Next-generation Android protection

An Android security system built on four complementary detection layers and an AI Sphere of LLM-powered security tools, engineered to run entirely on your device.

The core

LAVAIQ Antivirus Engine

No single detection method holds up against modern Android malware. LAVAIQ runs four complementary layers, each contributing a different analytical perspective, so what one misses another catches.

Layer 01

Signature and hash comparison

Every Android app is signed by its developer, and SHA-256 or SHA-512 hashes can be computed from its contents. LAVAIQ compares those against a database of known malicious signatures. Near-perfect on known threats, useless against modified ones, which is exactly why it runs first, as a fast low-cost filter and never a solution on its own.

Layer 02

Permission anomaly detection

A contextual analysis of what an app asks for against what it claims to be. A flashlight app requesting SMS and call logs is a strong signal of intent with no signature involved. LAVAIQ keeps permission profiles for common app categories and scores deviations by severity and count.

Layer 03

Heuristic detection

Behavioural and structural features are matched against known malicious patterns by similarity rather than exact match, which catches unseen variants of known families. The rules were generated through AI analysis of malware, making this layer effective against obfuscated code whose surface has changed but whose structure has not.

Layer 04

Machine learning detection

The main research contribution. A neural network trained on curated benign and malicious applications, each reduced to a 100-dimensional feature vector and scored by a lightweight network of roughly 8,500 parameters into a continuous malice probability. Converted to TensorFlow Lite, it infers entirely on device.

Alongside the four

The Mesh

New signatures, malicious hashes, permission profiles and reputation data are pushed to every active installation, and each install acts as a node, so a threat seen anywhere informs everywhere. Real-time protection keeps this running in the background, triggering a full multi-layer analysis the moment a new app appears.

0Years of development
0Prototypes built
0Java detection classes
0Lines of detection code
0Model parameters
0Specialised databases

Capabilities

Beyond what a scannerwas ever built to catch

Modern attacks are not only malware. They are abused permissions, insecure settings, phishing, scam sites and zero-day vulnerabilities, and most antivirus software still answers all of it with a verdict and no explanation.

It catches what it has never seen before

The trained model infers malicious intent from statistical relationships rather than matching a list, so it generalises past its training set to variants that share the underlying characteristics of known malware. That is the whole reason the fourth layer exists.

Local-first by design

Inference runs on device through TensorFlow Lite. Nothing about your applications is transmitted for analysis, which removes the privacy cost and the latency at the same time.

Shared threat intelligence

The Mesh pushes new signatures and reputation data to every installation in real time. Detection improves as the user base grows.

Configuration, not just apps

Insecure settings and excessive permissions are a real attack surface, and no malicious app is needed to exploit one. LAVAIQ reads the configuration and tells you what to change.

Explained, not asserted

Any result can be questioned in plain language, so the engine stops being a black box and becomes something you can reason about.

Nothing happens without your say-so

AI functions are read-only by default. No impactful operation runs without explicit approval through a consent-gated interface, which keeps the agent structurally incapable of changing the device on its own.

The AI Sphere

Security thatanswers questions

The second architectural pillar, a set of LLM-powered functions, several of which have no equivalent in existing Android antivirus software.

Ask AI for explainable security

Contextual assistance embedded throughout the interface. Any detection result or flagged application can be explained in plain language, turning an automated verdict into an informed decision.

AI device remediation

Analyses the device's current configuration and returns jargon-free, specific recommendations such as disabling third-party installation sources, revoking unnecessary critical permissions and aligning settings with current best practice.

Multi-phase fake news detection

Submit a URL and a chain of LLM models evaluates factual reliability, identifies fabricated claims, and assesses whether the source shows the characteristics of scam infrastructure or coordinated misinformation.

LazuliQ, a custom fine-tuned model

An open-weight base adapted for the cybersecurity domain with LoRA across the attention and feed-forward layers, trained on a purpose-built dataset and quantised to GGUF so it runs efficiently on limited infrastructure.

Autonomous

LAVAIQ AI Agent

A fully agentic system for security researchers. It takes a natural-language question, decides which tools to invoke, and reasons across app inspection, device settings, Wi-Fi analysis and external reputation checks to reach an assessment a signature scanner could not. It can remediate too, but every impactful action is routed through a consent gate.

Interface

Sophisticated inside,simple on screen

Four years of security research, presented as something you can read at a glance.

01Findings explained in language that assumes no security background
02Analysis running quietly in the background, not only when you ask for it
03On-device inference, so battery and memory cost stay minimal
04A warning that says why, with a direct fix rather than a dead end
The LAVAIQ Android app showing a device security scan

Recognition

Judged, andjudged well

LAVAIQ has been recognised at regional and national level in Slovakia, and is heading to the European stage.

Selected to represent Slovakia at EUCYS 2026 in Kiel, Germany Festival of Science and Technology, National Round

LAVAIQ was selected from the National Round of the 28th Annual Festival of Science and Technology to represent Slovakia at the European Union Contest for Young Scientists, the EU's most prestigious competition for young researchers, bringing together roughly 40 countries. The project was recognised for its innovation in cybersecurity, AI application and mobile threat prevention.

Nov 2025 · AMAVET

Regional silverOct 2025

2nd place, Festival of Science and Technology, Bratislava Regional Round

Placed LAVAIQ among the top innovations from the Bratislava and Trnava regions at Slovakia's leading competition for young researchers.

AMAVET, Association for Youth, Science and Technology

National bronzeApr 2025

3rd place, Secondary School Professional Activity (SOČ), National Round

Recognised nationally for LAVAIQ's multi-layered protection, combining static app analysis, heuristic and anomaly detection, and AI-driven adaptive threat assessment.

State Institute of Professional Education (SIOV)

Regional goldMar 2025

1st place, Secondary School Professional Activity (SOČ), Regional Round

First place in the regional round, qualifying LAVAIQ for the national competition.

State Institute of Professional Education (SIOV)

Roadmap

Coming to Android

Through 2025

Research and development

Four years of work across more than 30 prototypes, with the last eighteen months a complete rebuild of the architecture, detection layers and AI integrations.

2026, now

Beta testing

Final refinements, model tuning and optimisation on real devices.

Next

Gradual release

Publication step by step, possibly beginning with individual functions as standalone tools. A lightweight open-source version is under consideration.

Built by one student

DominikWalser

AI & Technology Enthusiast

Startups & Innovation

LAVAIQ is an independent project, designed, researched and developed by a single student developer with a passion for AI, LLMs and cybersecurity. Open to collaboration, research partnerships and new opportunities.

Artificial IntelligenceLLMsMachine LearningMobile CybersecurityStartups & Innovation

LAVAIQ arrives onAndroid soon

The waitlist gets access before the public release.

Questions, research, collaboration

Every message gets a response.