International Journal of Advanced Technology and Engineering Exploration ISSN (Print): 2394-5443    ISSN (Online): 2394-7454 Volume-13 Issue-141 August-2026
  1. 4923
    Citations
  2. 2.8
    CiteScore
Adaptive malware detection under concept drift: an evolutionary deep learning framework with GA-based retraining

Zahraa Salim Dawood1 and Amel H. Abbas2

Quality Assurance and University Performance Department,University of Baghdad, Baghdad,Iraq1
Department of Computer Science, College of Science,Al-Mustansiriyah University, Baghdad,Iraq2
Corresponding Author : Zahraa Salim Dawood

Received : 14-January-2026; Revised : 25-August-2026; Accepted : 26-August-2026

Abstract

The continuous evolution of malware can lead to performance degradation in static detection models; a phenomenon commonly associated with concept drift. This study presents an adaptive retraining approach that addresses concept drift while improving the performance of deep learning-based malware classifiers. The proposed methodology employs a convolutional neural network (CNN), selected for its ability to identify localized malicious patterns within application programming interface (API) call sequences. A key contribution of this work is the integration of a genetic algorithm (GA) into the proposed framework to generate new feature patterns for adaptive retraining. These GA-generated patterns enhance the CNN's ability to adapt to distributional shifts by providing an enriched feature set for model retraining. The experimental results demonstrate the effectiveness of the proposed approach. The static CNN initially achieved an accuracy of 98%; however, its performance declined by 12 percentage points, from 98% to 86%, when evaluated on a newly collected dataset, indicating the effect of concept drift. The proposed adaptive framework mitigated this performance degradation by incorporating GA-generated feature patterns during retraining, improving the accuracy to 97.7% on the same dataset. These findings demonstrate the potential of the proposed framework to provide robust and adaptive malware detection under evolving data distributions.

Keywords

Concept drift, Malware detection, Adaptive retraining, Convolutional neural network, Genetic algorithm, API call sequences.

Cite this article

Dawood ZS, Abbas AH. Adaptive malware detection under concept drift: an evolutionary deep learning framework with GA-based retraining. International Journal of Advanced Technology and Engineering Exploration. 2026;13(141):408-427. DOI : 10.19101/IJATEE.2026.131340003

