{
  "success": true,
  "prediction": "Malware",
  "confidence": 98.75,
  "risk_score": 35.0,
  "risk_level": "LOW",
  "active_permissions": 3,
  "model_used": "Voting Ensemble"
}

๐Ÿ“œ License

Distributed under the MIT License. See LICENSE for more information.