•  
  •  
 

Article Type

Review

Abstract

Android malware is not only increasing in size and sophistication but is also a challenge to be detected on a large scale. Static analysis is popular due to its ability to detect malware without running applications or tracing run-time events. However, features, datasets, labeling methods, and assessment methodology differ, which makes studying performance difficult. This is a systematic study of 78 peer reviewed articles written between 2021 and 2026 regarding the Android malware detection by static analysis. In each of the studies, the current survey cover the following feature source, feature representation and engineering, learning paradigms, datasets and labeling methods, and evaluation configuration Permissions, API-based features, opcode-bytecode indicators, manifest-component indicators, metadata-certificate indicators, hybrid static features, adversarial and robustness-oriented designs, graph-based designs, and transformer-based models are represented. Synthesis trade-offs include larger semantic and structural representation, validity risks, that lack of obfuscation resistance is not evaluated, and reporting of repeatability is poor. This study suggests an evidence-based taxonomy and comparative synthesis of static detection methods, structured dataset landscape for decision making, and gap analysis for time sensitive evaluation, leakage prevention, robust benchmarking and repeatable reporting. These findings point to building and experimenting with static detectors for Android malware.

Keywords

Android malware detection, Static analysis permissions, API calls, Opcode, Graph neural networks

Share

COinS