{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T04:21:51Z","timestamp":1769746911563,"version":"3.49.0"},"reference-count":82,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2025,5,21]],"date-time":"2025-05-21T00:00:00Z","timestamp":1747785600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,5,21]],"date-time":"2025-05-21T00:00:00Z","timestamp":1747785600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61562040"],"award-info":[{"award-number":["61562040"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Science and Technology Project of the Education Department of Jiangxi Province","award":["GJJ200313"],"award-info":[{"award-number":["GJJ200313"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1007\/s10664-025-10671-9","type":"journal-article","created":{"date-parts":[[2025,5,21]],"date-time":"2025-05-21T05:12:10Z","timestamp":1747804330000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["JNFuzz-Droid: a lightweight fuzzing and taint analysis framework for native code of Android applications"],"prefix":"10.1007","volume":"30","author":[{"given":"Jianchao","family":"Cao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fan","family":"Guo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yanwen","family":"Qu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,5,21]]},"reference":[{"key":"10671_CR1","first-page":"119","volume-title":"10th International Conference on Malicious and Unwanted Software","author":"A Abraham","year":"2015","unstructured":"Abraham A, Andriatsimandefitra R, Brunelat A, Lalande J, Tong VVT (2015) Grodddroid: a gorilla for triggering malicious behaviors. 10th International Conference on Malicious and Unwanted Software. IEEE, IEEE Computer Society, Fajardo, PR, USA, MALWARE, pp 119\u2013127"},{"key":"10671_CR2","unstructured":"AFLplusplus (2024a) The afl++ fuzzing framework. https:\/\/aflplus.plus\/"},{"key":"10671_CR3","unstructured":"AFLplusplus (2024b) AFLplusplus_frida_mode. https:\/\/github.com\/AFLplusplus\/AFLplusplus\/tree\/stable\/frida_mode"},{"key":"10671_CR4","unstructured":"AFLplusplus (2024c) AFLplusplus_qbdi_mode. https:\/\/github.com\/AFLplusplus\/AFLplusplus\/tree\/stable\/utils\/qbdi_mode"},{"key":"10671_CR5","doi-asserted-by":"crossref","unstructured":"Afonso VM, de\u00a0Geus PL, Bianchi A, Fratantonio Y, Kruegel C, Vigna G, Doup\u00e9 A, Polino M (2016) Going native: Using a large-scale analysis of android apps to create a practical native-code sandboxing policy. In: 23rd Annual Network and Distributed System Security Symposium, NDSS, The Internet Society, San Diego, California, USA","DOI":"10.14722\/ndss.2016.23384"},{"key":"10671_CR6","doi-asserted-by":"publisher","unstructured":"Allix K, Bissyand\u00e9 TF, Klein J, Traon YL (2016) Androzoo: collecting millions of android apps for the research community. In: Kim M, Robbes R, Bird C (eds) Proceedings of the 13th International Conference on Mining Software Repositories, MSR 2016, Austin, TX, USA, May 14-22, 2016, ACM, pp 468\u2013471, https:\/\/doi.org\/10.1145\/2901739.2903508","DOI":"10.1145\/2901739.2903508"},{"key":"10671_CR7","doi-asserted-by":"publisher","unstructured":"Andarzian SB, Ladani BT (2020) Compositional taint analysis of native codes for security vetting of android applications. In: 2020 10th International Conference on Computer and Knowledge Engineering (ICCKE), pp 567\u2013572, https:\/\/doi.org\/10.1109\/ICCKE50421.2020.9303643","DOI":"10.1109\/ICCKE50421.2020.9303643"},{"issue":"1","key":"10671_CR8","first-page":"13","volume":"14","author":"SB