A Classification Framework and Research Progress on Adaptation Methods for Concept Drift in Malicious Code Detection Models
Abstract
1. Introduction
- To the best of our knowledge, this is the first survey paper to comprehensively investigate the emergence, evolution, and progression of concept drift;
- This review proposes a novel taxonomy that categorizes existing solutions for concept drift based on differences in their modeling paradigms and adaptation mechanisms;
- This review attempts to discuss the strengths and limitations of existing solutions, serving as a comprehensive reference for advanced techniques employed to counteract concept drift;
- We discuss open issues and challenges that remain to be addressed and suggest potential directions for future research.
2. Methods
2.1. Search Methodology
2.2. Key Words
2.3. Inclusion and Exclusion Criteria
2.4. Research Questions
3. Taxonomy of Concept Drift Adaptation
3.1. Related Works
3.2. Categorization of Studies
3.3. Detection Approaches Based on ML
3.4. Detection Approaches Based on DNNs
3.5. Detection Approaches Based on GNNs
3.6. Detection Approaches Based on CL
3.7. Detection Approaches Based on Meta-L
3.8. Other Approaches
4. Findings and Discussion
4.1. Responses to RQs
4.2. Findings and Discussion from the Review
| Category | Advantages | Limitations | Maturity | Interpretability | Anti-Drift Mechanism | Resource Overhead |
|---|---|---|---|---|---|---|
| ML | Low complexity | Existence of detection gap | High | Strong | Periodic retraining | Proportional to retraining frequency |
| DNN | Powerful representation capabilities; automatic feature extraction | High cost; black-box nature | High | Poor | Inherent robustness to concept drift | High |
| GNN | Structural invariance; models software dependencies well | Complex graph construction | High | Medium | Graph structure stability; domain adaptation | High |
| CL | Online incremental updates | Catastrophic forgetting/error accumulation | Medium | Medium | Online updates; anti-forgetting mechanisms | Medium |
| Meta-L | Fast adaptation; significant theoretical potential | Immature; high training difficulty | Low | Poor | Prior knowledge from meta-tasks | High |
| Method/Author | F1-Score | ACC | Avg. Detection Time per Sample (ms) | |
|---|---|---|---|---|
| ML | ASDroid | 95.7% | 95.8% | - |
| ECMT | 76% | 96% | - | |
| SCRR | 86.5% | 95.8% | - | |
| Li et al. | 99.4% | 99.7% | 140 | |
| DNN | GreedyBlock | 97.9% | 96% | 3337.9 |
| ACE | 87.1% | 87% | 675.89 | |
| MeMalDet | 99.7% | 99.7% | 11.1 | |
| CADE | 96% | 99.2% | 3200 | |
| GNN | APIVec2++ | 99.4% | 97.3% | 919.9 |
| HeteroNet | - | 97.3% | - | |
| Li et al. | 99.7% | 92% | - | |
| CL | MalFSCIL | - | 82.9% | 0.36 |
| TAMD-IL | >95% | - | 1.14 (Train) | |
| Chen et al. | 93.5% | 98.8% | - | |
| Meta-L | Zhu et al. | 97.9% | 99.2% | - |
| Meta-MAMC | 94% | - | 1113.28 |
5. Challenges and Future Directions
6. Conclusions
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Appendix A
| ID | Citation ID | Publication Year | Author(s) | Category |
|---|---|---|---|---|
| 1 | [18] | 2024 | Y. A. Abid et al. | ML |
| 2 | [48] | 2024 | V. Agate et al. | ML |
| 3 | [49] | 2024 | A. M. R. AlSobeh et al. | ML |
| 4 | [50] | 2025 | A. Augello et al. | ML |
| 5 | [51] | 2022 | F. Barbero et al. | ML |
| 6 | [52] | 2023 | D. Feng et al. | ML |
| 7 | [19] | 2022 | A. Guerra-Manzanares et al. | ML |
| 8 | [53] | 2022 | A. Guerra-Manzanares et al. | ML |
| 9 | [54] | 2024 | S. Gulmez et al. | ML |
| 10 | [15] | 2025 | Q. Hu et al. | ML |
| 11 | [55] | 2022 | M. J. Hussain et al. | ML |
| 12 | [56] | 2021 | R. Korine et al. | ML |
| 13 | [17] | 2023 | S. Li et al. | ML |
| 14 | [57] | 2023 | B. Molina-Coronado et al. | ML |
| 15 | [58] | 2025 | S. Park et al. | ML |
| 16 | [16] | 2024 | Y. Yang et al. | ML |
| 17 | [59] | 2024 | Q. Zhang et al. | ML |
| 18 | [22] | 2021 | L. Yang et al. | DNN |
| 19 | [60] | 2020 | S. Cui et al. | DNN |
| 20 | [61] | 2024 | B. G. Doan et al. | DNN |
| 21 | [62] | 2023 | D. K. A et al. | DNN |
| 22 | [63] | 2022 | H. Chi et al. | DNN |
| 23 | [64] | 2024 | L. Cui et al. | DNN |
| 24 | [21] | 2025 | Y. Huang et al. | DNN |
| 25 | [20] | 2024 | K. Lucas et al. | DNN |
| 26 | [23] | 2024 | P. Maniriho et al. | DNN |
| 27 | [65] | 2023 | H. Yang et al. | DNN |
| 28 | [25] | 2024 | L. Cui et al. | GNN |
| 29 | [7] | 2025 | A. S. Li et al. | GNN |
| 30 | [26] | 2023 | R. Song et al. | GNN |
