{"id":"https:\/\/openalex.org\/W4411996801","doi":"https:\/\/doi.org\/10.1109\/spw67851.2025.00042","title":"LeoDroid: An LLM-Based Few-Shot Multi-Label Detection for Android Malware","display_name":"LeoDroid: An LLM-Based Few-Shot Multi-Label Detection for Android Malware","publication_year":2025,"publication_date":"2025-05-15","ids":{"openalex":"https:\/\/openalex.org\/W4411996801","doi":"https:\/\/doi.org\/10.1109\/spw67851.2025.00042"},"language":"en","primary_location":{"id":"doi:10.1109\/spw67851.2025.00042","is_oa":false,"landing_page_url":"https:\/\/doi.org\/10.1109\/spw67851.2025.00042","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Security and Privacy Workshops (SPW)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https:\/\/openalex.org\/A5109768179","display_name":"Minhong Dong","orcid":"https:\/\/orcid.org\/0009-0002-6762-4902"},"institutions":[{"id":"https:\/\/openalex.org\/I198091727","display_name":"Tianjin Polytechnic University","ror":"https:\/\/ror.org\/00xsr9m91","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I198091727"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Minhong Dong","raw_affiliation_strings":["School of Software, Tiangong University,Tianjin,China"],"affiliations":[{"raw_affiliation_string":"School of Software, Tiangong University,Tianjin,China","institution_ids":["https:\/\/openalex.org\/I198091727"]}]},{"author_position":"middle","author":{"id":"https:\/\/openalex.org\/A5100657035","display_name":"Liyuan Liu","orcid":"https:\/\/orcid.org\/0000-0003-2585-323X"},"institutions":[{"id":"https:\/\/openalex.org\/I194450716","display_name":"Jilin University","ror":"https:\/\/ror.org\/00js3aw79","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I194450716"]},{"id":"https:\/\/openalex.org\/I4210134929","display_name":"Jilin Province Science and Technology Department","ror":"https:\/\/ror.org\/049x38272","country_code":"CN","type":"government","lineage":["https:\/\/openalex.org\/I4210134929"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Liyuan Liu","raw_affiliation_strings":["College of Computer Science and Technology, Jilin University,Jilin,China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Jilin University,Jilin,China","institution_ids":["https:\/\/openalex.org\/I4210134929","https:\/\/openalex.org\/I194450716"]}]},{"author_position":"middle","author":{"id":"https:\/\/openalex.org\/A5101834321","display_name":"Qi Guo","orcid":"https:\/\/orcid.org\/0000-0002-8329-7668"},"institutions":[{"id":"https:\/\/openalex.org\/I162868743","display_name":"Tianjin University","ror":"https:\/\/ror.org\/012tb2g32","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I162868743"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qi Guo","raw_affiliation_strings":["College of Intelligence and Computing, Tianjin University,Tianjin,China"],"affiliations":[{"raw_affiliation_string":"College of Intelligence and Computing, Tianjin University,Tianjin,China","institution_ids":["https:\/\/openalex.org\/I162868743"]}]},{"author_position":"middle","author":{"id":"https:\/\/openalex.org\/A5020536498","display_name":"Hongpeng Bai","orcid":"https:\/\/orcid.org\/0000-0002-6298-3327"},"institutions":[{"id":"https:\/\/openalex.org\/I162868743","display_name":"Tianjin University","ror":"https:\/\/ror.org\/012tb2g32","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I162868743"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hongpeng Bai","raw_affiliation_strings":["College of Intelligence and Computing, Tianjin University,Tianjin,China"],"affiliations":[{"raw_affiliation_string":"College of Intelligence and Computing, Tianjin University,Tianjin,China","institution_ids":["https:\/\/openalex.org\/I162868743"]}]},{"author_position":"middle","author":{"id":"https:\/\/openalex.org\/A5000461602","display_name":"Ruijie Gong","orcid":"https:\/\/orcid.org\/0000-0002-4971-1802"},"institutions":[{"id":"https:\/\/openalex.org\/I198091727","display_name":"Tianjin Polytechnic