Andarzian","year":"2022","unstructured":"Andarzian SB, Ladani BT (2022) SANT: static analysis of native threads for security vetting of android applications. ISC Int J Inf Secur 14(1):13\u201325","journal-title":"ISC Int J Inf Secur"},{"key":"10671_CR9","doi-asserted-by":"publisher","unstructured":"Arzt S, Rasthofer S, Fritz C, Bodden E, Bartel A, Klein J, Traon YL, Octeau D, McDaniel PD (2014) Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. In: O\u2019Boyle MFP, Pingali K (eds) ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI \u201914, Edinburgh, United Kingdom - June 09 - 11, 2014, ACM, pp 259\u201326https:\/\/doi.org\/10.1145\/2594291.2594299","DOI":"10.1145\/2594291.2594299"},{"key":"10671_CR10","unstructured":"avast (2024) Retdec is a retargetable machine-code decompiler based on llvm. https:\/\/retdec.com\/"},{"key":"10671_CR11","doi-asserted-by":"crossref","unstructured":"Backes M, Bugiel S, Schranz O, von Styp-Rekowsky P, Weisgerber S (2017) Artist: The android runtime instrumentation and security toolkit. In: 2017 IEEE European Symposium on Security and Privacy, EuroS &P, IEEE, Paris, France, pp 481\u2013495","DOI":"10.1109\/EuroSP.2017.43"},{"key":"10671_CR12","doi-asserted-by":"publisher","first-page":"481","DOI":"10.1109\/EuroSP.2017.43","volume-title":"2017 IEEE European Symposium on Security and Privacy","author":"M Backes","year":"2017","unstructured":"Backes M, Bugiel S, Schranz O, von Styp-Rekowsky P, Weisgerber S (2017) Artist: The android runtime instrumentation and security toolkit. 2017 IEEE European Symposium on Security and Privacy. EuroS &P, IEEE, Paris, France, pp 481\u2013495"},{"key":"10671_CR13","doi-asserted-by":"publisher","unstructured":"Cao J, Guo F, Qu Y (2024) Jnfuzz-droid: A lightweight fuzzing and taint analysis framework for android native code. In: IEEE International Conference on Software Analysis, Evolution and Reengineering, SANER 2024, Rovaniemi, Finland, March 12-15, 2024, IEEE, pp 255\u2013266, https:\/\/doi.org\/10.1109\/SANER60148.2024.00033","DOI":"10.1109\/SANER60148.2024.00033"},{"key":"10671_CR14","doi-asserted-by":"publisher","unstructured":"Cao S, He B, Sun X, Ouyang Y, Zhang C, Wu X, Su T, Bo L, Li B, Ma C, Li J, Wei T (2023) Oddfuzz: Discovering java deserialization vulnerabilities via structure-aware directed greybox fuzzing. In: 44th IEEE Symposium on Security and Privacy, SP 2023, San Francisco, CA, USA, May 21-25, 2023, IEEE, pp 2726\u20132743, https:\/\/doi.org\/10.1109\/SP46215.2023.10179377","DOI":"10.1109\/SP46215.2023.10179377"},{"key":"10671_CR15","doi-asserted-by":"crossref","unstructured":"Christensen AS, M\u00f8ller A, Schwartzbach MI (2003) Precise analysis of string expressions. In: Static Analysis, 10th International Symposium, SAS, Springer, San Diego, CA, USA, Lecture Notes in Computer Science, vol 2694, pp 1\u201318","DOI":"10.1007\/3-540-44898-5_1"},{"key":"10671_CR16","doi-asserted-by":"crossref","unstructured":"Dinesh S, Burow N, Xu D, Payer M (2020) Retrowrite: Statically instrumenting COTS binaries for fuzzing and sanitization. In: 2020 IEEE Symposium on Security and Privacy, SP, IEEE, San Francisco, CA, USA, pp 1497\u20131511","DOI":"10.1109\/SP40000.2020.00009"},{"key":"10671_CR17","doi-asserted-by":"crossref","unstructured":"Enck W, Gilbert P, Han S, Tendulkar V, Chun B, Cox LP, Jung J, McDaniel PD, Sheth AN (2014) Taintdroid: An information-flow tracking system for realtime privacy monitoring on smartphones. ACM Trans Comput Syst 32(2):5:1\u20135:29","DOI":"10.1145\/2619091"},{"key":"10671_CR18","doi-asserted-by":"publisher","first-page":"1497","DOI":"10.1109\/SP40000.2020.00009","volume-title":"2020 IEEE Symposium on Security and Privacy","author":"S Dinesh","year":"2020","unstructured":"Dinesh S, Burow N, Xu D, Payer M (2020) Retrowrite: Statically instrumenting COTS binaries for fuzzing and sanitization. 