{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:38:09Z","timestamp":1784392689235,"version":"3.55.0"},"reference-count":75,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2021,4,9]],"date-time":"2021-04-09T00:00:00Z","timestamp":1617926400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,4,9]],"date-time":"2021-04-09T00:00:00Z","timestamp":1617926400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-1755890"],"award-info":[{"award-number":["CCF-1755890"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-1252644"],"award-info":[{"award-number":["CCF-1252644"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1629771"],"award-info":[{"award-number":["CNS-1629771"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CCF-1618132"],"award-info":[{"award-number":["CCF-1618132"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2021,5]]},"DOI":"10.1007\/s10664-020-09932-6","type":"journal-article","created":{"date-parts":[[2021,4,9]],"date-time":"2021-04-09T15:03:09Z","timestamp":1617980589000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["Flair: efficient analysis of Android inter-component vulnerabilities in response to incremental changes"],"prefix":"10.1007","volume":"26","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6686-466X","authenticated-orcid":false,"given":"Hamid","family":"Bagheri","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jianghao","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jarod","family":"Aerts","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Negar","family":"Ghorbani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sam","family":"Malek","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,4,9]]},"reference":[{"key":"9932_CR1","unstructured":"Jackson D (2012) Software Abstractions, 2nd edn., MIT Press, Cambridge"},{"key":"9932_CR2","unstructured":"Alloy Models from the Covert project (2015) https:\/\/seal.ics.uci.edu\/projects\/covert"},{"key":"9932_CR3","unstructured":"Malgenome Project (2017) http:\/\/www.malgenomeproject.org"},{"key":"9932_CR4","unstructured":"DroidBench (2018). https:\/\/github.com\/secure-software-engineering\/DroidBench\/"},{"key":"9932_CR5","unstructured":"ICC-Bench (2018) https:\/\/github.com\/fgwei\/ICC-Bench"},{"key":"9932_CR6","unstructured":"Bazaar (2019). https:\/\/cafebazaar.ir\/\/"},{"key":"9932_CR7","unstructured":"F-Droid (2019) https:\/\/f-droid.org\/"},{"key":"9932_CR8","unstructured":"Flair web page (2019) https:\/\/sites.google.com\/view\/flairappanalysis"},{"key":"9932_CR9","unstructured":"Google Play Market (2019) http:\/\/play.google.com\/store\/apps\/"},{"key":"9932_CR10","unstructured":"Number of available apps in the Google Play Store (2019) https:\/\/www.statista.com\/statistics\/266210\/number-of-available-applications-in-the-google-play-store\/"},{"key":"9932_CR11","unstructured":"About Android App Bundles (2020) https:\/\/developer.android.com\/guide\/app-bundle"},{"key":"9932_CR12","unstructured":"About Dynamic Delivery (2020) https:\/\/developer.android.com\/guide\/app-bundle\/dynamic-delivery"},{"key":"9932_CR13","unstructured":"GitHub Repository (2020) https:\/\/github.com\/"},{"key":"9932_CR14","unstructured":"Mobile Operating System Market Share Worldwide (2020) https:\/\/gs.statcounter.com\/os-market-share\/mobile\/worldwide"},{"key":"9932_CR15","doi-asserted-by":"publisher","unstructured":"Alhanahnah M, Yan Q, Bagheri H, Zhou H, Tsutano Y, Srisa-an W, Luo X (2019) Detecting vulnerable android inter-app communication in dynamically loaded code. In: IEEE International conference on computer communications, INFOCOM, Paris, France, April 29 - May 2, 2019, pp 