Android malware presents a persistent threat to users’ privacy and data integrity. To combat this, researchers have proposed machine learning-based (ML-based) Android malware detection (AMD) methods. However, adversarial Android malware attacks compromise the detection integrity of the ML-based AMD methods, raising significant concerns. Existing defenses against adversarial Android malware mainly focus on feature space attacks that generate adversarial feature vectors only, while defenses against realistic problem space attacks that generate real adversarial malware remain relatively underexplored. In this paper, we take a step toward this gap by proposing ADD, a practical adversarial Android malware defense framework designed as a plug-in to enhance the adversarial robustness of the ML-based AMD methods against problem space attacks. Our evaluation across multiple ML-based AMD methods shows that ADD performs well against the evaluated state-of-the-art problem space adversarial Android malware attacks. Additionally, ADD shows the defense effectiveness in enhancing the adversarial robustness of real-world antivirus solutions.