2020 IEEE Symposium on Security and Privacy. USA, SP, IEEE, San Francisco, CA, pp 1497\u20131511"},{"key":"10671_CR19","doi-asserted-by":"crossref","unstructured":"Fourtounis G, Triantafyllou L, Smaragdakis Y (2020) Identifying java calls in native code via binary scanning. In: ISSTA \u201920: 29th ACM SIGSOFT International Symposium on Software Testing and Analysis, ACM, Virtual Event, USA, pp 388\u2013400","DOI":"10.1145\/3395363.3397368"},{"key":"10671_CR20","unstructured":"Google (2024a) Android linker changes for NDK developers. https:\/\/android.googlesource.com\/platform\/bionic\/+\/master\/android-changes-for-ndk-developers.md"},{"key":"10671_CR21","first-page":"388","volume-title":"ISSTA \u201920: 29th ACM SIGSOFT International Symposium on Software Testing and Analysis","author":"G Fourtounis","year":"2020","unstructured":"Fourtounis G, Triantafyllou L, Smaragdakis Y (2020) Identifying java calls in native code via binary scanning. ISSTA \u201920: 29th ACM SIGSOFT International Symposium on Software Testing and Analysis. ACM, Virtual Event, USA, pp 388\u2013400"},{"key":"10671_CR22","unstructured":"Google (2024c) UI_Application Exerciser Monkey _ Android Studio _ Android Developers. https:\/\/developer.android.com\/studio\/test\/other-testing-tools\/monkey"},{"key":"10671_CR23","doi-asserted-by":"crossref","unstructured":"Gordon MI, Kim D, Perkins JH, Gilham L, Nguyen N, Rinard MC (2015) Information flow analysis of android applications in droidsafe. In: 22nd Annual Network and Distributed System Security Symposium, NDSS, The Internet Society, San Diego, California, USA, pp 4014\u20134040","DOI":"10.14722\/ndss.2015.23089"},{"key":"10671_CR24","unstructured":"Gradle (2024) Gradle build tool. https:\/\/gradle.org\/"},{"key":"10671_CR25","first-page":"4014","volume-title":"22nd Annual Network and Distributed System Security Symposium","author":"MI Gordon","year":"2015","unstructured":"Gordon MI, Kim D, Perkins JH, Gilham L, Nguyen N, Rinard MC (2015) Information flow analysis of android applications in droidsafe. 22nd Annual Network and Distributed System Security Symposium. The Internet Society, San Diego, California, USA, NDSS, pp 4014\u20134040"},{"key":"10671_CR26","doi-asserted-by":"crossref","unstructured":"Hwang S, Lee S, Kim J, Ryu S (2021b) Justgen: Effective test generation for unspecified JNI behaviors on jvms. In: 43rd IEEE\/ACM International Conference on Software Engineering: Companion Proceedings, ICSE Companion 2021, Madrid, Spain, May 25-28, 2021, IEEE, Madrid, Spain, pp 171\u2013172","DOI":"10.1109\/ICSE-Companion52605.2021.00073"},{"key":"10671_CR27","first-page":"1708","volume-title":"43rd IEEE\/ACM International Conference on Software Engineering, ICSE 2021, Madrid, Spain, 22\u201330 May 2021","author":"S Hwang","year":"2021","unstructured":"Hwang S, Lee S, Kim J, Ryu S (2021) Justgen: Effective test generation for unspecified JNI behaviors on jvms. 43rd IEEE\/ACM International Conference on Software Engineering, ICSE 2021, Madrid, Spain, 22\u201330 May 2021. IEEE, Madrid, Spain, pp 1708\u20131718"},{"key":"10671_CR28","first-page":"171","volume-title":"43rd IEEE\/ACM International Conference on Software