550\u2013558. https:\/\/doi.org\/10.1109\/INFOCOM.2019.8737637","DOI":"10.1109\/INFOCOM.2019.8737637"},{"key":"9932_CR16","doi-asserted-by":"publisher","first-page":"2782","DOI":"10.1109\/TIFS.2020.2976556","volume":"15","author":"M Alhanahnah","year":"2020","unstructured":"Alhanahnah M, Yan Q, Bagheri H, Zhou H, Tsutano Y, Srisa-an W, Luo X (2020) DINA: detecting hidden android inter-app communication in dynamic loaded code. IEEE Trans Inf Forensics Secur 15:2782\u20132797. https:\/\/doi.org\/10.1109\/TIFS.2020.2976556","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"9932_CR17","doi-asserted-by":"publisher","unstructured":"Armando A, Costa G, Merlo A (2012) Formal modeling and reasoning about the android security framework Palamidessi C, Ryan MD (eds). https:\/\/doi.org\/10.1007\/978-3-642-41157-1_5","DOI":"10.1007\/978-3-642-41157-1_5"},{"key":"9932_CR18","doi-asserted-by":"crossref","unstructured":"Arzt S, Rasthofer S, Fritz C, Bodden E, Bartel A, Klein J, Le Traon Y, Octeau D, McDaniel P (2014) Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. In: ACM SIGPLAN Conference on programming language design and implementation, PLDI \u201914, Edinburgh, United Kingdom - June 09 - 11, 2014, PLDI\u201914.ACM, Edinburgh, pp 29","DOI":"10.1145\/2666356.2594299"},{"key":"9932_CR19","doi-asserted-by":"publisher","first-page":"31","DOI":"10.1016\/j.jss.2016.05.039","volume":"119","author":"H Bagheri","year":"2016","unstructured":"Bagheri H, Garcia J, Sadeghi A, Malek S, Medvidovic N (2016) Software architectural principles in contemporary mobile software: from conception to practice. J Syst Softw 119:31\u201344. https:\/\/doi.org\/10.1016\/j.jss.2016.05.039","journal-title":"J Syst Softw"},{"key":"9932_CR20","doi-asserted-by":"publisher","unstructured":"Bagheri H, Kang E, Malek S, Jackson D (2015) Detection of design flaws in the android permission protocol through bounded verification. In: Bj\u00f8rner N, de Boer F (eds) FM 2015: formal methods, Lecture Notes in Computer Science, vol 9109, pp 73\u201389. Springer International Publishing. https:\/\/doi.org\/10.1007\/978-3-319-19249-9_6","DOI":"10.1007\/978-3-319-19249-9_6"},{"issue":"5","key":"9932_CR21","doi-asserted-by":"publisher","first-page":"525","DOI":"10.1007\/s00165-017-0445-z","volume":"30","author":"H Bagheri","year":"2018","unstructured":"Bagheri H, Kang E, Malek S, Jackson D (2018) A Formal Approach for Detection of Security Flaws in the Android Permission System. Form Asp Comput 30(5):525\u2013544. https:\/\/doi.org\/10.1007\/s00165-017-0445-z","journal-title":"Form Asp Comput"},{"key":"9932_CR22","doi-asserted-by":"crossref","unstructured":"Bagheri H, Malek S (2016) Titanium: efficient analysis of evolving alloy specifications. In: Proceedings of the ACM SIGSOFT International symposium on the foundations of software engineering, FSE\u201916","DOI":"10.1145\/2950290.2950337"},{"key":"9932_CR23","doi-asserted-by":"publisher","unstructured":"Bagheri H, Sadeghi A, Behrouz RJ, Malek S (2016) Practical, formal synthesis and automatic enforcement of security policies for android. In: 46th Annual IEEE\/IFIP international conference on dependable systems and networks, DSN 2016, Toulouse, France, June 28 - July 1, 2016. IEEE Computer Society, pp 514\u2013525. https:\/\/doi.org\/10.1109\/DSN.2016.53","DOI":"10.1109\/DSN.2016.53"},{"key":"9932_CR24","doi-asserted-by":"crossref","unstructured":"Bagheri H, Sadeghi A, Garcia J, Malek S (2015) COVERT: compositional analysis of android inter-app permission leakage IEEE. Trans Softw Eng (TSE)","DOI":"10.1109\/TSE.2015.2419611"},{"key":"9932_CR25","doi-asserted-by":"publisher","unstructured":"Bagheri H, Song Y, Sullivan KJ (2010) Architectural style as an independent variable. In: Pecheur C, Andrews J, Nitto ED (eds) ASE 2010, 25th IEEE\/ACM International