{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T19:51:34Z","timestamp":1768420294042,"version":"3.49.0"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030808242","type":"print"},{"value":"9783030808259","type":"electronic"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-80825-9_16","type":"book-chapter","created":{"date-parts":[[2021,7,8]],"date-time":"2021-07-08T23:38:40Z","timestamp":1625787520000},"page":"319-340","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["PetaDroid: Adaptive Android Malware Detection Using Deep Learning"],"prefix":"10.1007","author":[{"given":"ElMouatez Billah","family":"Karbab","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,7,9]]},"reference":[{"key":"16_CR1","unstructured":"Cyber attacks on Android devices on the rise (2018). https:\/\/www.gdatasoftware.com\/blog\/2018\/11\/31255-cyber-attacks-on-android-devices-on-the-rise"},{"key":"16_CR2","unstructured":"Mobile OS market share (2019). http:\/\/gs.statcounter.com\/os-market-share\/mobile\/worldwide"},{"key":"16_CR3","series-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","doi-asserted-by":"publisher","first-page":"86","DOI":"10.1007\/978-3-319-04283-1_6","volume-title":"Security and Privacy in Communication Networks","author":"Y Aafer","year":"2013","unstructured":"Aafer, Y., Du, W., Yin, H.: DroidAPIMiner: mining API-level features for robust malware detection in Android. In: Zia, T., Zomaya, A., Varadharajan, V., Mao, M. (eds.) SecureComm 2013. LNICST, vol. 127, pp. 86\u2013103. Springer, Cham (2013). https:\/\/doi.org\/10.1007\/978-3-319-04283-1_6"},{"key":"16_CR4","doi-asserted-by":"crossref","unstructured":"Allix, K., Bissyand\u00e9, T.F., Klein, J., Le Traon, Y.: AndroZoo: collecting millions of android apps for the research community. In: Proceedings of the 13th International Conference on Mining Software Repositories (2016)","DOI":"10.1145\/2901739.2903508"},{"key":"16_CR5","doi-asserted-by":"publisher","first-page":"1731","DOI":"10.1007\/s12652-020-02243-0","volume":"12","author":"A Amira","year":"2021","unstructured":"Amira, A., Derhab, A., Karbab, E.B., Nouali, O., Khan, F.A.: Tridroid: a triage and classification framework for fast detection of mobile threats in android markets. J. Ambient Intell. Humaniz. Comput. 12, 1731\u20131755 (2021)","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"16_CR6","doi-asserted-by":"crossref","unstructured":"Arp, D., Spreitzenbarth, M., Hubner, M., Gascon, H., et al.: DREBIN: effective and explainable detection of Android malware in your pocket. In: Symposium Network and Distributed System Security (2014)","DOI":"10.14722\/ndss.2014.23247"},{"key":"16_CR7","doi-asserted-by":"publisher","first-page":"107639","DOI":"10.1016\/j.comnet.2020.107639","volume":"184","author":"Y Bai","year":"2021","unstructured":"Bai, Y., Xing, Z., Ma, D., Li, X., Feng, Z.: Comparative analysis of feature representations and machine learning methods in android family classification. Comput. Netw. 184, 107639 (2021)","journal-title":"Comput. Netw."},{"key":"16_CR8","doi-asserted-by":"crossref","unstructured":"Canfora, G., Medvet, E.: Acquiring and analyzing app metrics for effective mobile malware detection. In: Proceedings of the 2016 ACM on International Workshop on Security and Privacy Analytics (2016)","DOI":"10.1145\/2875475.2875481"},{"key":"16_CR9","doi-asserted-by":"publisher","first-page":"987","DOI":"10.1109\/TIFS.2019.2932228","volume":"15","author":"X Chen","year":"2020","unstructured":"Chen, X., et al.: Android HIV: a study of repackaging malware for evading machine-learning detection. IEEE Trans. Inf. Forensics Secur. 