Home / Journals / CMC / Online First / doi:10.32604/cmc.2026.083615
Special Issues
Table of Content

Open Access

ARTICLE

McIFAR: A Multi-Contextual Interaction-Based Framework for Detecting Context-Triggered Android Ransomware

Sonam Jain1, Tanya Gera2,*, Rupali Gill1, Afnan Almegren3, Ateeq Ur Rehman4,*, Salil Bharany1
1 Chitkara University Institute of Engineering and Technology, Chitkara University, Punjab, India
2 School of Computer Science and Engineering, Lovely Professional University, Phagwara, Punjab, India
3 Department of Applied Linguistics, College of Languages, Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia
4 School of Computing, Gachon University, Seongnam-si, Republic of Korea
* Corresponding Author: Tanya Gera. Email: email; Ateeq Ur Rehman. Email: email

Computers, Materials & Continua https://doi.org/10.32604/cmc.2026.083615

Received 07 April 2026; Accepted 09 June 2026; Published online 08 July 2026

Abstract

Android ransomware has emerged as a major threat to mobile ecosystems. Modern Android ransomware has evolved beyond the reach of traditional signature-based detection, often lying dormant until specific strategic triggers activate its malicious payload. These strategic ransomware variants activate payloads only under specific device states, events, and conditions that are absent in a sandbox testing environment. To address these sophisticated evasion tactics, this article introduces a novel framework, McIFAR (Multi-contextual Interaction-based Detection Framework for Android Ransomware), that leverages in-context emulation within malware sandboxing to elicit dormant behaviours that are missed by conventional testing, thereby transcending the limitations of isolated static or dynamic analysis. A robust two-stage methodology is presented. In the first stage, the Cross-Validation Feature Selection Ensemble (CVFSE) identifies dominant indicators. This is followed by the Contextual Interaction Feature Orchestrator (CIFO), processing dominant features to encode complex behavioral interactions between features and context in the second stage. Unlike existing studies that rely solely on static and dynamic data, this approach prioritizes contextual interaction, thereby significantly enhancing detection accuracy. The experimental results on the KronoDroid dataset demonstrate that McIFAR achieves a 99.48% detection accuracy, outperforming traditional baselines. The statistical analysis using the Friedman and Nemenyi post-hoc tests confirms that the results are both significant and consistent. The future work includes enhancing the framework by incorporating richer contextual scenarios in in-context emulation, along with federated learning and real-time lightweight deployment.

Keywords

Android ransomware; context; detection; feature; interaction; ransomware; machine learning
  • 121

    View

  • 31

    Download

  • 0

    Like

Share Link