{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T01:08:59Z","timestamp":1773709739452,"version":"3.50.1"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2020,3,17]],"date-time":"2020-03-17T00:00:00Z","timestamp":1584403200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,3,17]],"date-time":"2020-03-17T00:00:00Z","timestamp":1584403200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cluster Comput"],"published-print":{"date-parts":[[2020,12]]},"DOI":"10.1007\/s10586-020-03083-5","type":"journal-article","created":{"date-parts":[[2020,3,18]],"date-time":"2020-03-18T12:48:44Z","timestamp":1584535724000},"page":"3233-3253","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":31,"title":["Can machine learning model with static features be fooled: an adversarial machine learning approach"],"prefix":"10.1007","volume":"23","author":[{"given":"Rahim","family":"Taheri","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Reza","family":"Javidan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Shojafar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"P.","family":"Vinod","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mauro","family":"Conti","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,3,17]]},"reference":[{"key":"3083_CR1","doi-asserted-by":"crossref","unstructured":"Aafer, Y., Du, W., Yin, H.: Droidapiminer: mining API-level features for robust malware detection in Android. In: International Conference on Security and Privacy in Communication Systems, pp. 86\u2013103. Springer (2013)","DOI":"10.1007\/978-3-319-04283-1_6"},{"key":"3083_CR2","doi-asserted-by":"crossref","unstructured":"Arp, D., Spreitzenbarth, M., Gascon, H., Rieck, K., Siemens, C.: Drebin: effective and explainable detection of android malware in your pocket. In: Proceedings of NDSS (2014)","DOI":"10.14722\/ndss.2014.23247"},{"key":"3083_CR3","doi-asserted-by":"crossref","unstructured":"Barrera, D., Kayacik, H.G., van Oorschot, P.C., Somayaji, A.: A methodology for empirical analysis of permission-based security models and its application to Android. In: Proceedings of 17th ACM CCS, pp. 73\u201384 (2010)","DOI":"10.1145\/1866307.1866317"},{"key":"3083_CR4","doi-asserted-by":"crossref","unstructured":"Biggio, B., et al.: Evasion attacks against machine learning at test time. In: Joint European Conference on Machine Learning and Knowledge Discovery in Databases, pp. 387\u2013402. Springer (2013)","DOI":"10.1007\/978-3-642-40994-3_25"},{"key":"3083_CR5","unstructured":"Carlini, N., Wagner, D.: Audio adversarial examples: targeted attacks on speech-to-text. arXiv preprint (2018). arXiv:1801.01944"},{"key":"3083_CR6","unstructured":"Contagio dataset (2019). http:\/\/contagiominidump.blogspot.com\/. Accessed 25 May 2019"},{"key":"3083_CR7","unstructured":"Eykholt, K., et al.: Physical adversarial examples for object detectors. arXiv preprint (2018). arXiv:1807.07769"},{"key":"3083_CR8","doi-asserted-by":"crossref","unstructured":"Goebel, R., Chander, A., Holzinger, K., Lecue, F., Akata, Z., Stumpf, S., Kieseberg, P., Holzinger, A.: Explainable AI: the new 42? In: International Cross-Domain Conference for Machine Learning and Knowledge Extraction, pp. 295\u2013303. Springer (2018)","DOI":"10.1007\/978-3-319-99740-7_21"},{"key":"3083_CR9","unstructured":"Goodfellow, I., Pouget-Abadie, J., Mirza, M., Xu, B., Warde-Farley, D., Ozair, S., Courville, A., Bengio, Y.: Generative adversarial nets. In: Proceedings of NIPS, pp. 2672\u20132680 (2014)"},{"key":"3083_CR10","unstructured":"Goodfellow, I.J., et al.: Explaining and harnessing adversarial examples. arXiv preprint (2014). arXiv:1412.6572"},{"key":"3083_CR11","doi-asserted-by":"crossref","unstructured":"Grosse, K., et al.: Adversarial examples for malware detection. In: European Symposium on Research in Computer Security, pp. 62\u201379. Springer (2017)","DOI":"10.1007\/978-3-319-66399-9_4"},{"key":"3083_CR12","unstructured":"Grosse, K., et al.: On the (statistical) detection of adversarial examples. arXiv preprint (2017). arXiv:1702.06280"},{"key":"3083_CR13","unstructured":"Ho, T.K.: Random decision forests. In: Proceedings of the Third International Conference on Document Analysis and Recognition, 1995, vol 1, pp. 278\u2013282. IEEE (1995)"},{"key":"3083_CR14","doi-asserted-by":"crossref","unstructured":"Huang, L., Joseph, A.D., Nelson, B., Rubinstein, B.I., Tygar, J.: Adversarial machine learning. In: Proceedings of the 4th ACM Workshop on Security and Artificial Intelligence, pp. 43\u201358. ACM (2011)","DOI":"10.1145\/2046684.2046692"},{"key":"3083_CR15","unstructured":"Huang, Y., et al.: Malware evasion attack and defense. arXiv preprint (2019). arXiv:1904.05747"},{"key":"3083_CR16","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1016\/j.cose.2017.03.011","volume":"68","author":"F Idrees","year":"2017","unstructured":"Idrees, F., Rajarajan, M., Conti, M., Chen, T.M., Rahulamathavan, Y.: Pindroid: a novel Android malware detection system using ensemble learning methods. Comput. Secur. 68, 36\u201346 (2017)","journal-title":"Comput. Secur."},{"key":"3083_CR17","unstructured":"Jiang, X., Zhou, Y.: Dissecting android malware: characterization and evolution. In: Proceedings of IEEE S&P, pp. 95\u2013109 (2012)"},{"key":"3083_CR18","unstructured":"KNN complexity (2019). http:\/\/www.cs.haifa.ac.il\/~rita\/ml_course\/lectures\/KNN.pdf. Accessed 25 May 2019"},{"key":"3083_CR19","unstructured":"Kreuk, F., Adi, Y., Cisse, M., Keshet, J.: Fooling end-to-end speaker verification by adversarial examples. arXiv preprint (2018). arXiv:1801.03339"},{"key":"3083_CR20","unstructured":"Kurakin, A., Goodfellow, I., Bengio, S.: Adversarial examples in the physical world. arXiv preprint (2016). arXiv:1607.02533"},{"issue":"3","key":"3083_CR21","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1007\/s11721-016-0126-1","volume":"10","author":"W Li","year":"2016","unstructured":"Li, W., Gauci, M., Gro\u00df, R.: Turing learning: a metric-free approach to inferring behavior and its application to swarms. Swarm Intell. 10(3), 211\u2013243 (2016)","journal-title":"Swarm Intell."},{"key":"3083_CR22","doi-asserted-by":"crossref","unstructured":"Lindorfer, M., Neugschwandtner, M., Platzer, C.: Marvin: efficient and comprehensive mobile app classification through static and dynamic analysis. In: Proceedings of IEEE 39th Annual COMPSAC, vol 2, pp. 422\u2013433 (2015)","DOI":"10.1109\/COMPSAC.2015.103"},{"key":"3083_CR23","doi-asserted-by":"crossref","unstructured":"Meng, G., et al.: Mystique: evolving Android malware for auditing anti-malware tools. In: Proceedings of 11th ACM Asia CCS, pp. 365\u2013376 (2016)","DOI":"10.1145\/2897845.2897856"},{"key":"3083_CR24","unstructured":"Moonsamy, V., Batten, L.: Zero permission Android applications\u2014attacks and defenses. In: ATIS 2012: Proceedings of the 3rd Applications and Technologies in Information Security Workshop, pp. 5\u20139. School of Information Systems, Deakin University (2012)"},{"key":"3083_CR25","doi-asserted-by":"crossref","unstructured":"Moser, A., Kruegel, C., Kirda, E.: Limits of static analysis for malware detection. In: Proceedings of IEEE 23rd ACSAC, pp. 421\u2013430 (2007)","DOI":"10.1109\/ACSAC.2007.21"},{"key":"3083_CR26","doi-asserted-by":"crossref","unstructured":"Narain, S., Vo-Huu, T.D., Block, K., Noubir, G.: Inferring user routes and locations using zero-permission mobile sensors. In: Proceedings of IEEE S&P, pp. 397\u2013413 (2016)","DOI":"10.1109\/SP.2016.31"},{"key":"3083_CR27","unstructured":"Papernot, N., et al.: Distillation as a defense to adversarial perturbations against deep neural networks. arXiv preprint (2014). arXiv:1511.04508"},{"key":"3083_CR28","doi-asserted-by":"crossref","unstructured":"Papernot, N., et al.: Distillation as a defense to adversarial perturbations against deep neural networks. In: Proceedings of IEEE S&P, pp. 582\u2013597 (2016)","DOI":"10.1109\/SP.2016.41"},{"key":"3083_CR29","doi-asserted-by":"crossref","unstructured":"Papernot, N., et al.: The limitations of deep learning in adversarial settings. In: Proceedings of IEEE Euro