| 31 | [66] | 2025 | B. Zou et al. | GNN |
| 32 | [4] | 2023 | Y. Chen et al. | CL |
| 33 | [29] | 2020 | A. Yan et al. | CL |
| 34 | [29] | 2020 | A. Yan et al. | CL |
| 35 | [67] | 2023 | M. Amin et al. | CL |
| 36 | [68] | 2021 | G. Andresini et al. | CL |
| 37 | [28] | 2025 | Y. Chai et al. | CL |
| 38 | [69] | 2021 | A. A. Darem et al. | CL |
| 39 | [70] | 2025 | X. Deng et al. | CL |
| 40 | [71] | 2024 | Z. Deng et al. | CL |
| 41 | [72] | 2022 | I. Finder et al. | CL |
| 42 | [73] | 2021 | Z. Kan et al. | CL |
| 43 | [74] | 2025 | D. Kejriwal et al. | CL |
| 44 | [75] | 2022 | Z. Liu et al. | CL |
| 45 | [76] | 2021 | U. Urooj et al. | CL |
| 46 | [77] | 2024 | J. Wang et al. | CL |
| 47 | [78] | 2022 | D. Zhao et al. | CL |
| 48 | [69] | 2021 | A. A. Darem et al. | CL |
| 49 | [30] | 2024 | Y. Li et al. | Meta-L |
| 50 | [31] | 2022 | J. Zhu et al. | Meta-L |
| 51 | [79] | 2025 | V. Lin et al. | Other |
| 52 | [80] | 2021 | W. Aoudi et al. | Other |
| 53 | [81] | 2025 | A. Augello et al. | Other |
| 54 | [82] | 2023 | T. Chow et al. | Other |
| 55 | [32] | 2023 | A. Coscia et al. | Other |
| 56 | [83] | 2022 | A. Duby et al. | Other |
| 57 | [84] | 2025 | A. Ponte et al. | Other |
| 58 | [85] | 2020 | A. Satoh et al. | Other |
| 59 | [33] | 2025 | P. Yan et al. | Other |
| 60 | [34] | 2023 | X. Zhang et al. | Other |
| 61 | [12] | 2024 | D. Adhikari et al. | Review |
| 62 | [86] | 2026 | D. Asimopoulos et al. | Review |
| 63 | [11] | 2026 | M. Brosolo et al. | Review |
| 64 | [87] | 2026 | J. Challa et al. | Review |
| 65 | [88] | 2025 | P. Dubey et al. | Review |
| 66 | [89] | 2025 | A. Guerra et al. | Review |
| 67 | [90] | 2026 | V. Kehl et al. | Review |
| 68 | [91] | 2021 | A. Razgallah et al. | Review |
| 79 | [92] | 2025 | N. Soleymani et al. | Review |
| 70 | [93] | 2025 | Y. Tian et al. | Review |
| 71 | [13] | 2026 | A. Wani et al. | Review |
| 72 | [94] | 2026 | J. Zhao et al. | Review |
References
- Liu, L.; Wang, B.-S.; Yu, B.; Zhong, Q.-X. Automatic malware classification and new malware detection using machine learning. Front. Inf. Technol. Electron. Eng. 2017, 18, 1336–1347. [Google Scholar] [CrossRef] [Scilit]
- Arroyabe, M.F.; Arranz, C.F.A.; De Arroyabe, I.F.; de Arroyabe, J.C.F. Revealing the realities of cybercrime in small and medium enterprises: Understanding fear and taxonomic perspectives. Comput. Secur. 2024, 141, 103826. [Google Scholar] [CrossRef] [Scilit]
- Smallman, J. A Survey on Malware Detection and Analysis. J. Sci. Technol. 2024, 5, 1–14. [Google Scholar] [CrossRef] [Scilit]
- Chen, Y.; Ding, Z.; Wagner, D. Continuous Learning for Android Malware Detection. In Proceedings of the 32nd USENIX Security Symposium, Anaheim, CA, USA, 9–11 August 2023; pp. 1127–1144. [Google Scholar]
- Gama, J.; Zliobaite, I.; Bifet, A.; Pechenizkiy, M.; Bouchachia, A. A survey on concept drift adaptation. ACM Comput. Surv. 2014, 46, 44. [Google Scholar] [CrossRef] [Scilit]
- Chen, Z.; Zhang, Z.; Kan, Z.; Yang, L.; Cortellazzi, J.; Pendlebury, F.; Pierazzi, F.; Cavallaro, L.; Wang, G. Is It Overkill? Analyzing Feature-Space Concept Drift in Malware Detectors. In Proceedings of the IEEE Workshop on Deep Learning Security and Privacy, San Francisco, CA, USA, 25–25 May 2023; pp. 21–28. [Google Scholar]
- Li, A.S.; Iyengar, A.; Kundu, A.; Bertino, E.; Iyengar, A. Revisiting Concept Drift in Windows Malware Detection: Adaptation to Real Drifted Malware with Minimal Samples. In Proceedings of the Proceedings 2025 Network and Distributed System Security Symposium, San Diego, CA, USA, 23–28 February 2025. [Google Scholar]
- Tsymbal, A. The Problem of Concept Drift: Definitions and Related Work; TCD-CS-2004-15; Trinity College Dublin, Department of Computer Science: Dublin, Ireland, 2004. [Google Scholar]
- Lu, J.; Liu, A.; Dong, F.; Gu, F.; Gama, J.; Zhang, G. Learning under Concept Drift: A Review. IEEE Trans. Knowl. Data Eng. 2018, 31, 2346–2363. [Google Scholar] [CrossRef] [Scilit]
- Bayram, F.A.; Ahmed, B.S.; Kassler, A. From Concept Drift to Model Degradation: An Overview on Performance-Aware Drift Detectors. Knowl.-Based Syst. 2022, 245, 108632. [Google Scholar] [CrossRef] [Scilit]
- Brosolo, M.; K. A, A.; Conti, M.; K. A, R.R.; K. P, M.S.; Nicolazzo, S.; Nocera, A.; P., V. Security through the eyes of AI: How visualization is shaping malware detection. Comput. Sci. Rev. 2026, 61, 100914. [Google Scholar] [CrossRef] [Scilit]
