Labeled Multi-Stage Android APT Datasets

Published: 16 February 2026| Version 3 | DOI: 10.17632/bdtn9vj7d7.3
Contributors:
Amjed Alkadhimi, Thulfiqar Jabar, Manmeet Mahinderjit Singh

Description

This dataset contains Android device behavior data collected from a physical device to support the detection of multi-stage Advanced Persistent Threat (APT) attacks. It includes resource usage features (CPU, RAM, battery, RX, TX, traffic) and app-level features (permissions, sensors, services), covering multiple APT stages such as Initial Compromise, Credential Access / Privilege Escalation, and Exfiltration.

Files

Steps to reproduce

Users of the dataset are kindly requested to acknowledge the source by citing the following publication DEFEAT: Android Device Behavior-Based Datasets for Multi-Stage APT https://doi.org/10.1016/j.dib.2026.112539

Institutions

Categories

Cybersecurity, Mobile Platform, Cyber Attack, Android Malware

Funders

Licence