15, 987\u20131001 (2020)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"16_CR10","doi-asserted-by":"crossref","unstructured":"Ding, S.H.H., Fung, B.C.M., Charland, P.: Asm2Vec: boosting static representation robustness for binary clone search against code obfuscation and compiler optimization. In: Security and Privacy (2019)","DOI":"10.1109\/SP.2019.00003"},{"key":"16_CR11","unstructured":"Ester, M., Kriegel, H., Sander, J., Xu, X.: A density-based algorithm for discovering clusters in large spatial databases with noise. AAAI Press (1996)"},{"key":"16_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3162625","volume":"26","author":"J Garcia","year":"2018","unstructured":"Garcia, J., Hammad, M., Malek, S.: Lightweight, obfuscation-resilient detection and family identification of Android malware. ACM Trans. Softw. Eng. Methodol. 26, 1\u201329 (2018)","journal-title":"ACM Trans. Softw. Eng. Methodol."},{"key":"16_CR13","volume-title":"Deep Learning","author":"I Goodfellow","year":"2016","unstructured":"Goodfellow, I., Bengio, Y., et al.: Deep Learning. MIT Press, Cambridge (2016)"},{"key":"16_CR14","unstructured":"Jordaney, R., et al.: Transcend: detecting concept drift in malware classification models. In: 26th USENIX Security Symposium, USENIX Security 2017, Vancouver, BC, Canada, August 16\u201318, 2017 (2017)"},{"key":"16_CR15","doi-asserted-by":"crossref","unstructured":"Karbab, E.B., Debbabi, M.: ToGather: automatic investigation of android malware cyber-infrastructures. In: Proceedings of the 13th International Conference on Availability, Reliability and Security, ARES (2018)","DOI":"10.1145\/3230833.3230870"},{"key":"16_CR16","doi-asserted-by":"publisher","first-page":"S77","DOI":"10.1016\/j.diin.2019.01.017","volume":"28","author":"EB Karbab","year":"2019","unstructured":"Karbab, E.B., Debbabi, M.: Maldy: portable, data-driven malware detection using natural language processing and machine learning techniques on behavioral analysis reports. Digit. Investig. 28, S77\u2013S87 (2019)","journal-title":"Digit. Investig."},{"key":"16_CR17","doi-asserted-by":"crossref","unstructured":"Karbab, E.B., Debbabi, M., Derhab, A., Mouheb, D.: Cypider: building community-based cyber-defense infrastructure for Android malware detection. In: ACM Computer Security Applications Conference (ACSAC) (2016)","DOI":"10.1145\/2991079.2991124"},{"key":"16_CR18","doi-asserted-by":"publisher","first-page":"S48","DOI":"10.1016\/j.diin.2018.01.007","volume":"24","author":"EB Karbab","year":"2018","unstructured":"Karbab, E.B., Debbabi, M., Derhab, A., Mouheb, D.: MalDozer: automatic framework for Android malware detection using deep learning. Digit. Investig. 24, S48\u2013S59 (2018)","journal-title":"Digit. Investig."},{"key":"16_CR19","doi-asserted-by":"publisher","first-page":"101965","DOI":"10.1016\/j.cose.2020.101965","volume":"97","author":"EB Karbab","year":"2020","unstructured":"Karbab, E.B., Debbabi, M., Derhab, A., Mouheb, D.: Scalable and robust unsupervised android malware fingerprinting using community-based network partitioning. Comput. Secur. 97, 101965 (2020)","journal-title":"Comput. Secur."},{"key":"16_CR20","doi-asserted-by":"publisher","first-page":"S33","DOI":"10.1016\/j.diin.2016.04.013","volume":"18","author":"EB Karbab","year":"2016","unstructured":"Karbab, E.B., Debbabi, M., Mouheb, D.: Fingerprinting Android packaging: generating DNAs for malware detection. Digit. Investig. 18, S33\u2013S45 (2016)","journal-title":"Digit. Investig."