Engineering: Companion Proceedings, ICSE Companion 2021, Madrid, Spain, May 25\u201328, 2021","author":"S Hwang","year":"2021","unstructured":"Hwang S, Lee S, Kim J, Ryu S (2021) Justgen: Effective test generation for unspecified JNI behaviors on jvms. 43rd IEEE\/ACM International Conference on Software Engineering: Companion Proceedings, ICSE Companion 2021, Madrid, Spain, May 25\u201328, 2021. IEEE, Madrid, Spain, pp 171\u2013172"},{"key":"10671_CR29","unstructured":"Jun Gao (2024) gaojun0816_nativediscloser. https:\/\/github.com\/gaojun0816\/nativediscloser"},{"key":"10671_CR30","doi-asserted-by":"crossref","unstructured":"Kadir AFA, Stakhanova N, Ghorbani AA (2015) Android botnets: What urls are telling us. In: Network and System Security - 9th International Conference, NSS 2015, Springer, New York, NY, USA, Lecture Notes in Computer Science, vol 9408, pp 78\u201391","DOI":"10.1007\/978-3-319-25645-0_6"},{"key":"10671_CR31","doi-asserted-by":"crossref","unstructured":"Kim T, Ha H, Choi S, Jung J, Chun B (2017) Breaking ad-hoc runtime integrity protection mechanisms in android financial apps. In: Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security, AsiaCCS, ACM, Abu Dhabi, United Arab Emirates, pp 179\u2013192","DOI":"10.1145\/3052973.3053018"},{"key":"10671_CR32","doi-asserted-by":"crossref","unstructured":"Lee S (2019) JNI program analysis with automatically extracted C semantic summary. In: Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis, ISSTA, ACM, Beijing, China, pp 448\u2013451","DOI":"10.1145\/3293882.3338990"},{"key":"10671_CR33","doi-asserted-by":"publisher","unstructured":"Lee S, Lee H, Ryu S (2020) Broadening horizons of multilingual static analysis: Semantic summary extraction from C code for JNI program analysis. In: 35th IEEE\/ACM International Conference on Automated Software Engineering, ASE 2020, Melbourne, Australia, September 21-25, 2020, IEEE, pp 127\u2013137, https:\/\/doi.org\/10.1145\/3324884.3416558,","DOI":"10.1145\/3324884.3416558"},{"key":"10671_CR34","doi-asserted-by":"crossref","unstructured":"Li D, Lyu Y, Wan M, Halfond WGJ (2015a) String analysis for java and android applications. In: Proceedings of the 2015 10th Joint Meeting on Foundations of Software Engineering, ESEC\/FSE, ACM, Bergamo, Italy, pp 661\u2013672","DOI":"10.1145\/2786805.2786879"},{"key":"10671_CR35","doi-asserted-by":"crossref","unstructured":"Li L, Bartel A, Bissyand\u00e9 TF, Klein J, Traon YL, Arzt S, Rasthofer S, Bodden E, Octeau D, McDaniel PD (2015b) Iccta: Detecting inter-component privacy leaks in android apps. In: 37th IEEE\/ACM International Conference on Software Engineering, ICSE, IEEE Computer Society, Florence, Italy, pp 280\u2013291","DOI":"10.1109\/ICSE.2015.48"},{"key":"10671_CR36","first-page":"280","volume-title":"37th IEEE\/ACM International Conference on Software Engineering","author":"L Li","year":"2015","unstructured":"Li L, Bartel A, Bissyand\u00e9 TF, Klein J, Traon YL, Arzt S, Rasthofer S, Bodden E, Octeau D, McDaniel PD (2015) Iccta: Detecting inter-component privacy leaks in android apps. 37th IEEE\/ACM International Conference on Software Engineering. IEEE Computer Society, Florence, Italy, ICSE, pp 280\u2013291"},{"key":"10671_CR37","doi-asserted-by":"crossref","unstructured":"Lu L, Li Z, Wu Z, Lee W, Jiang G (2012) CHEX: statically vetting android apps for component hijacking vulnerabilities. In: the ACM Conference on Computer and Communications Security, CCS, ACM, Raleigh, NC, USA, pp 