conference on automated software engineering, Antwerp, Belgium, September 20-24, 2010. ACM, pp 159\u2013162. https:\/\/doi.org\/10.1145\/1858996.1859026","DOI":"10.1145\/1858996.1859026"},{"key":"9932_CR26","doi-asserted-by":"publisher","unstructured":"Bagheri H, Sullivan KJ (2012) Pol: specification-driven synthesis of architectural code frameworks for platform-based applications. In: Ostermann K, Binder W (eds) Generative programming and component engineering, GPCE\u201912, Dresden, Germany, September 26-28, 2012. ACM, pp 93\u2013102. https:\/\/doi.org\/10.1145\/2371401.2371416","DOI":"10.1145\/2371401.2371416"},{"key":"9932_CR27","doi-asserted-by":"publisher","unstructured":"Bagheri H, Sullivan KJ (2013) Bottom-up model-driven development. In: Notkin D, Cheng BHC, Pohl K (eds) 35th International conference on software engineering, ICSE \u201913, San Francisco, CA, USA, May 18-26, 2013. IEEE Computer Society, pp 1221\u20131224. https:\/\/doi.org\/10.1109\/ICSE.2013.6606683","DOI":"10.1109\/ICSE.2013.6606683"},{"issue":"3","key":"9932_CR28","doi-asserted-by":"publisher","first-page":"441","DOI":"10.1007\/s00165-016-0360-8","volume":"28","author":"H Bagheri","year":"2016","unstructured":"Bagheri H, Sullivan KJ (2016) Model-driven synthesis of formally precise, stylized software architectures. Formal Asp Comput 28 (3):441\u2013467. https:\/\/doi.org\/10.1007\/s00165-016-0360-8","journal-title":"Formal Asp Comput"},{"key":"9932_CR29","doi-asserted-by":"publisher","unstructured":"Bagheri H, Tang C, Sullivan KJ (2014) TradeMaker: Automated dynamic analysis of synthesized tradespaces. In: Jalote P, Briand LC, van der Hoek A (eds) 36th International conference on software engineering, ICSE \u201914, Hyderabad, India - May 31 - June 07, 2014. ACM, pp 106\u2013116. https:\/\/doi.org\/10.1145\/2568225.2568291","DOI":"10.1145\/2568225.2568291"},{"issue":"2","key":"9932_CR30","doi-asserted-by":"publisher","first-page":"145","DOI":"10.1109\/TSE.2016.2587646","volume":"43","author":"H Bagheri","year":"2017","unstructured":"Bagheri H, Tang C, Sullivan KJ (2017) Automated synthesis and dynamic analysis of tradeoff spaces for object-relational mapping. IEEE Trans Software Eng 43(2):145\u2013163. https:\/\/doi.org\/10.1109\/TSE.2016.2587646","journal-title":"IEEE Trans Software Eng"},{"key":"9932_CR31","doi-asserted-by":"publisher","unstructured":"Bagheri H, Wang J, Aerts J, Malek S (2018) Efficient, evolutionary security analysis of interacting android apps. In: 2018 IEEE International conference on software maintenance and evolution (ICSME), pp 357\u2013368. https:\/\/doi.org\/10.1109\/ICSME.2018.00044","DOI":"10.1109\/ICSME.2018.00044"},{"key":"9932_CR32","doi-asserted-by":"crossref","unstructured":"Bosu A, Liu F, Yao DD, Wang G (2017) Collusive data leak and more: large-scale threat analysis of inter-app communications. In: Proceedings of the 2017 ACM on Asia conference on computer and communications security, AsiaCCS 2017, Abu Dhabi, United Arab Emirates, April 2-6, 2017. pp 71\u201385","DOI":"10.1145\/3052973.3053004"},{"key":"9932_CR33","unstructured":"Bugiel S, Davi L, Dmitrienko A, Fischer T, Sadeghi A (2011) Xmandroid: a new android evolution to mitigate privilege escalation attacks. Technische Universit\u00c3t Darmstadt Technical Report TR-2011-04"},{"key":"9932_CR34","unstructured":"Bugiel S, David L, Dmitrienko A, Fischer T, Sadeghi A, Shastry B (2012) Towards taming privilege-escalation attacks on android. In: 19th Annual network and distributed system security symposium, NDSS 2012, San Diego, California, USA, February 5-8"},{"key":"9932_CR35","doi-asserted-by":"publisher","unstructured":"Bugliesi M, Calzavara S, Span\u00c3 A (2013) Lintent: Towards security type-checking of android