University","ror":"https:\/\/ror.org\/00xsr9m91","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I198091727"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ruijie Gong","raw_affiliation_strings":["School of Software, Tiangong University,Tianjin,China"],"affiliations":[{"raw_affiliation_string":"School of Software, Tiangong University,Tianjin,China","institution_ids":["https:\/\/openalex.org\/I198091727"]}]},{"author_position":"middle","author":{"id":"https:\/\/openalex.org\/A5053292340","display_name":"Yude Bai","orcid":null},"institutions":[{"id":"https:\/\/openalex.org\/I198091727","display_name":"Tianjin Polytechnic University","ror":"https:\/\/ror.org\/00xsr9m91","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I198091727"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yude Bai","raw_affiliation_strings":["School of Software, Tiangong University,Tianjin,China"],"affiliations":[{"raw_affiliation_string":"School of Software, Tiangong University,Tianjin,China","institution_ids":["https:\/\/openalex.org\/I198091727"]}]},{"author_position":"middle","author":{"id":"https:\/\/openalex.org\/A5100308583","display_name":"Wenying He","orcid":null},"institutions":[{"id":"https:\/\/openalex.org\/I184843921","display_name":"Hebei University of Technology","ror":"https:\/\/ror.org\/018hded08","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I184843921"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenying He","raw_affiliation_strings":["School of Artificial Intelligence, Hebei University of Technology,Tianjin,China"],"affiliations":[{"raw_affiliation_string":"School of Artificial Intelligence, Hebei University of Technology,Tianjin,China","institution_ids":["https:\/\/openalex.org\/I184843921"]}]},{"author_position":"middle","author":{"id":"https:\/\/openalex.org\/A5025220226","display_name":"Ze Wang","orcid":"https:\/\/orcid.org\/0000-0001-6971-2004"},"institutions":[{"id":"https:\/\/openalex.org\/I198091727","display_name":"Tianjin Polytechnic University","ror":"https:\/\/ror.org\/00xsr9m91","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I198091727"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ze Wang","raw_affiliation_strings":["School of Software, Tiangong University,Tianjin,China"],"affiliations":[{"raw_affiliation_string":"School of Software, Tiangong University,Tianjin,China","institution_ids":["https:\/\/openalex.org\/I198091727"]}]},{"author_position":"middle","author":{"id":"https:\/\/openalex.org\/A5040791046","display_name":"Guangquan Xu","orcid":"https:\/\/orcid.org\/0000-0001-8701-3944"},"institutions":[{"id":"https:\/\/openalex.org\/I162868743","display_name":"Tianjin University","ror":"https:\/\/ror.org\/012tb2g32","country_code":"CN","type":"education","lineage":["https:\/\/openalex.org\/I162868743"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guangquan Xu","raw_affiliation_strings":["College of Intelligence and Computing, Tianjin University,Tianjin,China"],"affiliations":[{"raw_affiliation_string":"College of Intelligence and Computing, Tianjin University,Tianjin,China","institution_ids":["https:\/\/openalex.org\/I162868743"]}]},{"author_position":"last","author":{"id":"https:\/\/openalex.org\/A5100329259","display_name":"Ji Zhang","orcid":"https:\/\/orcid.org\/0000-0002-1244-2880"},"institutions":[{"id":"https:\/\/openalex.org\/I185523456","display_name":"University of Southern Queensland","ror":"https:\/\/ror.org\/04sjbnx57","country_code":"AU","type":"education","lineage":["https:\/\/openalex.org\/I185523456"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Ji Zhang","raw_affiliation_strings":["University of Southern Queensland,Queensland,Australia"],"affiliations":[{"raw_affiliation_string":"University of Southern Queensland,Queensland,Australia","institution_ids":["https:\/\/openalex.org\/I185523456"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":10,"corresponding_author_ids":["https:\/\/openalex.org\/A5109768179"],"corresponding_institution_ids":["https:\/\/openalex.org\/I198091727"],"apc_list":null,"apc_paid":null,"fwci":3.8348,"has_fulltext":false,"cited_by_count":3,"citation_normalized_percentile":{"value":0.93453112,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"294","last_page":"306"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https:\/\/openalex.org\/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9995999932289124,"subfield":{"id":"https:\/\/openalex.org\/subfields\/1711","display_name":"Signal