229\u2013240","DOI":"10.1145\/2382196.2382223"},{"key":"10671_CR38","unstructured":"Zalewski M (2024) american fuzzy lop. https:\/\/lcamtuf.coredump.cx\/afl\/"},{"key":"10671_CR39","first-page":"229","volume-title":"the ACM Conference on Computer and Communications Security","author":"L Lu","year":"2012","unstructured":"Lu L, Li Z, Wu Z, Lee W, Jiang G (2012) CHEX: statically vetting android apps for component hijacking vulnerabilities. the ACM Conference on Computer and Communications Security. CCS, ACM, Raleigh, NC, USA, pp 229\u2013240"},{"key":"10671_CR40","doi-asserted-by":"crossref","unstructured":"Nethercote N, Seward J (2007) Valgrind: a framework for heavyweight dynamic binary instrumentation. In: Proceedings of the ACM SIGPLAN 2007 Conference on Programming Language Design and Implementation, ACM, San Diego, California, USA, pp 89\u2013100","DOI":"10.1145\/1250734.1250746"},{"key":"10671_CR41","doi-asserted-by":"publisher","unstructured":"Octeau D, Luchaup D, Dering ML, Jha S, McDaniel PD (2015) Composite constant propagation: Application to android inter-component communication analysis. In: Bertolino A, Canfora G, Elbaum SG (eds) 37th IEEE\/ACM International Conference on Software Engineering, ICSE 2015, Florence, Italy, May 16-24, 2015, Volume 1, IEEE Computer Society, pp 77\u201388, https:\/\/doi.org\/10.1109\/ICSE.2015.30, https:\/\/doi.org\/10.1109\/ICSE.2015.30","DOI":"10.1109\/ICSE.2015.30"},{"key":"10671_CR42","unstructured":"oleavr (2024) Frida dynamic instrumentation toolkit for developers, reverse-engineers, and security researchers. https:\/\/frida.re\/"},{"key":"10671_CR43","unstructured":"ORACLE (2024a) Design Overview - Resolving Native Method Names. https:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/guides\/jni\/spec\/design.html#wp615"},{"key":"10671_CR44","unstructured":"ORACLE (2024b) Jni apis and developer guides. https:\/\/docs.oracle.com\/javase\/8\/docs\/technotes\/guides\/jni\/"},{"key":"10671_CR45","unstructured":"ORACLE (2024) JNI Functions. https:\/\/docs.oracle.com\/javase\/8\/docs\/technotes\/guides\/jni\/spec\/functions.html"},{"key":"10671_CR46","unstructured":"ORACLE (2024a) Jni functions. https:\/\/docs.oracle.com\/javase\/8\/docs\/technotes\/guides\/jni\/spec\/functions.html#RegisterNatives"},{"key":"10671_CR47","unstructured":"ORACLE (2024b) JNI Functions - Global and Local References. https:\/\/docs.oracle.com\/javase\/7\/docs\/technotes\/guides\/jni\/spec\/functions.html#global_local"},{"key":"10671_CR48","unstructured":"ORACLE (2024c) resolving native method names. https:\/\/docs.oracle.com\/javase\/8\/docs\/technotes\/guides\/jni\/spec\/design.html#resolving_native_method_names"},{"key":"10671_CR49","unstructured":"ORACLE (2024) The Invocation API. https:\/\/docs.oracle.com\/javase\/8\/docs\/technotes\/guides\/jni\/spec\/invocation.html"},{"key":"10671_CR50","unstructured":"OWASP (2024) Timer-checks at Android Anti-Reversing Defenses. https:\/\/mas.owasp.org\/"},{"key":"10671_CR51","doi-asserted-by":"crossref","unstructured":"Pauck F, Bodden E, Wehrheim H (2018) Do android taint analysis tools keep their promises? In: Proceedings of the 2018 ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC\/SIGSOFT FSE, ACM, Lake Buena Vista, FL, USA, pp 331\u2013341","DOI":"10.1145\/3236024.3236029"},{"key":"10671_CR52","unstructured":"QEMU (2024) Qemu. https:\/\/www.qemu.org\/"},{"key":"10671_CR53","unstructured":"Qiling Framework (2024) Qiling framework. https:\/\/qiling.io\/"},{"key":"10671_CR54","doi-asserted-by":"crossref","unstructured":"Qiu L, Wang