},{"key":"16_CR21","doi-asserted-by":"crossref","unstructured":"Karbab, E.M.B., Debbabi, M., Alrabaee, S., Mouheb, D.: DySign: dynamic fingerprinting for the automatic detection of Android malware. In: International Conference on Malicious and Unwanted Software (2016)","DOI":"10.1109\/MALWARE.2016.7888739"},{"key":"16_CR22","doi-asserted-by":"crossref","unstructured":"Kim, J., al. Structural information based malicious app similarity calculation and clustering. In: Proceedings of the 2015 Conference on Research in Adaptive and Convergent Systems (2015)","DOI":"10.1145\/2811411.2811545"},{"key":"16_CR23","doi-asserted-by":"crossref","unstructured":"Kim, Y.: Convolutional neural networks for sentence classification. CoRR (2014)","DOI":"10.3115\/v1\/D14-1181"},{"key":"16_CR24","unstructured":"Lakshminarayanan, B., Pritzel, A., Blundell, C.: Simple and scalable predictive uncertainty estimation using deep ensembles. In: Annual Conference on Neural Information Processing Systems (2017)"},{"key":"16_CR25","doi-asserted-by":"crossref","unstructured":"Lindorfer, M., Neugschwandtner, M., et al.: Andrubis-1,000,000 apps later: a view on current Android malware behaviors. In: Building Analysis Datasets and Gathering Experience Returns for Security (BADGERS). IEEE (2014)","DOI":"10.1109\/BADGERS.2014.7"},{"key":"16_CR26","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/j.cose.2015.02.007","volume":"51","author":"D Maiorca","year":"2015","unstructured":"Maiorca, D., Ariu, D., Corona, I., Aresu, M., Giacinto, G.: Stealth attacks: an extended insight into the obfuscation effects on Android malware. Comput. Secur. 51, 16\u201331 (2015)","journal-title":"Comput. Secur."},{"key":"16_CR27","doi-asserted-by":"crossref","unstructured":"Mariconti, E., Onwuzurike, L., Andriotis, P., De Cristofaro, E., Ross, G., Stringhini, G.: MaMaDroid: detecting Android malware by building Markov chains of behavioral models. In: NDSS (2017)","DOI":"10.14722\/ndss.2017.23353"},{"key":"16_CR28","doi-asserted-by":"crossref","unstructured":"Massarelli, L., Aniello, L., Ciccotelli, C., Querzoni, L., Ucci, D., Baldoni, R.: Android malware family classification based on resource consumption over time. In: 12th International Conference on Malicious and Unwanted Software, MALWARE 2017, Fajardo, PR, USA, October 11\u201314, 2017 (2017)","DOI":"10.1109\/MALWARE.2017.8323954"},{"key":"16_CR29","doi-asserted-by":"crossref","unstructured":"McLaughlin, N., et al.: Deep Android malware detection. In: CODASPY (2017)","DOI":"10.1145\/3029806.3029823"},{"key":"16_CR30","unstructured":"Mikolov, T., Sutskever, I., et al.: Distributed representations of words and phrases and their compositionality. In: NIPS Neural Information Processing Systems (2013)"},{"key":"16_CR31","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3313391","volume":"22","author":"L Onwuzurike","year":"2019","unstructured":"Onwuzurike, L., Mariconti, E., Andriotis, P., Cristofaro, E.D., Ross, G.J., Stringhini, G.: MaMaDroid: Detecting Android malware by building Markov chains of behavioral models (extended version). ACM Trans. Priv. Secur. 22, 1\u201334 (2019)","journal-title":"ACM Trans. Priv. Secur."},{"key":"16_CR32","unstructured":"Pendlebury, F., Pierazzi, F., Jordaney, R., Kinder, J., Cavallaro, L.: TESSERACT: eliminating experimental bias in malware classification across space and time. In: USENIX (2019)"},{"key":"16_CR33","doi-asserted-by":"crossref","unstructured":"Rastogi, V., Chen, Y., Jiang, X.: DroidChameleon: evaluating android anti-malware against transformation attacks. In: 8th ACM Symposium on Information, Computer and Communications Security, ASIA CCS 2013 (2013)","DOI":"10.1145\/2484313.2484355"},{"key":"16_CR34","unstructured":"Rosenberg, A., Hirschberg, J.: V-measure: a conditional entropy-based external cluster evaluation measure. In: EMNLP-CoNLL (2007)"},{"key":"16_CR35","unstructured":"Shi, Q., et al.: Hash kernels. In: International Conference on Artificial