Ilmu Komputer & AI editorial
Open AccessOA2026
Name2Pkg: Lightweight One-Class Android Malware Screening via Name-Package Correspondence Modeling
A character-level seq2seq anomaly detector that flags malicious Android apps using only app names and package names, achieving 0.982 ROC-AUC at 28.20 ms CPU latency.
Changyeop Sung; Yeonjae Kang; Jaeho Shin; Huy Kang Kimยท 2026ยท DOI 10.48550/arXiv.2609.24389
The core problem
Deep learning-based malware detection has become a staple of security-critical services, yet most detectors depend on internal features extracted from APK files or on runtime behavior. Extracting such features is computationally expensive, which constrains their deployment in large-scale, early-stage screening pipelines where millions of applications must be triaged quickly. The authors observe that malicious apps frequently exhibit weak correspondence between their user-facing app names and their package names, a discrepancy that offers a low-cost screening signal requiring no APK disassembly or dynamic instrumentation. Name2Pkg is presented as a lightweight one-class classification method that leverages only two strings: the app name and the package name. The central hypothesis is that benign developers tend to keep these identifiers semantically and lexically aligned, whereas malware authors often reuse, obfuscate, or mismatch them. By formulating malware screening as a sequence anomaly detection problem, the work aims to provide an efficient and effective pre-filtering signal for large-scale security systems, complementing heavier detectors rather than replacing them.
Innovation
The evaluation uses a dataset of 67,129 real-world applications. On held-out test data, Name2Pkg achieves an area under the receiver operating characteristic curve (ROC-AUC) of 0.982 and a malware recall of 0.885 at an achieved false-positive rate of 0.044. These figures indicate that the name-package correspondence signal alone is highly discriminative, despite relying on no internal APK features or runtime behavior. Operationally, the model maintains a 3.57 MiB checkpoint and a CPU inference latency of 28.20 ms per sample, confirming its suitability for large-scale, early-stage screening. The combination of high recall at a low false-positive rate is particularly relevant for pre-filtering, where the goal is to route a manageable subset of candidates to more expensive downstream analysis without overwhelming analysts with false alarms. The compact checkpoint and CPU-only inference further lower the barrier to integration into existing security infrastructure, avoiding GPU provisioning costs that often accompany deep learning detectors.
Deep learning-based malware detection has become a staple of security-critical services, yet most detectors depend on internal features extracted from APK files or on runtime behavior. Extracting such features is computationally expensive, which constrains their deployment in large-scale, early-stage screening pipelines where millions of applications must be triaged quickly. The authors observe that malicious apps frequently exhibit weak correspondence between their user-facing app names and their package names, a discrepancy that offers a low-cost screening signal requiring no APK disassembly or dynamic instrumentation. Name2Pkg is presented as a lightweight one-class classification method that leverages only two strings: the app name and the package name. The central hypothesis is that benign developers tend to keep these identifiers semantically and lexically aligned, whereas malware authors often reuse, obfuscate, or mismatch them. By formulating malware screening as a sequence anomaly detection problem, the work aims to provide an efficient and effective pre-filtering signal for large-scale security systems, complementing heavier detectors rather than replacing them.
Name2Pkg models the conditional likelihood of a package name given an app name using a character-level sequence-to-sequence (seq2seq) model. For an app name and package name , the model estimates and derives an anomaly score from the length-normalized negative log-likelihood:
Why it matters
The results position Name2Pkg as a complementary pre-filtering layer rather than a standalone replacement for comprehensive malware analysis. Its strength lies in exploiting a cheap, readily available signal: the semantic and lexical relationship between an app's display name and its package identifier. Because the model is trained only on benign data, it avoids the cost and staleness associated with maintaining labeled malware datasets, and it can generalize to previously unseen malware families as long as they exhibit anomalous name-package correspondence. The 0.044 false-positive rate implies that roughly one in twenty-three benign applications would be flagged, a trade-off that may be acceptable in a tiered pipeline but warrants calibration per deployment context. Limitations include reliance on the assumption that benign developers maintain consistent naming conventions, potential evasion by malware authors who deliberately align app and package names, and the absence of multilingual or cross-marketplace evaluation in the reported setup. Future work could combine Name2Pkg scores with lightweight static or metadata features, adapt thresholds per app category, and study adversarial naming strategies. Overall, the method offers an efficient and effective pre-filtering signal for large-scale security systems, with a favorable balance of accuracy, model size, and inference latency.
Who should read this
CS practitioners and researchers
Opening member contentโฆ