Y, Rubin J (2018) Analyzing the analyzers: Flowdroid\/iccta, amandroid, and droidsafe. In: Proceedings of ISSTA 2018, ACM, Amsterdam, The Netherlands, pp 176\u2013186","DOI":"10.1145\/3213846.3213873"},{"key":"10671_CR55","unstructured":"Quarkslab (2024) QBDI - QuarkslaB Dynamic binary Instrumentation. https:\/\/qbdi.quarkslab.com\/"},{"key":"10671_CR56","doi-asserted-by":"crossref","unstructured":"Rasthofer S, Arzt S, Miltenberger M, Bodden E (2016) Harvesting runtime values in android applications that feature anti-analysis techniques. In: 23rd Annual Network and Distributed System Security Symposium, NDSS 2016, San Diego, California, USA, February 21-24, 2016, The Internet Society","DOI":"10.14722\/ndss.2016.23066"},{"key":"10671_CR57","unstructured":"Rodrigo Chiossi (2024) Androidxref. http:\/\/androidxref.com\/"},{"key":"10671_CR58","doi-asserted-by":"crossref","unstructured":"Rodriguez SA, van\u00a0der Kouwe E (2019) Meizodon: Security benchmarking framework for static android malware detectors. In: Proceedings of the Third Central European Cybersecurity Conference, CECC, ACM, Munich, Germany, pp 8:1\u20138:7","DOI":"10.1145\/3360664.3360672"},{"key":"10671_CR59","unstructured":"S B Andarzian and B T Ladani (2022) SANT: static analysis of native threads for security vetting of android applications. ISC Int J Inf Secur 14(1):13\u201325"},{"key":"10671_CR60","doi-asserted-by":"publisher","unstructured":"Samhi J, Gao J, Daoudi N, Graux P, Hoyez H, Sun X, Allix K, Bissyand\u00e9 TF, Klein J (2022) Jucify: A step towards android code unification for enhanced static analysis. In: 44th IEEE\/ACM 44th International Conference on Software Engineering, ICSE 2022, Pittsburgh, PA, USA, May 25-27, 2022, ACM, pp 1232\u2013124https:\/\/doi.org\/10.1145\/3510003.3512766","DOI":"10.1145\/3510003.3512766"},{"issue":"Supplement","key":"10671_CR61","first-page":"301405","volume":"42","author":"C Shi","year":"2022","unstructured":"Shi C, Cheng CC, Guan Y (2022) Libdroid: Summarizing information flow of android native libraries via static analysis. Digit Investig 42(Supplement):301405","journal-title":"Digit Investig"},{"key":"10671_CR62","doi-asserted-by":"crossref","unstructured":"Shi C, Cheng CC, Guan Y (2022) Libdroid: Summarizing information flow of android native libraries via static analysis. Digit Investig 42(Supplement):301405","DOI":"10.1016\/j.fsidi.2022.301405"},{"key":"10671_CR63","doi-asserted-by":"publisher","unstructured":"Shoshitaishvili Y, Wang R, Salls C, Stephens N, Polino M, Dutcher A, Grosen J, Feng S, Hauser C, Kr\u00fcgel C, Vigna G (2016) SOK: (state of) the art of war: Offensive techniques in binary analysis. In: IEEE Symposium on Security and Privacy, SP 2016, San Jose, CA, USA, May 22-26, 2016, IEEE Computer Society, pp 138\u2013157, https:\/\/doi.org\/10.1109\/SP.2016.17","DOI":"10.1109\/SP.2016.17"},{"key":"10671_CR64","unstructured":"Skylot (2024) Jadx: Dex to java decompiler. https:\/\/github.com\/skylot\/jadx"},{"key":"10671_CR65","doi-asserted-by":"publisher","unstructured":"Srivastava P, Payer M (2021) Gramatron: effective grammar-aware fuzzing. In: Cadar C, Zhang X (eds) ISSTA \u201921: 30th ACM SIGSOFT International Symposium on Software Testing and Analysis, Virtual Event, Denmark, July 11-17, 2021, ACM, pp 244\u2013256, https:\/\/doi.org\/10.1145\/3460319.3464814","DOI":"10.1145\/3460319.3464814"},{"key":"10671_CR66","first-page":"165","volume-title":"7th ACM Conference on Security & Privacy in Wireless and Mobile Networks, WiSec\u201914","author":"M