applications. In: Beyer D, Boreale M (eds) Formal techniques for distributed systems, no. 7892 in Lecture Notes in Computer Science. https:\/\/doi.org\/10.1007\/978-3-642-38592-6_20. Springer, Berlin, pp 289\u2013304","DOI":"10.1007\/978-3-642-38592-6_20"},{"key":"9932_CR36","doi-asserted-by":"crossref","unstructured":"Chaudhuri A (2009) Language-based security on Android. In: Proceedings of programming languages and analysis for security (PLAS\u201909). pp 1\u20137","DOI":"10.1145\/1554339.1554341"},{"key":"9932_CR37","doi-asserted-by":"crossref","unstructured":"Chin E, Felt AP, Greenwood K, Wagner D (2011) Analyzing inter-application communication in android. In: Proceedings of the 9th international conference on mobile systems, applications, and services. ACM, Washington, pp 239\u2013252","DOI":"10.1145\/1999995.2000018"},{"key":"9932_CR38","unstructured":"Cozza R, Durand I, Gupta A (2014) Market share: ultramobiles by region, OS and Form Factor, 4Q13 and 2013 Gartner market research report"},{"key":"9932_CR39","doi-asserted-by":"crossref","unstructured":"Davi L, Dmitrienko A, Sadeghi A, Winandy M Burmester M, Tsudik G, Magliveras S, Ili\u0107 I (eds) (2010) Privilege escalation attacks on android. Springer, Berlin","DOI":"10.1007\/978-3-642-18178-8_30"},{"key":"9932_CR40","unstructured":"Dietz M, Shekhar S, Pisetsky Y, Shu A, Wallach DS (2011) QUIRE: Lightweight provenance for smart phone operating systems. In: USENIX Security symposium. San Francisco, CA"},{"key":"9932_CR41","doi-asserted-by":"publisher","unstructured":"Felt AP, Chin E, Hanna S, Song D, Wagner D (2011) Android permissions demystified. In: Proceedings of the 18th ACM Conference on computer and communications security, CCS \u201911. https:\/\/doi.org\/10.1145\/2046707.2046779. ACM, Chicago, pp 627\u2013638","DOI":"10.1145\/2046707.2046779"},{"key":"9932_CR42","unstructured":"Felt AP, Hanna S, Chin E, Wang HJ, Moshchuk E (2011) Permission re-delegation: attacks and defenses. In: In 20th Usenix security symposium. San Francisco, CA"},{"key":"9932_CR43","doi-asserted-by":"crossref","unstructured":"Fragkaki E, Bauer L, Jia L, Swasey D (2012) Modeling and enhancing android\u2019s permission system. In: 17th European symposium on research in computer security (ESORICS), pp 1\u201318","DOI":"10.21236\/ADA579929"},{"key":"9932_CR44","unstructured":"Fuchs AP, Chaudhuri A, Foster JS (2009) SCanDroid: automated security certification of Android applications"},{"key":"9932_CR45","doi-asserted-by":"crossref","unstructured":"Ganov S, Khurshid S, Perry DE (2012) Annotations for alloy: automated incremental analysis using domain specific solvers. In: Proceedings of ICFEM, pp 414\u2013429","DOI":"10.1007\/978-3-642-34281-3_29"},{"key":"9932_CR46","doi-asserted-by":"publisher","unstructured":"Hammad M, Bagheri H, Malek S (2017) Determination and enforcement of least-privilege architecture in android. In: 2017 IEEE International conference on software architecture, ICSA 2017, Gothenburg, Sweden, April 3-7, 2017. IEEE, pp 59\u201368. https:\/\/doi.org\/10.1109\/ICSA.2017.18","DOI":"10.1109\/ICSA.2017.18"},{"key":"9932_CR47","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1016\/j.jss.2018.11.049","volume":"149","author":"M Hammad","year":"2019","unstructured":"Hammad M, Bagheri H, Malek S (2019) DelDroid: An automated approach for determination and enforcement of least-privilege architecture in android. J Syst Softw 149:83\u2013100","journal-title":"J Syst Softw"},{"issue":"2","key":"9932_CR48","doi-asserted-by":"publisher","first-page":"256","DOI":"10.1145\/505145.505149","volume":"11","author":"D Jackson","year":"2002","unstructured":"Jackson D (2002) Alloy: a lightweight object modelling notation. ACM Trans Softw