- Adhikari, D.; Jiang, W.; Zhan, J.; Rawat, D.B.; Bhattarai, A. Recent advances in anomaly detection in Internet of Things: Status, challenges, and perspectives. Comput. Sci. Rev. 2024, 54, 100665. [Google Scholar] [CrossRef] [Scilit]
- Wani, A.; Basha, N.K.; Mohammed, M.; Hussain, I.; Ananth, C.; Rai, H.M. AI-driven botnet detection in IoT networks: A comprehensive research review. Comput. Sci. Rev. 2026, 61, 100941. [Google Scholar] [CrossRef] [Scilit]
- Dener, M.; Ok, G.; Orman, A. Malware Detection Using Memory Analysis Data in Big Data Environment. Appl. Sci. 2022, 12, 8604. [Google Scholar] [CrossRef] [Scilit]
- Hu, Q.; Wang, W.; Song, H.; Guo, S.; Zhang, J.; Zhang, S. ASDroid: Resisting Evolving Android Malware with API Clusters Derived From Source Code. IEEE Trans. Inf. Forensics Secur. 2025, 20, 1822–1835. [Google Scholar] [CrossRef] [Scilit]
- Yang, Y.; Yuan, B.; Lou, J.; Qin, Z. SCRR: Stable Malware Detection under Unknown Deployment Environment Shift by Decoupled Spurious Correlations Filtering. IEEE Trans. Dependable Secur. Comput. 2024, 14, 1–12. [Google Scholar] [CrossRef] [Scilit]
- Li, S.; Li, Y.; Wu, X.; Otaibi, S.A.; Tian, Z. Imbalanced Malware Family Classification Using Multimodal Fusion and Weight Self-Learning. IEEE Trans. Intell. Transp. Syst. 2023, 24, 7642–7652. [Google Scholar] [CrossRef] [Scilit]
- Abid, Y.A.; Wu, J.; Farhan, M.; Ahmad, T. ECMT Framework for Internet of Things: An Integrative Approach Employing In-Memory Attribute Examination and Sophisticated Neural Network Architectures in Conjunction with Hybridized Machine Learning Methodologies. IEEE Internet Things J. 2024, 11, 5867–5886. [Google Scholar] [CrossRef] [Scilit]
- Guerra-Manzanares, A.; Luckner, M.; Bahsi, H. Android malware concept drift using system calls: Detection, characterization and challenges. Expert Syst. Appl. 2022, 206, 117200. [Google Scholar] [CrossRef] [Scilit]
- Lucas, K.; Lin, W.; Bauer, L.; Reiter, M.K.; Sharif, M. Training Robust ML-based Raw-Binary Malware Detectors in Hours, not Months. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, Salt Lake City, UT, USA, 14 October 2024; pp. 124–138. [Google Scholar]
- Huang, Y.; He, M.; Wang, X.; Zhang, J.; Guo, S. ACE: A Static Android Malware Detection Method Based on Supervised Contrastive Learning. IEEE Internet Things J. 2025, 12, 23550–23562. [Google Scholar] [CrossRef] [Scilit]
- Yang, L.; Guo, W.; Hao, Q.; Ciptadi, A.; Ahmadzadeh, A.; Xing, X.; Wang, G. CADE: Detecting and Explaining Concept Drift Samples for Security Applications. In Proceedings of the 30th USENIX Security Symposium, Vancouver, BC, Canada, 11–13 August 2021; pp. 2327–2344. [Google Scholar]
- Maniriho, P.; Mahmood, A.N.; Chowdhury, M.J.M. MeMalDet: A memory analysis-based malware detection framework using deep autoencoders and stacked ensemble under temporal evaluations. Comput. Secur. 2024, 142, 103864. [Google Scholar] [CrossRef] [Scilit]
- Shokouhinejad, H.; Higgins, G.; Razavi-Fara, R.; Mohammadian, H.; Ghorbani, A.A. On the Consistency of GNN Explanations for Malware Detection. arXiv 2025, arXiv:2504.16316v2. [Google Scholar] [CrossRef] [Scilit]
- Cui, L.; Yin, J.; Cui, J.; Ji, Y.; Liu, P.; Hao, Z.; Yun, X. API2Vec++: Boosting API Sequence Representation for Malware Detection and Classification. IEEE Trans. Softw. Eng. 2024, 50, 2142–2162. [Google Scholar] [CrossRef] [Scilit]
- Song, R.; Li, L.; Cui, L.; Liu, Q.; Gao, J. Binary Malware Detection via Heterogeneous Information Deep Ensemble Learning. In Proceedings of the 2023 IEEE 29th International Conference on Parallel and Distributed Systems (ICPADS), Danzhou, China, 17–21 December 2023; pp. 1147–1156. [Google Scholar]
- Rahman, M.S.; Wright, M.; Coull, S.E. On the Limitations of Continual Learning for Malware Classification. In Proceedings of the Conference on Lifelong Learning Agents, Montréal, QC, Canada, 22–24 August 2022. [Google Scholar]
- Chai, Y.; Chen, X.; Qiu, J.; Du, L.; Xiao, Y.; Feng, Q.; Ji, S.; Tian, Z. MalFSCIL: A Few-Shot Class-Incremental Learning Approach for Malware Detection. IEEE Trans. Inf. Forensics Secur. 2025, 20, 2999–3014. [Google Scholar] [CrossRef] [Scilit]
- Yan, A.; Chen, Z.; Spolaor, R.; Tan, S.; Zhao, C.; Peng, L.; Yang, B. Network-based Malware Detection with a Two-tier Architecture for Online Incremental Update. In Proceedings of the 2020 IEEE/ACM 28th International Symposium on Quality of Service, Hangzhou, China, 15–17 June 2020. [Google Scholar]