References
[1]
Alshoulie M, Mehmood A. Deep learning approaches for malware detection: a comprehensive review of techniques, challenges, and future directions. IEEE Access. 2025; 13:118652-77.
[2]
Zmaimita H, Madani A, Zine-dine K. The application of machine learning and deep learning in cybersecurity:“malware detection and classification”. In international conference on intelligent systems and digital applications 2025 (pp. 95-103). Cham: Springer Nature Switzerland.
[3]
Zhang S, Gao M, Wang L, Xu S, Shao W, Kuang R. A malware-detection method using deep learning to fully extract API sequence features. Electronics. 2025; 41(2):1-24.
[4]
He Y, Lei J, Qin Z, Ren K, Chen C. Combating concept drift with explanatory detection and adaptation for android malware classification. In proceedings of the ACM SIGSAC conference on computer and communications security 2025 (pp. 978-92). ACM.
[5]
Augello A, De PA, Lo RG. Hybrid multilevel detection of mobile devices malware under concept drift. Journal of Network and Systems Management. 2025; 33(2):1-32.
[6]
Musa HO, Younis MT. Effective android malware detection using CNN and LSTM model with GWO-based feature selection. Babylonian Journal of Machine Learning. 2026; 2026:1-22.
[7]
Sabbah A, Jarrar R, Zein S, Mohaisen D. Understanding concept drift with deprecated permissions in Android malware detection. IEEE Transactions on Dependable and Secure Computing. 2026; 23(4):8292-306.
[8]
Bakır H, Bakır R, Alkhaldi T, Darem AA, Alhashmi AA, Alqhatani A. ViTGuard: a synergistic approach to malware detection using vision transformers and genetic algorithms optimization. Pattern Analysis and Applications. 2025; 28(4):1-20.
[9]
El-hajj M. Beyond the generalization illusion: a production mlops framework for federated behavioral malware detection with real-time drift adaptation. In 9th cyber security in networking conference (CSNet) 2025 (pp. 215-21). IEEE.
[10]
Roh E, Kaya Y, Kruegel C, Vigna G, Hong S. Madcat: combating malware detection under concept drift with test-time adaptation. In proceedings of the 42nd international conference on machine learning 2025 (pp. 500-15).
[11]
Alam MT, Piplai A, Rastogi N. ADAPT: a pseudo-labeling approach to combat concept drift in malware detection. In 28th international symposium on research in attacks, intrusions and defenses (RAID) 2025 (pp. 693-712). IEEE.
[12]
Mcfadden S, Foley M, D'onghia M, Hicks C, Mavroudis V, Paoletti N, et al. DRMD: deep reinforcement learning for malware detection under concept drift. In proceedings of the AAAI conference on artificial intelligence 2026 (pp. 854-62). AAAI.
[13]
Mahdi MS. A deep learning–based hybrid neural network model for malware detection. Journal of Techniques. 2026; 8(1):62-70.
[14]
Fernando DW. Fesad: ransomware detection with machine learning using adaption to concept drift. Doctoral Dissertation, Department of Computer Science, University of London. 2023.
[15]
Kamdan, Pratama Y, Munzi RS, Mustafa AB, Kharisma IL. Static malware detection and classification using machine learning: a random forest approach. Engineering Proceedings. 2025; 107(1):1-9.
[16]
Ali SF, Abdulrazzaq MR, Gaata MT. Learning techniques-based malware detection: a comprehensive review. Mesopotamian Journal of CyberSecurity. 2025; 5(1):273-300.
[17]
Hussain MD, Muzaffar A. Online learning-based android malware detection using API call graphs and drift detection: a comparative study. In proceedings of the AAAI symposium series 2025 (pp. 87-9). AAAI.
[18]
Yang J, He L, Cai X, Ran P, Wang N. AdvAttack: adversarial attack against machine learning-based android malware detection models. International Journal of Information Security. 2026; 25(4):1-17.
[19]
Tayyab UE, Khan FB, Durad MH, Khan A, Lee YS. A survey of the recent trends in deep learning based malware detection. Journal of Cybersecurity and Privacy. 2022; 2(4):800-29.
[20]
Chowdhury NU, Haque A, Soliman H, Hossen MS, Fatima T, Ahmed I. Android malware detection using machine learning: a review. In intelligent systems conference 2023 (pp. 507-22). Cham: Springer Nature Switzerland.
[21]
Hidayat S, Utami E, Setyanto A, Karim A. Advancements in machine learning and deep learning for malware detection challenges breakthroughs. In 4th international conference on creative communication and innovative technology (ICCIT) 2025 (pp. 1-6). IEEE.
[22]
Mishra A, Stamp M. Cluster analysis and concept drift detection in malware. Journal of Computer Virology and Hacking Techniques. 2025; 21(1):1-16.
[23]
Alsuwat E, Solaiman S, Alsuwat H. Concept drift analysis and malware attack detection system using secure adaptive windowing. Computers, Materials and Continua. 2023; 75(2):3743-59.
[24]
Wang Q, Wang L, Zhao W. A classification framework and research progress on adaptation methods for concept drift in malicious code detection models. Future Internet. 2026; 18(5):1-27.
[25]
Salman AM, Al-nuaimi BT, Subhi AA, Alkattan H. Enhancing cybersecurity with machine learning: a hybrid approach for anomaly detection and threat prediction. Mesopotamian Journal of CyberSecurity. 2025; 5(1):202-15.
[26]
Karat G, Kannimoola JM, Nair N, Vazhayil A, VG S, Poornachandran P. CNN-LSTM hybrid model for enhanced malware analysis and detection. Procedia Computer Science. 2024; 233:492-503.
[27]
Youssef N, Elbaraway N, Elmaghraby A. Transformer-based API call sequence modeling for dynamic malware detection. In southeastcon 2025 2025 (pp. 494-500). IEEE.
[28]
Alanzi SM, Alzahrani AJ. IoT malware detection using hybrid deep learning algorithms. International Journal of Computer Science & Network Security. 2024; 24(12):1-17.
[29]
Derweesh MS, Alazawi SA, Al-saleh AH. Enhanced network anomaly detection using hybrid deep learning network based on interactive threshold. Baghdad Science Journal. 2025; 22(12):4293-305.
[30]
Alkhafaji N, Viana T, Al-sherbaz A. Integrated genetic algorithm and deep learning approach for effective cyber-attack detection and classification in industrial internet of things (IIoT) environments. Arabian Journal for Science and Engineering. 2025; 50(15):12071-95.
[31]
Yang Z, Zhu H, Li Z, Wang G, Su M. A malware detection method based on genetic algorithm optimized CNN-SENet network. IEEE Access. 2024; 12:160052-63.
[32]
Qiu J, Nepal S, Luo W, Pan L, Tai Y, Zhang J, et al. Data-driven android malware intelligence: a survey. In international conference on machine learning for cyber security 2019 (pp. 183-202). Cham: Springer International Publishing.
[33]
Ahmed F, Hasan MK, Alvi ST. A comprehensive review of machine learning-based approaches for malware detection. In 5th international conference on emerging smart technologies and applications (eSmarTA) 2025 (pp. 1-8). IEEE.
[34]
Zhang B, Wang Z, Cai Z, He P, Liu C. Linear DOA estimation method based on NGO-SVM. In 23rd international conference on communication technology (ICCT) 2023 (pp. 144-9). IEEE.
[35]
Abid DE, Ghazli A, Bouache M. Multi-branch graph neural network for robust malware detection. The Journal of Supercomputing. 2025; 81(15):1-28.
[36]
Ismail R, Essameldin R, Darwish SM. GAPSI-genetic algorithm approach addressing feature drift using PSI. Social Network Analysis and Mining. 2025; 15(1):1-20.
[37]
Pierazzi F, Pendlebury F, Cortellazzi J, Cavallaro L. Intriguing properties of adversarial ml attacks in the problem space. In symposium on security and privacy (SP) 2020 (pp. 1332-49). IEEE.