RESEARCH
Robust Graph-Based Android Malware Classification Under Distribution Shift
San José State · Spring 2026
robustness gap 36.2 → 31.0
How far does a graph neural network's accuracy fall when Android malware stops looking like its training data, and does telling the model which features are missing close that gap? Training with simulated missing features cut the robustness gap from 36.2 to 31.0 points. The gating model I proposed did not beat that, most likely because the extra features were synthetic.