Eng Methodol (TOSEM) 11(2):256\u2013290","journal-title":"ACM Trans Softw Eng Methodol (TOSEM)"},{"issue":"4","key":"9932_CR49","doi-asserted-by":"publisher","first-page":"403","DOI":"10.1023\/B:AUSE.0000038938.10589.b9","volume":"11","author":"S Khurshid","year":"2004","unstructured":"Khurshid S, Marinov D (2004) TestEra: specification-based testing of java programs using SAT. Autom Softw Eng 11(4):403\u2013434","journal-title":"Autom Softw Eng"},{"key":"9932_CR50","doi-asserted-by":"crossref","unstructured":"Klieber W, Flynn L, Bhosale A, Jia L, Bauer L (2014) Android taint flow analysis for app sets. In: Proceedings of the 3rd ACM SIGPLAN International workshop on the state of the art in java program analysis. ACM, Edinburgh, UK, pp 1\u20136","DOI":"10.1145\/2614628.2614633"},{"key":"9932_CR51","doi-asserted-by":"crossref","unstructured":"Lee YK, Bang JY, Safi G, Shahbazian A, Zhao Y, Medvidovic N (2017) A SEALANT for inter-app security holes in android. In: Proceedings of the 39th International conference on software engineering, ICSE 2017, Buenos Aires, Argentina, May 20-28, 2017. pp 312\u2013323","DOI":"10.1109\/ICSE.2017.36"},{"key":"9932_CR52","doi-asserted-by":"publisher","unstructured":"Li L, Bartel A, Bissyand\u00e9 TF, Klein J, Traon YL (2015) ApkCombiner: combining multiple android apps to support inter-app analysis. In: Federrath H, Gollmann D (eds) ICT Systems security and privacy protection - 30th IFIP TC 11 International conference, SEC 2015, Hamburg, Germany, May 26-28, 2015, Proceedings, ICT SEC\u201915, vol 455. Springer, pp 513\u2013527. https:\/\/doi.org\/10.1007\/978-3-319-18467-8_34","DOI":"10.1007\/978-3-319-18467-8_34"},{"key":"9932_CR53","doi-asserted-by":"crossref","unstructured":"Li L, Bartel A, Bissyande T, Klein J, Traon YL, Arzt S, Rasthofer S, Bodden E, Octeau D, McDaniel P (2015) IccTA: Detecting inter-component privacy leaks in android apps. In: Proceedings of the 37th International conference on software engineering, ICSE 2015. Florence, Italy","DOI":"10.1109\/ICSE.2015.48"},{"key":"9932_CR54","unstructured":"Li L, Bartel A, Klein J, Traon YL, Arzt S, Rasthofer S, Bodden E, Octeau D, McDaniel P (2014) I know what leaked in your pocket: uncovering privacy leaks on android apps with static taint analysis. arXiv:1404.7431 [cs]"},{"key":"9932_CR55","doi-asserted-by":"crossref","unstructured":"Lu L, Li Z, Wu Z, Lee W, Jiang G (2012) Chex: statically vetting android apps for component hijacking vulnerabilities. In: Proceedings of the 2012 ACM conference on computer and communications security. ACM, Raleigh, pp 229\u2013240","DOI":"10.1145\/2382196.2382223"},{"key":"9932_CR56","doi-asserted-by":"crossref","unstructured":"Marforio C, Ritzdorf H, Francillo A, Capkun S (2012) Analysis of the communication between colluding applications on modern smartphones. In: The annual computer security applications conference (ACSAC), ACSAC\u201912","DOI":"10.1145\/2420950.2420958"},{"key":"9932_CR57","doi-asserted-by":"publisher","unstructured":"Mirzaei N, Garcia J, Bagheri H, Sadeghi A, Malek S (2016) Reducing combinatorics in GUI testing of android applications. In: Dillon LK, Visser W, Williams L (eds) Proceedings of the 38th International conference on software engineering, ICSE 2016, Austin, TX, USA, May 14-22, 2016. ACM, pp 559\u2013570. https:\/\/doi.org\/10.1145\/2884781.2884853","DOI":"10.1145\/2884781.2884853"},{"key":"9932_CR58","doi-asserted-by":"publisher","unstructured":"Near JP, Jackson D (2014) Derailer: interactive security analysis for web applications. In: Proceedings of the 29th ACM\/IEEE International conference on automated software engineering, ASE \u201914. https:\/\/doi.org\/10.1145\/2642937.2643012. ACM, New York, pp 