Penerapan Model Ensemble Stacking untuk Deteksi Malware dengan Optimasi Hyperparameter pada Support Vector Machine, Random Forest, dan XGBoost

Penulis

  • Jonathan Fanosara Telaumbanua
  • Aji Gautama Putrada
  • Ryan Lingga Wicaksono

Abstrak

Peningkatan jumlah pengguna Android menjadikannya sasaran utama dalam penyebaran malware Android, sehingga dibutuhkan model deteksi malware yang akurat dan efisien. Penelitian ini bertujuan untuk membangun dan menganalisis model ensemble stacking yang menggunakan tiga algoritma pembelajaran mesin, yaitu Support Vector Machine (SVM), Random Forest, dan XGBoost, yang dioptimasi menggunakan hyperparameter tuning GridSearchCV. Ensemble stacking digunakan untuk meningkatkan performa deteksi dengan menggabungkan keunggulan masing-masing base learner agar menghasilkan model yang lebih kuat. Dataset yang digunakan adalah NaticusDataset, yaitu dataset malware Android berbasis fitur permissions yang diminta oleh aplikasi. Hasil pengujian menunjukkan bahwa model SVM menghasilkan accuracy sebesar 0.9651, precision 0.9585, recall 0.9714, dan F1-score 0.9649. Model Random Forest memperoleh accuracy 0.9700, precision 0.9756, recall 0.9643, dan F1-score 0.9699. Model XGBoost mencapai accuracy 0.9695, precision 0.9765, recall 0.9622, dan F1-score 0.9693. Model ensemble stacking memberikan peningkatan performa dengan accuracy 0.9702, precision 0.9769, recall 0.9633, dan F1-score 0.9700. Analisis fitur menggunakan feature importance dan SHAP menunjukkan kontribusi signifikan dari fitur permissions terhadap hasil deteksi malware.

Kata kunci— malware android, ensemble stacking, support vector machine, random forest, xgboost.

Referensi

N. Polatidis, S. Kapetanakis, M. Trovati, I. Korkontzelos, and Y. Manolopoulos, “FSSDroid: Feature subset selection for Android malware detection,” World Wide Web, vol. 27, no. 5, Sep. 2024, doi: 10.1007/s11280-024-01287-y.

F. Akbar, M. Hussain, R. Mumtaz, Q. Riaz, A. W. A. Wahab, and K. H. Jung, “Permissions-Based Detection of Android Malware Using Machine Learning,” Symmetry (Basel), vol. 14, no. 4, Apr. 2022, doi: 10.3390/sym14040718.

J. M. Arif, M. F. A. Razak, S. Awang, S. R. T. Mat, N. S. N. Ismail, and A. Firdaus, “A static analysis approach for Android permission-based malware detection systems,” PLoS One, vol. 16, no. 9 September, Sep. 2021, doi: 10.1371/journal.pone.0257968.

H. juan Zhu, Y. Li, L. min Wang, and V. S. Sheng, “A multi-model ensemble learning framework for imbalanced android malware detection,” Expert Syst Appl, vol. 234, Dec. 2023, doi: 10.1016/j.eswa.2023.120952.

J. Zhang, Z. Xu, Z. Xiong, and L. Cai, “Android malware detection based on feature fusion and the improved stacking ensemble model,” Journal of Computer Virology and Hacking Techniques, vol. 21, no. 1, Dec. 2025, doi: 10.1007/s11416-025-00546-4.

T. Li et al., “Malware detection model based on stacking ensemble technique,” Appl Soft Comput, vol. 180, Aug. 2025, doi: 10.1016/j.asoc.2025.113338.

A. Joshi and S. Kumar, “Stacking-based ensemble model for malware detection in android devices,” International Journal of Information Technology (Singapore), vol. 15, no. 6, pp. 2907–2915, Aug. 2023, doi: 10.1007/s41870-023-01392-7.

P. Sumalatha and G. S. Mahalakshmi, “MACHINE LEARNING BASED ENSEMBLE CLASSIFIER FOR ANDROID MALWARE DETECTION,” International Journal of Computer Networks and Communications, vol. 15, no. 4, pp. 111–122, Jul. 2023, doi: 10.5121/ijcnc.2023.15407.

X. Wang, L. Zhang, K. Zhao, X. Ding, and M. Yu, “MFDroid: A Stacking Ensemble Learning Framework for Android Malware Detection,” Sensors, vol. 22, no. 7, Apr. 2022, doi: 10.3390/s22072597.

A. M. R. AlSobeh, K. Gaber, M. M. Hammad, M. Nuser, and A. Shatnawi, “Android malware detection using time-aware machine learning approach,” Cluster Comput, vol. 27, no. 9, pp. 12627–12648, Dec. 2024, doi: 10.1007/s10586-024-04484-6.

M. Gaber, M. Ahmed, and H. Janicke, “Zero day malware detection with Alpha: Fast DBI with Transformer models for real world application,” Computers and Electrical Engineering, vol. 128, p. 110751, Dec. 2025, doi: 10.1016/j.compeleceng.2025.110751.

R. Y. Mawoh, J. B. A. Wacka, F. Tchakounte, C. Fachkha, and Kolyang, “An accurate approach to discriminate android colluded malware from single app malware using permissions intelligence,” Sci Rep, vol. 15, no. 1, Dec. 2025, doi: 10.1038/s41598-025-86568-w.

H. Fathi, O. Malkawi, A. Al Tawil, A. Shaban, D. Ibrahim, and M. A. Aladaileh, “Reinforcement learning-driven feature selection for enhanced classification in cybersecurity: Applications in IoT security and malware detection,” International Journal of Data and Network Science, vol. 9, no. 4, pp. 813–822, Sep. 2025, doi: 10.5267/j.ijdns.2025.8.003.

H. Bakır, “A new method for tuning the CNN pre-trained models as a feature extractor for malware detection,” Pattern Analysis and Applications, vol. 28, no. 1, Mar. 2025, doi: 10.1007/s10044-024-01381-x.

E. Baghirov, “A comprehensive investigation into robust malware detection with explainable AI,” Cyber Security and Applications, vol. 3, Dec. 2025, doi: 10.1016/j.csa.2024.100072.

Unduhan

Diterbitkan

2026-07-01

Terbitan

Bagian

Prodi S1 Informatika