- Li, Y.; Yuan, D.; Zhang, T.; Cai, H.; Lo, D.; Gao, C.; Luo, X.; Jiang, H. Meta-Learning for Multi-Family Android Malware Classification. ACM Trans. Softw. Eng. Methodol. 2024, 33, 174. [Google Scholar] [CrossRef] [Scilit]
- Zhu, J.; Jang-Jaccard, J.; Singh, A.; Welch, I.; Al-Sahaf, H.; Camtepe, S. A few-shot meta-learning based siamese neural network using entropy features for ransomware classification. Comput. Secur. 2022, 117, 102691. [Google Scholar] [CrossRef] [Scilit]
- Coscia, A.; Dentamaro, V.; Galantucci, S.; Maci, A.; Pirlo, G. YAMME: A YAra-byte-signatures Metamorphic Mutation Engine. IEEE Trans. Inf. Forensics Secur. 2023, 18, 4530–4545. [Google Scholar] [CrossRef] [Scilit]
- Yan, P.; Tan, S.; Wang, M.; Huang, J. Prompt Engineering-Assisted Malware Dynamic Analysis Using GPT-4. IEEE Trans. Dependable Secur. Comput. 2025, 22, 7712–7728. [Google Scholar] [CrossRef] [Scilit]
- Zhang, X.; Zhang, M.; Zhang, Y.; Zhong, M.; Zhang, X.; Cao, Y.; Yang, M. Slowing Down the Aging of Learning-Based Malware Detectors With API Knowledge. IEEE Trans. Dependable Secur. Comput. 2023, 20, 902–916. [Google Scholar] [CrossRef] [Scilit]
- Varikuti, H.V.; Kumari, V. A Hybrid Malware Detection Framework with Drift Adaptation for Timestamped Data. J. Theor. Appl. Inf. Technol. 2024, 102, 4137–4144. [Google Scholar]
- Ali, E.; Batool, N.; Rizwan, M.; Sarwar, S. Assessing Concept Drift in Malware: A Comprehensive Review and Analysis. In Proceedings of the 2024 21st International Bhurban Conference on Applied Sciences and Technology (IBCAST), Murree, Pakistan, 20–23 August 2024; pp. 564–569. [Google Scholar]
- Roh, E.; Kaya, Y.; Kruegel, C.; Vigna, G.; Hong, S. MADCAT: Combating Malware Detection Under Concept Drift with Test-Time Adaptation. arXiv 2025, arXiv:2505.18734. [Google Scholar] [CrossRef] [Scilit]
- Alam, M.T.F.; Fieblinger, R.; Mahara, A.; Rastogi, N. Poster: MORPH: Towards Automated Concept Drift Adaptation for Malware Detection. In Proceedings of the Network and Distributed System Security (NDSS) Symposium 2024, San Diego, CA, USA, 26 February–1 March 2024. [Google Scholar]
- Bosansky, B.; Hospodkova, L.; Najman, M.; Rigaki, M.; Babayeva, E.; Lisy, V. Counteracting Concept Drift by Learning with Future Malware Predictions. arXiv 2024, arXiv:2404.09352. [Google Scholar] [CrossRef] [Scilit]
- Jiang, Y.; Li, G.; Li, S.; Guo, Y. BenchMFC: A benchmark dataset for trustworthy malware family classification under concept drift. Comput. Secur. 2024, 139, 103706. [Google Scholar] [CrossRef] [Scilit]
- Apruzzese, G.; Laskov, P.; Tastemirova, A. SoK: The Impact of Unlabelled Data in Cyberthreat Detection. In Proceedings of the 2022 IEEE 7th European Symposium on Security and Privacy, Genova, Italy, 6–10 June 2022. [Google Scholar]
- Miao, C.; Kou, L.; Zhang, J.; Dong, G. A Lightweight Malware Detection Model Based on Knowledge Distillation. Mathematics 2024, 12, 4009. [Google Scholar] [CrossRef] [Scilit]
- Yao, H.; Huang, L.-K.; Zhang, L.; Wei, Y.; Tian, L.; Zou, J.; Huang, J.; Li, Z. Improving Generalization in Meta-learning via Task Augmentation. In Proceedings of the 38th International Conference on Machine Learning, Virtual Event, 18–24 July 2021. [Google Scholar]
- Patel, A.; Tomar, D.S.; Pateriya, R.K.; Haripriya, R. FL-MalDrift: A federated learning framework for malware detection under local concept drift. Sci. Rep. 2025, 16, 1821. [Google Scholar] [CrossRef] [Scilit]
- Zhou, K.; Liu, Z.; Qiao, Y.; Xiang, T.; Loy, C.C. Domain Generalization: A Survey. arXiv 2021, arXiv:2103.02503. [Google Scholar] [CrossRef] [Scilit]
- Zheng, X.Y.; Yang, S.; Ngai, E.C.H.; Jana, S.; Cavallaro, L. TIF: Learning Temporal Invariance in Android Malware Detectors. arXiv 2025, arXiv:2502.05098. [Google Scholar]
- He, Y.L.; Lei, J.; Qin, Z.; Ren, K.; Chen, C. Combating Concept Drift with Explanatory Detection and Adaptation for Android Malware Classification. arXiv 2024, arXiv:2405.04095. [Google Scholar]
- Agate, V.; De Paola, A.; Drago, S.; Ferraro, P.; Re, G.L. Enhancing IoT Network Security with Concept Drift-Aware Unsupervised Threat Detection. In Proceedings of the 2024 IEEE Symposium on Computers and Communications (ISCC), Paris, France, 26–29 June 2024; pp. 1–6. [Google Scholar]
- AlSobeh, A.M.R.; Gaber, K.; Hammad, M.M.; Nuser, M.; Shatnawi, A. Android malware detection using time-aware machine learning approach. Clust. Comput. 2024, 27, 12627–12648. [Google Scholar] [CrossRef] [Scilit]