587\u2013598","DOI":"10.1145\/2642937.2643012"},{"key":"9932_CR59","doi-asserted-by":"publisher","unstructured":"Octeau D, Jha S, Dering M, McDaniel P, Bartel A, Li L, Klein J, Traon YL (2016) Combining static analysis with probabilistic models to enable market-scale android inter-component analysis. In: Bod\u00edk R, Majumdar R (eds) Proceedings of the 43rd Annual ACM SIGPLAN-SIGACT symposium on principles of programming languages, POPL 2016, St. Petersburg, FL, USA, January 20 - 22, 2016. ACM, pp 469\u2013484. https:\/\/doi.org\/10.1145\/2837614.2837661","DOI":"10.1145\/2837614.2837661"},{"key":"9932_CR60","doi-asserted-by":"crossref","unstructured":"Octeau D, Luchaup D, Dering M, Jha S, McDaniel P (2015) Composite constant propagation: application to android inter-component communication analysis. In: International conference on software engineering. IEEE, Florence","DOI":"10.1109\/ICSE.2015.30"},{"key":"9932_CR61","unstructured":"Octeau D, McDaniel P, Jha S, Bartel A, Bodden E, Klein J, Le Traon Y (2013) Effective inter-component communication mapping in android with epicc: an essential step towards holistic security analysis. In: Proceedings of the 22Nd USENIX Conference on security, SEC\u201913. USENIX Association, pp 543\u2013558"},{"key":"9932_CR62","doi-asserted-by":"publisher","unstructured":"Ravitch T, Creswick ER, Tomb A, Foltzer A, Elliott T, Casburn L (2014) Multi-app security analysis with FUSE: statically detecting android app collusion. In: Proceedings of the 4th Program protection and reverse engineering workshop, PPREW-4. ACM, New Orleans pp 4:1\u20134:10. https:\/\/doi.org\/10.1145\/2689702.2689705","DOI":"10.1145\/2689702.2689705"},{"key":"9932_CR63","doi-asserted-by":"crossref","unstructured":"Rosner N, Siddiqui JH, Aguirre N, Khurshid S, Frias MF (2013) Ranger: parallel analysis of alloy models by range partitioning. In: Proceeding of the 28th IEEE\/ACM International conference on automated software engineering (ASE). pp 147\u2013157","DOI":"10.1109\/ASE.2013.6693075"},{"issue":"6","key":"9932_CR64","doi-asserted-by":"publisher","first-page":"492","DOI":"10.1109\/TSE.2016.2615307","volume":"43","author":"A Sadeghi","year":"2017","unstructured":"Sadeghi A, Bagheri H, Garcia J, Malek S (2017) A taxonomy and qualitative comparison of program analysis techniques for security assessment of android software. IEEE Trans Software Eng 43(6):492\u2013530. https:\/\/doi.org\/10.1109\/TSE.2016.2615307","journal-title":"IEEE Trans Software Eng"},{"key":"9932_CR65","doi-asserted-by":"publisher","unstructured":"Sadeghi A, Bagheri H, Malek S (2015) Analysis of android inter-app security vulnerabilities using COVERT. In: Bertolino A, Canfora G, Elbaum SG (eds) 37th IEEE\/ACM International conference on software engineering, ICSE 2015, Florence, Italy, May 16-24, 2015, vol 2. IEEE Computer Society, pp 725\u2013728. https:\/\/doi.org\/10.1109\/ICSE.2015.233","DOI":"10.1109\/ICSE.2015.233"},{"key":"9932_CR66","doi-asserted-by":"crossref","unstructured":"Sadeghi A, Jabbarvand R, Ghorbani N, Bagheri H, Malek S (2018) A temporal permission analysis and enforcement framework for android. In: Proceedings of the 40th International conference on software engineering, ICSE\u201918. pp 846\u2013857","DOI":"10.1145\/3180155.3180172"},{"key":"9932_CR67","doi-asserted-by":"publisher","unstructured":"Schmerl BR, Gennari J, Sadeghi A, Bagheri H, Malek S, C\u00e1mara J, Garlan D (2016) Architecture modeling and analysis of security in android systems. In: Tekinerdogan B, Zdun U, Babar MA (eds) Software architecture - 10th european conference, ECSA 2016, Copenhagen, Denmark, November 28 - December 2, 2016, Proceedings, Lecture Notes in Computer Science, vol 9839. pp 