{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T22:02:11Z","timestamp":1780437731034,"version":"3.54.1"},"reference-count":59,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T00:00:00Z","timestamp":1779321600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"funder":[{"DOI":"10.13039\/100014440","name":"Espa\u00f1a Ministerio de Ciencia e Innovaci\u00f3n","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100014440","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100014440","name":"Spain Ministry of Science Innovation and Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100014440","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100003339","name":"Spanish National Research Council","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100003339","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Expert Systems with Applications"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.eswa.2026.132961","type":"journal-article","created":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T15:51:49Z","timestamp":1779292309000},"page":"132961","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["DeepTrust: Multi-step classification through dissimilar adversarial representations for robust android malware detection"],"prefix":"10.1016","volume":"329","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-9708-9906","authenticated-orcid":false,"given":"Daniel","family":"Pulido-Cort\u00e1zar","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2448-1297","authenticated-orcid":false,"given":"Daniel","family":"Gibert","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8366-1458","authenticated-orcid":false,"given":"Felip","family":"Many\u00e0","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.eswa.2026.132961_bib0001","series-title":"Security and privacy in communication networks","first-page":"86","article-title":"DroidAPIMiner: Mining API-level features for robust malware detection in android","author":"Aafer","year":"2013"},{"key":"10.1016\/j.eswa.2026.132961_bib0002","series-title":"Database theory \u2013 ICDT 2001","first-page":"420","article-title":"On the surprising behavior of distance metrics in high dimensional space","volume":"vol. 1973","author":"Aggarwal","year":"2001"},{"key":"10.1016\/j.eswa.2026.132961_sbref0003","series-title":"Proceedings of the 25th ACM SIGKDD international conference on knowledge discovery & data mining","first-page":"2623","article-title":"Optuna: A next-generation hyperparameter optimization framework","author":"Akiba","year":"2019"},{"key":"10.1016\/j.eswa.2026.132961_bib0004","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2019.101663","article-title":"DL-droid: Deep learning based android malware detection using real devices","volume":"89","author":"Alzaylaee","year":"2020","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132961_sbref0005","series-title":"Proceedings of the italian conference on cybersecurity (ITASEC 2022), Rome, Italy, June 20\u201323, 2022","first-page":"169","article-title":"Robust machine learning for malware detection over time","volume":"vol. 3260","author":"Angioni","year":"2022"},{"key":"10.1016\/j.eswa.2026.132961_bib0006","doi-asserted-by":"crossref","DOI":"10.1016\/j.softx.2020.100403","article-title":"Obfuscapk: An open-source black-box obfuscation tool for android apps","volume":"11","author":"Aonzo","year":"2020","journal-title":"SoftwareX"},{"key":"10.1016\/j.eswa.2026.132961_bib0007","unstructured":"AppBrain (2026). Number of android applications on google play (May 2026). https:\/\/www.appbrain.com\/stats\/number-of-android-apps. Accessed: 2026-05-10."},{"key":"10.1016\/j.eswa.2026.132961_bib0008","series-title":"21st Annual network and distributed system security symposium, NDSS","article-title":"DREBIN: Effective and explainable detection of android malware in your pocket","author":"Arp","year":"2014"},{"key":"10.1016\/j.eswa.2026.132961_bib0009","doi-asserted-by":"crossref","DOI":"10.1016\/j.pmcj.2023.101859","article-title":"Hybrid machine learning model for malware analysis in android apps","volume":"97","author":"Bashir","year":"2024","journal-title":"Pervasive and Mobile Computing"},{"issue":"2","key":"10.1016\/j.eswa.2026.132961_bib0010","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1109\/MSEC.2023.3236543","article-title":"Are machine learning models for malware detection ready for prime time?","volume":"21","author":"Cavallaro","year":"2023","journal-title":"IEEE Security & Privacy"},{"key":"10.1016\/j.eswa.2026.132961_sbref0011","series-title":"Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining","first-page":"785","article-title":"XGBoost: A scalable tree boosting system","author":"Chen","year":"2016"},{"key":"10.1016\/j.eswa.2026.132961_sbref0012","series-title":"32nd USENIX security symposium (USENIX security 23)","first-page":"1127","article-title":"Continuous learning for android malware detection","author":"Chen","year":"2023"},{"key":"10.1016\/j.eswa.2026.132961_bib0013","unstructured":"Corporate, I. (2025). Smartphone market share. https:\/\/www.idc.com\/promo\/smartphone-marketshare. Accessed: 2025-06-13."