Processing"},"field":{"id":"https:\/\/openalex.org\/fields\/17","display_name":"Computer Science"},"domain":{"id":"https:\/\/openalex.org\/domains\/3","display_name":"Physical Sciences"}},"topics":[{"id":"https:\/\/openalex.org\/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9995999932289124,"subfield":{"id":"https:\/\/openalex.org\/subfields\/1711","display_name":"Signal Processing"},"field":{"id":"https:\/\/openalex.org\/fields\/17","display_name":"Computer Science"},"domain":{"id":"https:\/\/openalex.org\/domains\/3","display_name":"Physical Sciences"}},{"id":"https:\/\/openalex.org\/T12034","display_name":"Digital and Cyber Forensics","score":0.9800999760627747,"subfield":{"id":"https:\/\/openalex.org\/subfields\/1710","display_name":"Information Systems"},"field":{"id":"https:\/\/openalex.org\/fields\/17","display_name":"Computer Science"},"domain":{"id":"https:\/\/openalex.org\/domains\/3","display_name":"Physical Sciences"}},{"id":"https:\/\/openalex.org\/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9800000190734863,"subfield":{"id":"https:\/\/openalex.org\/subfields\/1710","display_name":"Information Systems"},"field":{"id":"https:\/\/openalex.org\/fields\/17","display_name":"Computer Science"},"domain":{"id":"https:\/\/openalex.org\/domains\/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https:\/\/openalex.org\/keywords\/malware","display_name":"Malware","score":0.7703864574432373},{"id":"https:\/\/openalex.org\/keywords\/computer-science","display_name":"Computer science","score":0.7520237565040588},{"id":"https:\/\/openalex.org\/keywords\/android","display_name":"Android (operating system)","score":0.7102167010307312},{"id":"https:\/\/openalex.org\/keywords\/android-malware","display_name":"Android malware","score":0.7057901620864868},{"id":"https:\/\/openalex.org\/keywords\/shot","display_name":"Shot (pellet)","score":0.5802990794181824},{"id":"https:\/\/openalex.org\/keywords\/single-shot","display_name":"Single shot","score":0.448210209608078},{"id":"https:\/\/openalex.org\/keywords\/android-application","display_name":"Android application","score":0.41758596897125244},{"id":"https:\/\/openalex.org\/keywords\/artificial-intelligence","display_name":"Artificial intelligence","score":0.397804319858551},{"id":"https:\/\/openalex.org\/keywords\/computer-security","display_name":"Computer security","score":0.3552618622779846},{"id":"https:\/\/openalex.org\/keywords\/computer-vision","display_name":"Computer vision","score":0.34530919790267944},{"id":"https:\/\/openalex.org\/keywords\/embedded-system","display_name":"Embedded system","score":0.33693546056747437},{"id":"https:\/\/openalex.org\/keywords\/operating-system","display_name":"Operating system","score":0.25434941053390503},{"id":"https:\/\/openalex.org\/keywords\/physics","display_name":"Physics","score":0.05806317925453186}],"concepts":[{"id":"https:\/\/openalex.org\/C541664917","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q14001","display_name":"Malware","level":2,"score":0.7703864574432373},{"id":"https:\/\/openalex.org\/C41008148","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q21198","display_name":"Computer science","level":0,"score":0.7520237565040588},{"id":"https:\/\/openalex.org\/C557433098","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q94","display_name":"Android (operating system)","level":2,"score":0.7102167010307312},{"id":"https:\/\/openalex.org\/C2989133298","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q94","display_name":"Android malware","level":3,"score":0.7057901620864868},{"id":"https:\/\/openalex.org\/C2778344882","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q278938","display_name":"Shot (pellet)","level":2,"score":0.5802990794181824},{"id":"https:\/\/openalex.org\/C3019835501","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q1310130","display_name":"Single shot","level":2,"score":0.448210209608078},{"id":"https:\/\/openalex.org\/C3017891749","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q94","display_name":"Android application","level":3,"score":0.41758596897125244},{"id":"https:\/\/openalex.org\/C154945302","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q11660","display_name":"Artificial intelligence","level":1,"score":0.397804319858551},{"id":"https:\/\/openalex.org\/C38652104","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q3510521","display_name":"Computer security","level":1,"score":0.3552618622779846},{"id":"https:\/\/openalex.org\/C31972630","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q844240","display_name":"Computer vision","level":1,"score":0.34530919790267944},{"id":"https:\/\/openalex.org\/C149635348","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q193040","display_name":"Embedded system","level":1,"score":0.33693546056747437},{"id":"https:\/\/openalex.org\/C111919701","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q9135","display_name":"Operating system","level":1,"score":0.25434941053390503},{"id":"https:\/\/openalex.org\/C121332964","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q413","display_name":"Physics","level":0,"score":0.05806317925453186},{"id":"https:\/\/openalex.org\/C120665830","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q14620","display_name":"Optics","level":1,"score":0},{"id":"https:\/\/openalex.org\/C178790620","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q11351","display_name":"Organic chemistry","level":1,"score":0},{"id":"https:\/\/openalex.org\/C185592680","wikidata":"https:\/\/www.wikidata.org\/wiki\/Q2329","display_name":"Chemistry","level":0,"score":0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109\/spw67851.2025.00042","is_oa":false,"landing_page_url":"https:\/\/doi.org\/10.1109\/spw67851.2025.00042","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE Security and Privacy Workshops (SPW)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https:\/\/openalex.org\/G1176171528","display_name":null,"funder_award_id":"F2024202076","funder_id":"https:\/\/openalex.org\/F4320322163","funder_display_name":"Natural Science Foundation of Hebei Province"},{"id":"https:\/\/openalex.org\/G2391775443","display_name":null,"funder_award_id":"62302148,62172297,62172372","funder_id":"https:\/\/openalex.org\/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https:\/\/openalex.org\/G7960374069","display_name":null,"funder_award_id":"2023YFB2703800","funder_id":"https:\/\/openalex.org\/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https:\/\/openalex.org\/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https:\/\/ror.org\/01h0zpd94"},{"id":"https:\/\/openalex.org\/F4320322163","display_name":"Natural Science Foundation of Hebei Province","ror":"https:\/\/ror.org\/01h0zpd94"},{"id":"https:\/\/openalex.org\/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":48,"referenced_works":["https:\/\/openalex.org\/W2551095084","https:\/\/openalex.org\/W2986232939","https:\/\/openalex.org\/W3023529621","https:\/\/openalex.org\/W3097730806","https:\/\/openalex.org\/W3125596609","https:\/\/openalex.org\/W3136841188","https:\/\/openalex.org\/W3137832402","https:\/\/openalex.org\/W3185341429","https:\/\/openalex.org\/W3189050980","https:\/\/openalex.org\/W3193490676","https:\/\/openalex.org\/W4213449907","https:\/\/openalex.org\/W4293195547","https:\/\/openalex.org\/W4312869909","https:\/\/openalex.org\/W4316021890","https:\/\/openalex.org\/W4328101188","https:\/\/openalex.org\/W4366112300","https:\/\/openalex.org\/W4382239830","https:\/\/openalex.org\/W4385755457","https:\/\/openalex.org\/W4387686540","https:\/\/openalex.org\/W4390590798","https:\/\/openalex.org\/W4391146823","https:\/\/openalex.org\/W4391558404","https:\/\/openalex.org\