Sun","year":"2014","unstructured":"Sun M, Tan G (2014) Nativeguard: protecting android applications from third-party native libraries. In: \u00c1cs G, Martin AP, Martinovic I, Castelluccia C, Traynor P (eds) 7th ACM Conference on Security & Privacy in Wireless and Mobile Networks, WiSec\u201914. ACM, Oxford, United Kingdom, pp 165\u2013176"},{"key":"10671_CR67","doi-asserted-by":"crossref","unstructured":"Sun M, Tan G (2014) Nativeguard: protecting android applications from third-party native libraries. In: \u00c1cs G, Martin AP, Martinovic I, Castelluccia C, Traynor P (eds) 7th ACM Conference on Security & Privacy in Wireless and Mobile Networks, WiSec\u201914, ACM, Oxford, United Kingdom, pp 165\u2013176","DOI":"10.1145\/2627393.2627396"},{"key":"10671_CR68","first-page":"1","volume-title":"22nd Annual Network and Distributed System Security Symposium","author":"K Tam","year":"2015","unstructured":"Tam K, Khan SJ, Fattori A, Cavallaro L (2015) Copperdroid: Automatic reconstruction of android malware behaviors. 22nd Annual Network and Distributed System Security Symposium. The Internet Society, San Diego, California, USA, NDSS, pp 1\u201315"},{"key":"10671_CR69","doi-asserted-by":"crossref","unstructured":"Tam K, Khan SJ, Fattori A, Cavallaro L (2015) Copperdroid: Automatic reconstruction of android malware behaviors. In: 22nd Annual Network and Distributed System Security Symposium, NDSS, The Internet Society, San Diego, California, USA, pp 1\u201315","DOI":"10.14722\/ndss.2015.23145"},{"key":"10671_CR70","unstructured":"Vall\u00e9e-Rai R, Hendren LJ (1998) Jimple: Simplifying java bytecode for analyses and transformations. https:\/\/api.semanticscholar.org\/CorpusID:10529361"},{"key":"10671_CR71","unstructured":"Vall\u00e9e-Rai R, Co P, Gagnon E, Hendren LJ, Lam P, Sundaresan V (1999) Soot - a java bytecode optimization framework. In: MacKay SA, Johnson JH (eds) Proceedings of the 1999 conference of the Centre for Advanced Studies on Collaborative Research, November 8-11, 1999, Mississauga, Ontario, Canada, IBM, p\u00a013, https:\/\/dl.acm.org\/citation.cfm?id=782008"},{"key":"10671_CR72","unstructured":"VirusTotal (2024) Virustotal - home. https:\/\/www.virustotal.com\/"},{"key":"10671_CR73","doi-asserted-by":"publisher","unstructured":"Wei F, Roy S, Ou X, Robby (2014) Amandroid: A precise and general inter-component data flow analysis framework for security vetting of android apps. In: Ahn G, Yung M, Li N (eds) Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, Scottsdale, AZ, USA, November 3-7, 2014, ACM, pp 1329\u2013134https:\/\/doi.org\/10.1145\/2660267.2660357","DOI":"10.1145\/2660267.2660357"},{"key":"10671_CR74","doi-asserted-by":"crossref","unstructured":"Wei F, Lin X, Ou X, Chen T, Zhang X (2018a) JN-SAF: precise and efficient ndk\/jni-aware inter-language static analysis framework for security vetting of android applications with native code. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS, ACM, Toronto, ON, Canada, pp 1137\u20131150","DOI":"10.1145\/3243734.3243835"},{"key":"10671_CR75","first-page":"115","volume-title":"23rd IEEE International Symposium on Quality of Service","author":"L Xue","year":"2015","unstructured":"Xue L, Qian C, Luo X (2015) Androidperf: A cross-layer profiling system for android applications. 