Open Access iconOpen Access

ARTICLE

McIFAR: A Multi-Contextual Interaction-Based Framework for Detecting Context-Triggered Android Ransomware

Sonam Jain1, Tanya Gera2,*, Rupali Gill1, Afnan Almegren3, Ateeq Ur Rehman4,*, Salil Bharany1

1 Chitkara University Institute of Engineering and Technology, Chitkara University, Punjab, India
2 School of Computer Science and Engineering, Lovely Professional University, Phagwara, Punjab, India
3 Department of Applied Linguistics, College of Languages, Princess Nourah bint Abdulrahman University, Riyadh, Saudi Arabia
4 School of Computing, Gachon University, Seongnam-si, Republic of Korea

* Corresponding Authors: Tanya Gera. Email: email; Ateeq Ur Rehman. Email: email

Computers, Materials & Continua 2026, 89(1), 99 https://doi.org/10.32604/cmc.2026.083615

Abstract

Android ransomware has emerged as a major threat to mobile ecosystems. Modern Android ransomware has evolved beyond the reach of traditional signature-based detection, often lying dormant until specific strategic triggers activate its malicious payload. These strategic ransomware variants activate payloads only under specific device states, events, and conditions that are absent in a sandbox testing environment. To address these sophisticated evasion tactics, this article introduces a novel framework, McIFAR (Multi-contextual Interaction-based Detection Framework for Android Ransomware), that leverages in-context emulation within malware sandboxing to elicit dormant behaviours that are missed by conventional testing, thereby transcending the limitations of isolated static or dynamic analysis. A robust two-stage methodology is presented. In the first stage, the Cross-Validation Feature Selection Ensemble (CVFSE) identifies dominant indicators. This is followed by the Contextual Interaction Feature Orchestrator (CIFO), processing dominant features to encode complex behavioral interactions between features and context in the second stage. Unlike existing studies that rely solely on static and dynamic data, this approach prioritizes contextual interaction, thereby significantly enhancing detection accuracy. The experimental results on the KronoDroid dataset demonstrate that McIFAR achieves a 99.48% detection accuracy, outperforming traditional baselines. The statistical analysis using the Friedman and Nemenyi post-hoc tests confirms that the results are both significant and consistent. The future work includes enhancing the framework by incorporating richer contextual scenarios in in-context emulation, along with federated learning and real-time lightweight deployment.

Keywords

Android ransomware; context; detection; feature; interaction; ransomware; machine learning

Cite This Article

APA Style
Jain, S., Gera, T., Gill, R., Almegren, A., Rehman, A.U. et al. (2026). McIFAR: A Multi-Contextual Interaction-Based Framework for Detecting Context-Triggered Android Ransomware. Computers, Materials & Continua, 89(1), 99. https://doi.org/10.32604/cmc.2026.083615
Vancouver Style
Jain S, Gera T, Gill R, Almegren A, Rehman AU, Bharany S. McIFAR: A Multi-Contextual Interaction-Based Framework for Detecting Context-Triggered Android Ransomware. Comput Mater Contin. 2026;89(1):99. https://doi.org/10.32604/cmc.2026.083615
IEEE Style
S. Jain, T. Gera, R. Gill, A. Almegren, A. U. Rehman, and S. Bharany, “McIFAR: A Multi-Contextual Interaction-Based Framework for Detecting Context-Triggered Android Ransomware,” Comput. Mater. Contin., vol. 89, no. 1, pp. 99, 2026. https://doi.org/10.32604/cmc.2026.083615



cc Copyright © 2026 The Author(s). Published by Tech Science Press.
This work is licensed under a Creative Commons Attribution 4.0 International License , which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.
  • 239

    View

  • 68

    Download

  • 0

    Like

Share Link