- Augello, A.; De Paola, A.; Lo Re, G. Hybrid Multilevel Detection of Mobile Devices Malware Under Concept Drift. J. Netw. Syst. Manag. 2025, 33, 36. [Google Scholar] [CrossRef] [Scilit]
- Barbero, F.; Pendlebury, F.; Pierazzi, F.; Cavallaro, L. Transcending TRANSCEND: Revisiting Malware Classification in the Presence of Concept Drift. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA, 26 May 2022; pp. 805–823. [Google Scholar]
- Feng, D.; Li, S.; Yang, Z.; Xiang, Y.; Zheng, J.; He, X. Research of Deep Learning and Adaptive Threshold-Based Signaling Storm Prediction and Top Cause Tracking. IEEE Access 2023, 11, 120603–120611. [Google Scholar] [CrossRef] [Scilit]
- Guerra-Manzanares, A.; Luckner, M.; Bahsi, H. Concept drift and cross-device behavior: Challenges and implications for effective android malware detection. Comput. Secur. 2022, 120, 102757. [Google Scholar] [CrossRef] [Scilit]
- Gulmez, S.; Kakisim, A.G.; Sogukpinar, I. Analysis of the Zero-Day Detection of Metamorphic Malware. In Proceedings of the 2024 9th International Conference on Computer Science and Engineering (UBMK), Antalya, Turkiye, 26–28 October 2024; pp. 1–6. [Google Scholar]
- Hussain, M.J.; Shaoor, A.; Baig, S.; Hussain, A.; Muqurrab, S.A. A hierarchical based ensemble classifier for behavioral malware detection using machine learning. In Proceedings of the 2022 19th International Bhurban Conference on Applied Sciences and Technology (IBCAST), Islamabad, Pakistan, 16–20 August 2022; pp. 702–706. [Google Scholar]
- Korine, R.; Hendler, D. DAEMON: Dataset/Platform-Agnostic Explainable Malware Classification Using Multi-Stage Feature Mining. IEEE Access 2021, 9, 78382–78399. [Google Scholar] [CrossRef] [Scilit]
- Molina-Coronado, B.; Mori, U.; Mendiburu, A.; Miguel-Alonso, J. Efficient concept drift handling for batch android malware detection models. Pervasive Mob. Comput. 2023, 96, 101849. [Google Scholar] [CrossRef] [Scilit]
- Park, S.; Lee, H.; Kim, D.; Jun Moon, H.; Cho, S.-J.; Hwang, Y.; Han, H.; Suh, K. Enhancing the Sustainability of Machine Learning-Based Malware Detection Techniques for Android Applications. IEEE Access 2025, 13, 98876–98887. [Google Scholar] [CrossRef] [Scilit]
- Zhang, Q.; Imran, A.; Bardhi, E.; Swamy, T.; Zhang, N.; Shahbaz, M.; Olukotun, K. Caravan: Practical Online Learning of In-Network ML Models with Labeling Agents. In Proceedings of the 3rd Workshop on Practical Adoption Challenges of ML for Systems, Austin, TX, USA, 4–6 November 2024; pp. 17–20. [Google Scholar]
- Cui, S.; Dong, C.; Shen, M.; Liu, Y.; Jiang, B.; Lu, Z. CBSeq: A Channel-level Behavior Sequence For Encrypted Malware Traffic Detection. IEEE Trans. Inf. Forensics Secur. 2023, 18, 5011–5025. [Google Scholar] [CrossRef] [Scilit]
- Doan, B.G.; Nguyen, D.Q.; Montague, P.; Abraham, T.; De Vel, O.; Camtepe, S.; Kanhere, S.S.; Abbasnejad, E.; Ranasinghe, D.C. Bayesian Learned Models Can Detect Adversarial Malware For Free. arXiv 2024. [Google Scholar] [CrossRef] [Scilit]
- A, D.K.; P, V.; Yerima, S.Y.; Bashar, A.; David, A.; T., A.; Antony, A.; Shavanas, A.K.; T., G.K. Obfuscated Malware Detection in IoT Android Applications Using Markov Images and CNN. IEEE Syst. J. 2023, 17, 2756–2766. [Google Scholar] [CrossRef] [Scilit]
- Chi, H.; Fei, Z.; Li, P.; Yang, B.; Wang, Z.; Gu, L. LISP-TBCNN: An AutoCAD Malware Detection Approach. In Proceedings of the 2022 7th IEEE International Conference on Data Science in Cyberspace (DSC), Guilin, China, 11–13 July 2022; pp. 353–359. [Google Scholar]
- Cui, L.; Zhu, Y.; Yin, J.; Hao, Z.; Wang, W.; Liu, P.; Yang, Z.; Yun, X. APIBeh: Learning Behavior Inclination of APIs for Malware Classification. In Proceedings of the 2024 IEEE 35th International Symposium on Software Reliability Engineering (ISSRE), Tsukuba, Japan, 28–31 October 2024; pp. 1–12. [Google Scholar]
- Yang, H.; Wang, Y.; Zhang, L.; Hu, Z.; Cheng, X.; Jiang, L. EAMDM: An Evolved Android Malware Detection Method Using API Clustering. In Proceedings of the 2023 IEEE 22nd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Exeter, UK, 1–3 November 2023; pp. 889–895. [Google Scholar]
- Zou, B.; Cao, C.; Wang, L.; Cheng, Y.; Dang, C.; Liu, Y.; Sun, J.; Cimato, S. Feature Graph Construction with Static Features for Malware Detection. IET Inf. Secur. 2025, 2025, 6687383. [Google Scholar] [CrossRef] [Scilit]
- Amin, M.; Al-Obeidat, F.; Tubaishat, A.; Shah, B.; Anwar, S.; Tanveer, T.A. Cyber security and beyond: Detecting malware and concept drift in AI-based sensor data streams using statistical techniques. Comput. Electr. Eng. 2023, 108, 108702. [Google Scholar] [CrossRef] [Scilit]
