Android-Malware Detection Using LLM
DOI:
https://doi.org/10.47392/IRJAEH.2026.0491Keywords:
Android,, Malware Detection, Large Language Models (LLMs), Explainable AI (XAI), Cybersecurity, RAG, Static AnalysisAbstract
The Android operating system dominates the mobile market, making it a prime target for malicious software (malware). For years, security researchers have relied on machine learning and deep learning models to detect these threats. While effective, these traditional methods often act as "black boxes," providing a "malicious" or "benign" label with little to no explanation. This lack of interpretability makes it difficult to analyze new threats or trust the model's decisions. The recent rise of Large Language Models (LLMs) presents a new paradigm. This paper reviews the emerging field of LLM-based Android malware detection. We use the LLM-MalDetect framework, which achieves 98.97% accuracy by fine-tuning a model on string-based features, as a baseline to demonstrate the power of LLMs as direct classifiers. We then survey the different ways researchers are applying these models: not just for classification, but as semantic feature extractors (AppPoet), synthetic data generators (Syn-detect), and, most importantly, as explainable analysis tools (MalLoc, TraceRAG). We find that the true innovation of LLMs lies not just in their high accuracy but in their unique ability to provide human-readable, code-grounded explanations for why an application is malicious, shifting the field from simple detection to true behavioral analysis.
Downloads
Downloads
Published
Issue
Section
License
Copyright (c) 2026 International Research Journal on Advanced Engineering Hub (IRJAEH)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
.