Adit-11/android-malware-detection
๐ก๏ธ Android Malware Detection System
   
An advanced, full-stack Machine Learning application for static Android APK analysis and malware classification. The system extracts application permissions, evaluates risk indicators using a normalized risk engine, and classifies the application as Benign or Malware using a Multi-Classifier Voting Ensemble.
It features a modern, responsive Cyber-Glass UI with dark mode support, an interactive simulated behavioral sandbox, and a developer API testing console.
๐ Key Features
- ๐งช Multi-Model Machine Learning Voting Ensemble: Combines predictions from Random Forest, Gradient Boosting, and Logistic Regression classifiers, returning classification outputs with calculated model confidence levels.
- ๐ฉบ Normalized Threat Risk Engine: Dynamically calculates a risk score (0-100) based on permission danger weights, permission categories, and known malware permission combination heuristics (e.g., SMS interception or spyware clusters).
- ๐ Static APK Scanner: Extracts manifest permissions directly from uploaded
.apkfiles using signature scan fallbacks. - ๐ป Interactive Sandbox Simulator: Step-by-step console visualization of simulated runtime execution events and system registry tracking (
regIP,regSP, Accumulators) driven by active permissions. Features a sticky header design and edge-aligned auto-scrolling console window. - ๐๏ธ Compact Tabbed Results UI: Groups manual analysis outputs into dedicated results tabs (Overview, Sandbox, SHAP Explainer, and Threats & Alternatives) for single-screen visibility and zero layout-shifting.
- ๐ Performance-Tuned Rendering: Uses lazy-loading for charts (SHAP and Dashboard stats) and optimized targeted CSS transitions (replacing wildcard rules) to eliminate all lag.
- ๐ Compliance Auditor PDF Export: Clean, print-friendly report stylesheets tailored for exporting complete security audits to PDF files. Automatically compiles the full vertical audit report (selected permissions list, risk gauge, model voting table, sandbox logs, SHAP charts, and alternative code recommendations) across clean page breaks.
๐๏ธ System Architecture
graph TD
A[APK Upload / Manual Selection] --> B[Feature Extraction & Categorization]
B --> C[Normalized Risk Scoring Engine]
B --> D[Ensemble Model Inference]
C --> E[Risk Level Classifier: Low/Med/High/Critical]
D --> F[Multi-Model Consensus & Confidence %]
E --> G[Cyber-Glass Web Interface & Sandbox simulation]
F --> G
G --> H[Auditing PDF Report Generation]๐ Model Performance Comparison
The classifiers were trained on the TUANDROMD dataset containing over 4,460 annotated malware and benign apps:
๐ Quick Start Guide
1. Clone & Set Up Directory
git clone <your-repository-url>
cd Andriod-Malware-Detection2. Configure Virtual Environment & Dependencies
# Create virtual environment
python -m venv venv
# Activate on macOS/Linux
source venv/bin/activate
# Install requirements
pip install -r requirements.txt3. Launch the Server
python app.py- Access the application in your browser at:
http://localhost:5005 - Demo Credentials: Username:
admin/ Password:admin123
๐ ๏ธ API Documentation
POST /api/predict
Executes manual predictions based on selected permission arrays.
Request Payload:
{
"app_name": "Calculator",
"model": "Voting Ensemble",
"permissions": ["SEND_SMS", "READ_SMS", "RECEIVE_SMS"]
}Response Payload:
{
"success": true,
"prediction": "Malware",
"confidence": 98.75,
"risk_score": 35.0,
"risk_level": "LOW",
"active_permissions": 3,
"model_used": "Voting Ensemble"
}๐ License
Distributed under the MIT License. See LICENSE for more information.