/W4392739326","https:\/\/openalex.org\/W4392902482","https:\/\/openalex.org\/W4393157085","https:\/\/openalex.org\/W4393159311","https:\/\/openalex.org\/W4393927401","https:\/\/openalex.org\/W4394769542","https:\/\/openalex.org\/W4399701697","https:\/\/openalex.org\/W4402125726","https:\/\/openalex.org\/W4402261655","https:\/\/openalex.org\/W4402288687","https:\/\/openalex.org\/W4402457704","https:\/\/openalex.org\/W4402593282","https:\/\/openalex.org\/W4402727610","https:\/\/openalex.org\/W4402952445","https:\/\/openalex.org\/W4403628430","https:\/\/openalex.org\/W4403792060","https:\/\/openalex.org\/W4404781668","https:\/\/openalex.org\/W4411552851","https:\/\/openalex.org\/W6704698082","https:\/\/openalex.org\/W6773914095","https:\/\/openalex.org\/W6778140923","https:\/\/openalex.org\/W6783413571","https:\/\/openalex.org\/W6811013733","https:\/\/openalex.org\/W6861721698","https:\/\/openalex.org\/W6871553294","https:\/\/openalex.org\/W6873452974"],"related_works":["https:\/\/openalex.org\/W3142396426","https:\/\/openalex.org\/W2471333042","https:\/\/openalex.org\/W2560361988","https:\/\/openalex.org\/W2507113366","https:\/\/openalex.org\/W4396643691","https:\/\/openalex.org\/W3200508744","https:\/\/openalex.org\/W3025122950","https:\/\/openalex.org\/W4409177797","https:\/\/openalex.org\/W2311926078","https:\/\/openalex.org\/W4404739899"],"abstract_inverted_index":{"Data":[0],"noise":[1,151],"poses":[2],"a":[3,75,100,105,113],"fundamental":[4],"challenge":[5],"in":[6,83,135],"Android":[7],"malware":[8,29,80],"detection":[9,81,156],"that":[10,78,103],"significantly":[11],"degrades":[12],"the":[13,68,145,194],"performance":[14,174],"of":[15],"machine":[16,185],"learning":[17,37,186],"models.":[18],"Traditional":[19],"approaches":[20],"using":[21],"third-party":[22],"services":[23],"like":[24],"VirusTotal":[25],"introduce":[26],"inconsistencies":[27],"from":[28,59],"evolution":[30],"and":[31,51,86,127,150,167],"temporal":[32],"label":[33,123],"variations,":[34],"while":[35],"deep":[36],"methods":[38,187],"struggle":[39],"with":[40,112,175],"noisy":[41,60,85],"data":[42],"due":[43],"to":[44,54,130,153],"their":[45,52],"reliance":[46],"on":[47,162,193],"large":[48,132],"clean":[49],"datasets":[50],"tendency":[53],"memorize":[55],"rather":[56],"than":[57,190],"generalize":[58],"labels.":[61],"To":[62],"address":[63],"these":[64],"challenges,":[65],"we":[66],"propose":[67],"LLM-based":[69],"Few-shot":[70],"Multi-Label":[71],"Malware":[72],"Detection":[73],"(LeoDroid),":[74],"novel":[76],"framework":[77,161],"enhances":[79],"robustness":[82],"both":[84],"data-scarce":[87],"environments,":[88],"which":[89],"are":[90],"enabled":[91],"by":[92,188],"Large":[93],"Language":[94],"Models":[95],"(LLMs).":[96],"Our":[97],"approach":[98],"employs":[99],"two-stage":[101],"process":[102],"integrates":[104],"core-set":[106,125],"strategy":[107],"for":[108],"selecting":[109],"representative":[110],"samples":[111],"carefully":[114],"designed":[115],"prompt":[116,120],"engineering":[117],"methodology.":[118],"The":[119,169],"design":[121],"combines":[122],"descriptions,":[124],"examples,":[126],"chain-of-thought":[128],"reasoning":[129],"guide":[131],"language":[133],"models":[134],"multi-label":[136],"classification":[137],"tasks.":[138],"Through":[139],"this":[140],"integration,":[141],"LeoDroid":[142],"effectively":[143],"manages":[144],"balance":[146],"between":[147],"sample":[148],"size":[149],"tolerance":[152],"maintain":[154],"high":[155],"accuracy.":[157],"We":[158],"evaluate":[159],"our":[160],"three":[163,191],"real-world":[164],"datasets-anonymousCERT,":[165],"Drebin,":[166],"VirusShare.":[168],"experimental":[170],"results":[171],"demonstrate":[172],"exceptional":[173],"an":[176],"MS-ACC":[177],"above":[178],"0.93":[179],"across":[180],"all":[181],"datasets,":[182],"surpassing":[183],"traditional":[184],"more":[189],"times":[192],"anonymousCERT.":[195]},"counts_by_year":[{"year":2026,"cited_by_count":3}],"updated_date":"2026-04-23T09:07:50.710637","created_date":"2025-10-10T00:00:00"}