Android malware detection collapses when the context stage comes out Six Android malware detectors in wide research use, including Drebin, MalScan, MaskDroid, and the LLM-based LAMD, flagged more than half the benign apps in a test set assembled from 49 Google Play categories, according to a new study. The detectors collapsed when apps requested permissions typical of legitimate tools, such as storage, contacts, SMS, and call logs, producing false positive rates that render them unreliable for real-world deployment. A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide research use, including Drebin, MalScan, and MaskDroid, produced that result on more than half the apps in a benign test set assembled from 49 Google Play categories. The worst performer, an LLM-based detector called LAMD, flagged … More https://www.helpnetsecurity.com/2026/07/29/android-malware-detection-research/ The post Android malware detection collapses when the context stage comes out https://www.helpnetsecurity.com/2026/07/29/android-malware-detection-research/ appeared first on Help Net Security https://www.helpnetsecurity.com .