S&P, pp. 372\u2013387 (2016)","DOI":"10.1109\/EuroSP.2016.36"},{"key":"3083_CR30","doi-asserted-by":"crossref","unstructured":"Peng, H., Gates, C., Sarma, B., Li, N., Qi, Y., Potharaju, R., Nita-Rotaru, C., Molloy, I.: Using probabilistic generative models for ranking risks of Android apps. In: Proceedings of 19th ACM CCS, pp. 241\u2013252 (2012)","DOI":"10.1145\/2382196.2382224"},{"key":"3083_CR31","unstructured":"Random forest (2019). https:\/\/cs.stackexchange.com\/questions\/66112\/what-is-the-big-oh-asymptotic-complexity-of-learning-in-random-forests. Accessed 25 May 2019"},{"issue":"1","key":"3083_CR32","doi-asserted-by":"publisher","first-page":"99","DOI":"10.1109\/TIFS.2013.2290431","volume":"9","author":"V Rastogi","year":"2014","unstructured":"Rastogi, V., Chen, Y., Jiang, X., et al.: Catch me if you can: evaluating Android anti-malware against transformation attacks. IEEE Trans. Inf. Forensics Secur. 9(1), 99\u2013108 (2014)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"3","key":"3083_CR33","doi-asserted-by":"publisher","first-page":"55","DOI":"10.1145\/2996358","volume":"49","author":"B Reaves","year":"2016","unstructured":"Reaves, B., Bowers, J., Gorski III, S.A., Anise, O., Bobhate, R., Cho, R., Das, H., Hussain, S., Karachiwala, H., Scaife, N., et al.: * droid: assessment and evaluation of Android application analysis tools. ACM Comput. Surv. (CSUR) 49(3), 55 (2016)","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"3083_CR34","doi-asserted-by":"crossref","unstructured":"Roy, S., et al.: Experimental study with real-world data for Android app security analysis using machine learning. In: Proceedings of 31st ACM ACSAC, pp. 81\u201390 (2015)","DOI":"10.1145\/2818000.2818038"},{"key":"3083_CR35","unstructured":"Shen, S., Tople, S., Saxena, P.: Auror: defending against poisoning attacks in collaborative deep learning systems. In: Proceedings of the 32nd Annual Conference on Computer Security Applications, pp. 508\u2013519. ACM (2016)"},{"key":"3083_CR36","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. arXiv preprint (2013). arXiv:1312.6199"},{"key":"3083_CR37","doi-asserted-by":"publisher","first-page":"230","DOI":"10.1016\/j.future.2019.11.034","volume":"105","author":"R Taheri","year":"2020","unstructured":"Rahim Taheri, Meysam Ghahramani, Reza Javidan, Mohammad Shojafar, Zahra Pooranian, Mauro Conti, (2020) Similarity-based Android malware detection using Hamming distance of static binary features. Future Gener. Comput. Syst. 105, 230\u2013247","journal-title":"Future Gener. Comput. Syst."},{"key":"3083_CR38","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2019.07.008","author":"F Zhou","year":"2019","unstructured":"Zhou, F., Yang, S., Fujita, H., Chen, D., Wen, C.: Deep learning fault diagnosis method based on global optimization GAN for unbalanced data. Knowl. Based Syst. (2019). https:\/\/doi.org\/10.1016\/j.knosys.2019.07.008","journal-title":"Knowl. Based Syst."}],"container-title":["Cluster Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-020-03083-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s10586-020-03083-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s10586-020-03083-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,3,17]],"date-time":"2021-03-17T00:20:27Z","timestamp":1615940427000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s10586-020-03083-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3,17]]},"references-count":38,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["3083"],"URL":"https:\/\/doi.org\/10.1007\/s10586-020-03083-5","relation":{},"ISSN":["1386-7857","1573-7543"],"issn-type":[{"value":"1386-7857","type":"print"},{"value":"1573-7543","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,3,17]]},"assertion":[{"value":"8 October 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 February 2020","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 March 2020","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 March 2020","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}