- Andresini, G.; Pendlebury, F.; Pierazzi, F.; Loglisci, C.; Appice, A.; Cavallaro, L. INSOMNIA: Towards Concept-Drift Robustness in Network Intrusion Detection. In Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, Virtual Event, 15 November 2021; pp. 111–122. [Google Scholar]
- Darem, A.A.; Ghaleb, F.A.; Al-Hashmi, A.A.; Abawajy, J.H.; Alanazi, S.M.; Al-Rezami, A.Y. An Adaptive Behavioral-Based Incremental Batch Learning Malware Variants Detection Model Using Concept Drift Detection and Sequential Deep Learning. IEEE Access 2021, 9, 97180–97196. [Google Scholar] [CrossRef] [Scilit]
- Deng, X.; Su, P.; Lin, D.; Zhu, M. Design and Research of Intelligent Analysis Model for Full Flow Monitoring Adapting to Complex Heterogeneous Networks in Power. In Proceedings of the 10th International Conference on Cyber Security and Information Engineering, Xining, China, 23–25 July 2025; pp. 211–219. [Google Scholar]
- Deng, Z.; Hubert, A.; Ben Yahia, S.; Bahsi, H. Active Learning-Based Mobile Malware Detection Utilizing Auto-Labeling and Data Drift Detection. In Proceedings of the 2024 IEEE International Conference on Cyber Security and Resilience (CSR), London, UK, 2–4 September 2024; pp. 146–151. [Google Scholar]
- Finder, I.; Sheetrit, E.; Nissim, N. A time-interval-based active learning framework for enhanced PE malware acquisition and detection. Comput. Secur. 2022, 121, 102838. [Google Scholar] [CrossRef] [Scilit]
- Kan, Z.; Pendlebury, F.; Pierazzi, F.; Cavallaro, L. Investigating Labelless Drift Adaptation for Malware Detection. In Proceedings of the 14th ACM Workshop on Artificial Intelligence and Security, Virtual Event, 15 November 2021; pp. 123–134. [Google Scholar]
- Kejriwal, D.; Chahar, A.; Garg, A.; Arora, A. Scalable Android Malware Detection via Incremental Learning and Chi-Square-based Feature Reduction. In Proceedings of the 2025 6th International Conference on Intelligent Communication Technologies and Virtual Mobile Networks (ICICV), Tirunelveli, India, 17–19 June 2025; pp. 929–934. [Google Scholar]
- Liu, Z.; Wang, R.; Peng, B.; Gan, Q. A convolutional neural network based Android malware detection method with dynamic fine-tuning. In Proceedings of the 2022 32nd International Telecommunication Networks and Applications Conference (ITNAC), Wellington, New Zealand, 30 November 2022–2 December 2022; pp. 300–305. [Google Scholar]
- Urooj, U.; Maarof, M.A.B.; Al-rimy, B.A.S. A proposed Adaptive Pre-Encryption Crypto-Ransomware Early Detection Model. In Proceedings of the 2021 3rd International Cyber Resilience Conference (CRC), Langkawi Island, Malaysia, 29–31 January 2021; pp. 1–6. [Google Scholar]
- Wang, J.; Li, P.; Weitkamp, E.; Satani, Y.; Omundsen, A. MalBuster: Scalable, Real-Time, and Concept Drift-Adaptive Malware Detection for Smart Environments. In Proceedings of the 2024 IEEE 21st Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA, 6–9 January 2024; pp. 352–355. [Google Scholar]
- Zhao, D.; Kou, L.; Zhang, J. Online Learning based Self-updating Incremental Malware Detection Model. In Proceedings of the 2022 9th International Conference on Dependable Systems and Their Applications (DSA), Wulumuqi, China, 4–5 August 2022; pp. 1004–1005. [Google Scholar]
- Lin, V.; Lee, I. Monitor and Recover: A Paradigm for Future Research on Distribution Shift in Learning-Enabled Cyber-Physical Systems; University of Pennsylvania: Philadelphia, PA, USA, 2025. [Google Scholar]
- Aoudi, W.; Almgren, M. A Framework for Determining Robust Context-Aware Attack-Detection Thresholds for Cyber-Physical Systems. In Proceedings of the 2021 Australasian Computer Science Week Multiconference, Virtual, 1–5 February 2021; pp. 1–6. [Google Scholar]
- Augello, A.; De Paola, A.; Lo Re, G. M2FD: Mobile malware federated detection under concept drift. Comput. Secur. 2025, 152, 104361. [Google Scholar] [CrossRef] [Scilit]
- Chow, T.; Kan, Z.; Linhardt, L.; Cavallaro, L.; Arp, D.; Pierazzi, F. Drift Forensics of Malware Classifiers. In Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security, Copenhagen, Denmark, 30 November 2023; pp. 197–207. [Google Scholar]
- Duby, A.; Taylor, T.; Bloom, G.; Zhuang, Y. Evaluating Feature Robustness for Windows Malware Family Classification. In Proceedings of the 2022 International Conference on Computer Communications and Networks (ICCCN), Honolulu, HI, USA, 25–28 July 2022; pp. 1–10. [Google Scholar]