Intelligence and Statistics (AISTATS) (2009)"},{"key":"16_CR36","doi-asserted-by":"crossref","unstructured":"Suarez-Tangil, G., et al.: DroidSieve: fast and accurate classification of obfuscated Android malware. In: Proceedings of the 7th ACM Conference on Data and Application Security and Privacy (CODASPY 2017), pp. 309\u2013320 (2017)","DOI":"10.1145\/3029806.3029825"},{"key":"16_CR37","unstructured":"Tram\u00e8r, F., Kurakin, A., Papernot, N., Goodfellow, I.J., Boneh, D., McDaniel, P.D.: Ensemble adversarial training: attacks and defenses. In: 6th International Conference on Learning Representations, ICLR 2018 (2018)"},{"key":"16_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1007\/978-3-319-60876-1_12","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"F Wei","year":"2017","unstructured":"Wei, F., Li, Y., Roy, S., Ou, X., Zhou, W.: Deep ground truth analysis of current Android malware. In: Polychronakis, M., Meier, M. (eds.) DIMVA 2017. LNCS, vol. 10327, pp. 252\u2013276. Springer, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-60876-1_12"},{"key":"16_CR39","doi-asserted-by":"crossref","unstructured":"Wu, Y., Li, X., Zou, D., Yang, W., Zhang, X., Jin, H.: MalScan: fast market-wide mobile malware scanning by social-network centrality analysis. In: 34th IEEE\/ACM International Conference on Automated Software Engineering (2019)","DOI":"10.1109\/ASE.2019.00023"},{"key":"16_CR40","doi-asserted-by":"crossref","unstructured":"Xu, K., Li, Y., Deng, R., Chen, K., Xu, J.: DroidEvolver: self-evolving android malware detection system. In: IEEE European Symposium on Security and Privacy (2019)","DOI":"10.1109\/EuroSP.2019.00014"},{"key":"16_CR41","doi-asserted-by":"crossref","unstructured":"Yuan, Z., Lu, Y., Wang, Z., Xue, Y.: Droid-Sec: deep learning in android malware detection. In: ACM SIGCOMM Computer Communication Review (2014)","DOI":"10.1145\/2619239.2631434"},{"key":"16_CR42","unstructured":"Zhang, X., Zhao, J.J., LeCun, Y.: Character-level convolutional networks for text classification. In: Advances in Neural Information Processing Systems (2015)"},{"key":"16_CR43","doi-asserted-by":"publisher","first-page":"3401","DOI":"10.1109\/TIFS.2019.2947861","volume":"15","author":"Y Zhang","year":"2020","unstructured":"Zhang, Y., et al.: Familial clustering for weakly-labeled Android malware using hybrid representation learning. IEEE Trans. Inf. Forensics Secur. 15, 3401\u20133414 (2020)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"16_CR44","doi-asserted-by":"crossref","unstructured":"Zhou, Y., Jiang, X.: Dissecting Android malware: characterization and evolution. In: IEEE Symposium on Security and Privacy (SP) (2012)","DOI":"10.1109\/SP.2012.16"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-80825-9_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,3]],"date-time":"2023-01-03T12:09:27Z","timestamp":1672747767000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-80825-9_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030808242","9783030808259"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-80825-9_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"9 July 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 July 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 July 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva2021.campus.ciencias.ulisboa.pt\/cfp.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"HotCRP","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"65","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"18","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"1","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"28% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}