23rd IEEE International Symposium on Quality of Service. IWQoS, IEEE, Portland, OR, USA, pp 115\u2013124"},{"key":"10671_CR76","first-page":"289","volume-title":"26th USENIX Security Symposium","author":"L Xue","year":"2017","unstructured":"Xue L, Zhou Y, Chen T, Luo X, Gu G (2017) Malton: Towards on-device non-invasive mobile malware analysis for ART. In: Kirda E, Ristenpart T (eds) 26th USENIX Security Symposium. USENIX Security, USENIX Association, Vancouver, BC, Canada, pp 289\u2013306"},{"issue":"7","key":"10671_CR77","doi-asserted-by":"publisher","first-page":"1529","DOI":"10.1109\/TIFS.2017.2661723","volume":"12","author":"Y Xue","year":"2017","unstructured":"Xue Y, Meng G, Liu Y, Tan TH, Chen H, Sun J, Zhang J (2017) Auditing anti-malware tools by evolving android malware and dynamic loading technique. IEEE Trans Inf Forensics Secur 12(7):1529\u20131544","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"3","key":"10671_CR78","doi-asserted-by":"publisher","first-page":"814","DOI":"10.1109\/TIFS.2018.2866347","volume":"14","author":"L Xue","year":"2019","unstructured":"Xue L, Qian C, Zhou H, Luo X, Zhou Y, Shao Y, Chan ATS (2019) Ndroid: Toward tracking information flows across multiple android contexts. IEEE Trans Inf Forensics Secur 14(3):814\u2013828","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"10671_CR79","doi-asserted-by":"crossref","unstructured":"Xue Y, Meng G, Liu Y, Tan TH, Chen H, Sun J, Zhang J (2017b) Auditing anti-malware tools by evolving android malware and dynamic loading technique. IEEE Trans Inf Forensics Secur 12(7):1529\u20131544","DOI":"10.1109\/TIFS.2017.2661723"},{"key":"10671_CR80","unstructured":"Yan L, Yin H (2012) Droidscope: Seamlessly reconstructing the OS and dalvik semantic views for dynamic android malware analysis. In: Proceedings of the 21th USENIX Security Symposium, USENIX Association, Bellevue, WA, USA, pp 569\u2013584"},{"issue":"10","key":"10671_CR81","doi-asserted-by":"publisher","first-page":"4014","DOI":"10.1109\/TSE.2021.3109563","volume":"48","author":"J Zhang","year":"2022","unstructured":"Zhang J, Wang Y, Qiu L, Rubin J (2022) Analyzing android taint analysis tools: Flowdroid, amandroid, and droidsafe. IEEE Trans Software Eng 48(10):4014\u20134040","journal-title":"IEEE Trans Software Eng"},{"key":"10671_CR82","doi-asserted-by":"crossref","unstructured":"Zhou H, Wu S, Luo X, Wang T, Zhou Y, Zhang C, Cai H (2022) Ncscope: hardware-assisted analyzer for native code in android apps. ISSTA \u201922: 31st ACM SIGSOFT International Symposium on Software Testing and Analysis. ACM, South Korea, pp 629\u2013641","DOI":"10.1145\/3533767.3534410"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-025-10671-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-025-10671-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-025-10671-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,13]],"date-time":"2025-09-13T08:53:35Z","timestamp":1757753615000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-025-10671-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,21]]},"references-count":82,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,9]]}},"alternative-id":["10671"],"URL":"https:\/\/doi.org\/10.1007\/s10664-025-10671-9","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,21]]},"assertion":[{"value":"5 May 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 May 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}},{"value":"The authors of this article declared that they have no conflict of interest.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of Interest"}},{"value":"The authors declare they have no financial interests.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of financial interests"}}],"article-number":"113"}}