- Ponte, A.; Demetrio, L.; Oneto, L.; Ogbu, I.T.; Biggio, B.; Roli, F. Demystifying the Role of Rule-Based Detection in AI Systems for Windows Malware Detection. In Proceedings of the 2025 IEEE European Symposium on Security and Privacy Workshops (EuroS & PW), Venice, Italy, 30 June–4 July 2025; pp. 9–15. [Google Scholar]
- Satoh, A.; Fukuda, Y.; Hayashi, T.; Kitagata, G. A Superficial Analysis Approach for Identifying Malicious Domain Names Generated by DGA Malware. IEEE Open J. Commun. Soc. 2020, 1, 1837–1849. [Google Scholar] [CrossRef] [Scilit]
- Asimopoulos, D.C.; Radoglou-Grammatikis, P.; Papadopoulos, G.T.; Sarigiannidis, P. Beyond vulnerabilities: A comprehensive survey of adversarial attacks across domains. Comput. Sci. Rev. 2026, 61, 100963. [Google Scholar] [CrossRef] [Scilit]
- Challa, J.S.; Aarti; Goyal, N.; Goyal, P. Time-sensitive data analytics: A survey of anytime techniques, applications and challenges. Comput. Sci. Rev. 2026, 59, 100850. [Google Scholar] [CrossRef] [Scilit]
- Dubey, P.; Kumar, M. Integrating Explainable AI with Federated Learning for Next-Generation IoT: A comprehensive review and prospective insights. Comput. Sci. Rev. 2025, 56, 100697. [Google Scholar] [CrossRef] [Scilit]
- Guerra-Manzanares, A.; Caprolu, M.; Di Pietro, R. A comprehensive review on machine learning-based VPN detection: Scenarios, methods, and open challenges. Comput. Sci. Rev. 2025, 58, 100781. [Google Scholar] [CrossRef] [Scilit]
- Kehl Matter, V.; Garcia Martins, M.; Barbosa, J.L.V. Context-aware security and machine learning for access control: A systematic mapping and taxonomies. Comput. Sci. Rev. 2026, 60, 100880. [Google Scholar] [CrossRef] [Scilit]
- Razgallah, A.; Khoury, R.; Hallé, S.; Khanmohammadi, K. A survey of malware detection in Android apps: Recommendations and perspectives for future research. Comput. Sci. Rev. 2021, 39, 100358. [Google Scholar] [CrossRef] [Scilit]
- Soleymani, N.; Moattar, M.H.; Sheibani, R. Dealing with high dimensional multi-view data: A comprehensive review of non-negative matrix factorization approaches in data mining and machine learning. Comput. Sci. Rev. 2025, 58, 100788. [Google Scholar] [CrossRef] [Scilit]
- Tian, Y.; Yu, Y.; Sun, J.; Wang, Y. From past to present: A survey of malicious URL detection techniques, datasets and code repositories. Comput. Sci. Rev. 2025, 58, 100810. [Google Scholar] [CrossRef] [Scilit]
- Zhao, J.; Chu, F.; Xie, L.; Che, Y.; Wu, Y.; Burke, A.F. A survey of transformer networks for time series forecasting. Comput. Sci. Rev. 2026, 60, 100883. [Google Scholar] [CrossRef] [Scilit]



| Database | Search Criteria | Results |
|---|---|---|
| ACM Digital Library | [[All: “malicious software”] OR [All: malware] OR [All: “malware detection”] OR [All: “threat detection”] OR [All: “intrusion detection”]] AND [[All: “concept drift”] OR [All: “concept shift”] OR [All: “data drift”] OR [All: “model aging”] OR [All: “distribution shift”] OR [All: “temporal evolution”] OR [All: “model staleness”]] AND NOT [[All: survey] OR [All: review]] AND [E-Publication Date: (01/01/2020 TO 12/31/2025)] | 8 |
| IEEE Xplore | (“malicious software” OR “malware detection”) AND (“concept drift” OR “concept shift”) NOT (survey OR review) | 66 |
| Web Of Science | (“malicious software” OR “malware detection”) AND (“concept drift” OR “concept shift”) NOT (survey OR review) | 35 |
| Elsevier (ScienceDirect) | (malware OR “malware detection” OR “malicious code”) AND (“concept drift” OR “concept shift”) AND (survey OR review) | 74 |
| Inclusion Criteria | Exclusion Criteria |
|---|---|
| Articles published after 2020 | No clear results |
| Studies focusing on malware detection | Unclear research methodology |
| Use of real malware samples or real + synthetic datasets as controls | Does not address detection model’s defense/adaptation to drift |
| Provision of at least one standard metric | Extremely small dataset without validation/control using real-world data |
| Clear explanation of training/testing time split | Retracted or with records of significant academic misconduct |
| Reference | Focus Area | Covers Concept Drift? | Covers Malware Detection? | Provides Adaptation Taxonomy? |
|---|---|---|---|---|
| [5] | General concept drift | Yes | No | Yes (general) |
| [9] | General concept drift | Yes | No | Yes (general) |
| [11] | Visualization-based malware detection | Yes | Yes | No (visualization-specific) |
