LLM-Orchestrated Multi-Agent Framework for Android Malware Detection from APK Analysis
Dosyalar
Tarih
Dergi Başlığı
Dergi ISSN
Cilt Başlığı
Yayıncı
Erişim Hakkı
Özet
In recent years, the rapid growth of Android applications has resulted in an increasing need for more sophisticated and adaptive detection methods. Although machine learning and deep learning techniques have proven their utility with respect to structured features, these approaches usually lack semantic reasoning abilities and are ineffective against increasingly complex threats. This paper presents a parallel multi-agent model for Android malware detection via APK inspection, which incorporates the use of Large Language Models (LLMs)-based orchestration. The proposed model coordinates the actions of three independent agents that will be involved in the semantic reasoning of various components included in raw APK files, such as manifest permissions, structure of files, and behavior indicators. In contrast with a single-model framework, the suggested approach uses cooperative reasoning between different LLMs, namely Gemini 2.5 Flash, DeepSeek V3, and GPT-4.1-mini, and makes its ultimate decision on whether the analyzed application is malicious based on a majority vote. The multi-agent LLM layer proved its semantic reasoning capabilities during qualitative case analysis.