274\u2013290. https:\/\/doi.org\/10.1007\/978-3-319-48992-6_21","DOI":"10.1007\/978-3-319-48992-6_21"},{"issue":"2","key":"9932_CR68","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2636242.2636244","volume":"18","author":"S Seneviratne","year":"2014","unstructured":"Seneviratne S, Seneviratne A, Mohapatra P, Mahanti A (2014) Predicting user traits from a snapshot of apps installed on a Smartphone. ACM SIGMOBILE Mobil Comput Commun Rev 18(2):1\u20138","journal-title":"ACM SIGMOBILE Mobil Comput Commun Rev"},{"key":"9932_CR69","unstructured":"Smith E, Coglio A (2015) Android platform modeling and android app verification in the ACL2 theorem prover. In: Proceedings of the 7th International conference on verified software: theories, tools, and experiments, VSTTE\u201915, pp 183\u2013201"},{"key":"9932_CR70","doi-asserted-by":"publisher","unstructured":"Taghdiri M (2004) Inferring specifications to detect errors in code. In: Proceedings of the 19th IEEE International conference on automated software engineering, ASE \u201904. https:\/\/doi.org\/10.1109\/ASE.2004.42. IEEE Computer Society, Washington, pp 144\u2013153","DOI":"10.1109\/ASE.2004.42"},{"key":"9932_CR71","unstructured":"Torlak E (2009) A constraint solver for software engineering: finding models and cores of large relational specifications. PhD thesis, MIT. http:\/\/alloy.mit.edu\/kodkod\/"},{"key":"9932_CR72","doi-asserted-by":"crossref","unstructured":"Uzuncaova E, Khurshid S (2007) Kato: A Program Slicing Tool for Declarative Specifications. In: Proceedings of international conference on software engineering, ICSE\u201907, pp 767\u2013770","DOI":"10.1109\/ICSE.2007.47"},{"key":"9932_CR73","doi-asserted-by":"crossref","unstructured":"Uzuncaova E, Khurshid S (2008) Constraint prioritization for efficient analysis of declarative models. In: Proceedings of international symposium on formal methods, FM\u201908","DOI":"10.1007\/978-3-540-68237-0_22"},{"key":"9932_CR74","doi-asserted-by":"publisher","unstructured":"Wei F, Roy S, Ou X (2014) Robby: Amandroid: a precise and general inter-component data flow analysis framework for security vetting of android apps. In: Proceedings of the 2014 ACM SIGSAC conference on computer and communications security, CCS \u201914. https:\/\/doi.org\/10.1145\/2660267.2660357. ACM, Scottsdale, pp 1329\u20131341","DOI":"10.1145\/2660267.2660357"},{"key":"9932_CR75","doi-asserted-by":"crossref","unstructured":"Zheng G, Bagheri H, Rothermel G, Wang J (2020) Platinum: Reusing Constraint Solutions in Bounded Analysis of Relational Logic. In: Wehrheim H, Cabot J (eds) Fundamental approaches to software engineering - 23rd international conference, FASE 2020, Held as part of the european joint conferences on theory and practice of software, ETAPS 2020, Dublin, Ireland, April 25-30, 2020, Proceedings, Lecture Notes in Computer Science, vol 12076. Springer, pp 29\u201352","DOI":"10.1007\/978-3-030-45234-6_2"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-020-09932-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-020-09932-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-020-09932-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,1]],"date-time":"2021-05-01T13:21:45Z","timestamp":1619875305000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-020-09932-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,4,9]]},"references-count":75,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2021,5]]}},"alternative-id":["9932"],"URL":"https:\/\/doi.org\/10.1007\/s10664-020-09932-6","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,4,9]]},"assertion":[{"value":"23 December 2020","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 April 2021","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"54"}}