| [12] | IoT anomaly detection | Yes | Yes (partial) | No |
| [13] | IoT botnet detection | Yes | Yes (botnet) | No |
| Our work | Concept drift adaptation in malware detection | Yes | Yes | Yes |
| Method/Author | Dataset | Temporal Performance Retention | Overhead | Key Limitations |
|---|---|---|---|---|
| ASDroid | AndroZoo, VirusShare | Outperforms baselines | Medium | Relies on API semantics; limited cross-platform generalization |
| SCRR | Drebin, AndroZoo | Stable under temporal and environmental shifts | Low | Difficulty in designing filtering rules |
| Li et al. [17] | CCF BDCI-21, Microsoft BIG-15 | Significantly improves rare families detection | High | High computational cost; feature extraction bottleneck |
| ECMT | MalMem2022 memory dump dataset | - | Low | Lack of temporal validation; substantial resource overhead |
| Method/Author | Dataset | Robustness | Interpretability | Overhead | Key Limitation |
|---|---|---|---|---|---|
| GreedyBlock | VTFeed | High against adversarial examples | Poor | High | Limited resistance to naturally evolving drift |
| ACE | AndroZoo | Superior on new samples without updates | Poor | Medium | Heavy reliance on known labels; requires retraining for entirely new families |
| CADE | Drebin | Excels at handling significant drift | Excellent | High | Weak against gradual, incremental drift |
| MeMalDet | IDS2018 | Stable high detection on obfuscated samples | Good | Low | Dependent on memory dumps; vulnerable to anti-forensic techniques |
| Method/Author | Dataset | Core Mechanism | Robustness | Overhead | Key Limitation |
|---|---|---|---|---|---|
| API2Vec++ | Self-constructed Windows PE dataset | Dynamic graph construction (TPG & TAPG); BERT-based path embedding | Strong cross-temporal | Medium | Relies on dynamic tracing; high computational complexity |
| HeteroNet | Self-constructed Windows PE dataset | Multi-source heterogeneous graph learning | Robust to future samples | Medium | Complex architecture; high inference cost |
| Li et al. [7] | Big-15, MB-24, MalwareDrift | Static CFGs; GIN with adversarial domain adaptation | Strong domain adaptation | High | Requires minimal labeled samples from target environment |
| Method/Author | Dataset | Core Mechanism | Robustness | Overhead | Key Limitation |
|---|---|---|---|---|---|
| MalFSCIL | BODMAS, NSFOCUS Real-World Malware | Memory replay; prototype Learning | High stability across multiple class-incremental tasks | Low | Complex architecture; performance limited by generative replay quality |
| TAMD-IL | Drebin, VirusShare, App market traffic | Model replacement; two-layer filtering | Moderate stability; enables seamless modular updates | Low | Lack of dedicated anti-forgetting mechanism |
| Chen et al. [4] | APIGraph, AndroZoo | Contrastive learning; active learning with Pseudo-loss | High stability in streaming scenarios with limited labeled data | Low | High training cost; pseudo-loss reliability unvalidated |
| Method/Author | Dataset | Core Mechanism | Meta-Task | Limitations |
|---|---|---|---|---|
| Zhu et al. [31] | Self-constructed | Few-shot Siamese network; entropy-based features; dual-center loss | Few-shot discrimination of ransomware families | Limited dataset size; unknown generalizability |
| Meta-MAMC | Drebin, AMD | Dual-sampling strategy | Few-/zero-shot classification for multi-family Android malware | Cross-platform generalization not validated |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Wang, Q.; Wang, L.; Zhao, W. A Classification Framework and Research Progress on Adaptation Methods for Concept Drift in Malicious Code Detection Models. Future Internet 2026, 18, 231. https://doi.org/10.3390/fi18050231
Wang Q, Wang L, Zhao W. A Classification Framework and Research Progress on Adaptation Methods for Concept Drift in Malicious Code Detection Models. Future Internet. 2026; 18(5):231. https://doi.org/10.3390/fi18050231
Chicago/Turabian StyleWang, Qi, Longjuan Wang, and Weiwei Zhao. 2026. "A Classification Framework and Research Progress on Adaptation Methods for Concept Drift in Malicious Code Detection Models" Future Internet 18, no. 5: 231. https://doi.org/10.3390/fi18050231
APA StyleWang, Q., Wang, L., & Zhao, W. (2026). A Classification Framework and Research Progress on Adaptation Methods for Concept Drift in Malicious Code Detection Models. Future Internet, 18(5), 231. https://doi.org/10.3390/fi18050231