},{"issue":"4","key":"10.1016\/j.eswa.2026.132961_sbref0014","doi-asserted-by":"crossref","first-page":"711","DOI":"10.1109\/TDSC.2017.2700270","article-title":"Yes, machine learning can be more secure! a case study on android malware detection","volume":"16","author":"Demontis","year":"2019","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.eswa.2026.132961_bib0015","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.121155","article-title":"Maldetect: A classifier fusion approach for detection of android malware","volume":"235","author":"Dhalaria","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132961_bib0016","first-page":"2171","article-title":"DEAP: Evolutionary algorithms made easy","volume":"13","author":"Fortin","year":"2012","journal-title":"Journal of Machine Learning Research"},{"issue":"5","key":"10.1016\/j.eswa.2026.132961_sbref0017","doi-asserted-by":"crossref","first-page":"1189","DOI":"10.1214\/aos\/1013203451","article-title":"Greedy function approximation: A gradient boosting machine","volume":"29","author":"Friedman","year":"2001","journal-title":"The Annals of Statistics"},{"issue":"3","key":"10.1016\/j.eswa.2026.132961_bib0018","doi-asserted-by":"crossref","DOI":"10.1145\/3162625","article-title":"Lightweight, obfuscation-resilient detection and family identification of android malware","volume":"26","author":"Garcia","year":"2018","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"10.1016\/j.eswa.2026.132961_bib0019","unstructured":"Ghiani, D., Angioni, D., Piras, G., Sotgiu, A., Minnei, L., Gupta, S., Pintor, M., Roli, F., & Biggio, B. (2025). Regression-aware continual learning for android malware detection. https:\/\/arxiv.org\/abs\/2507.18313."},{"key":"10.1016\/j.eswa.2026.132961_sbref0020","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2019.102526","article-title":"The rise of machine learning for detection and classification of malware: Research developments, trends and challenges","volume":"153","author":"Gibert","year":"2020","journal-title":"Journal of Network and Computer Applications"},{"key":"10.1016\/j.eswa.2026.132961_bib0021","series-title":"3rd International conference on learning representations, ICLR","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2015"},{"key":"10.1016\/j.eswa.2026.132961_bib0022","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103654","article-title":"Machine learning for android malware detection: Mission accomplished? A comprehensive review of open challenges and future perspectives","volume":"138","author":"Guerra-Manzanares","year":"2024","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132961_bib0023","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.122255","article-title":"Detection approaches for android malware: Taxonomy and review analysis","volume":"238","author":"Haidros Rahima Manzil","year":"2024","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132961_bib0024","series-title":"The fourteenth international conference on learning representations","article-title":"LAMDA: A longitudinal android malware benchmark for concept drift analysis","author":"Haque","year":"2026"},{"key":"10.1016\/j.eswa.2026.132961_bib0025","series-title":"Proceedings of 3rd international conference on document analysis and recognition","first-page":"278","article-title":"Random decision forests","volume":"vol. 1","author":"Ho","year":"1995"},{"key":"10.1016\/j.eswa.2026.132961_bib0026","unstructured":"Kingma, D. P., & Ba, J. (2014). Adam: A method for stochastic optimization. 10.48550\/ARXIV.1412.6980."},{"key":"10.1016\/j.eswa.2026.132961_bib0027","series-title":"Proceedings of the 36th international conference on machine learning","first-page":"3519","article-title":"Similarity of neural network representations revisited","volume":"vol. 97","author":"Kornblith","year":"2019"},{"issue":"1","key":"10.1016\/j.eswa.2026.132961_bib0028","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/2133360.2133363","article-title":"Isolation-based anomaly detection","volume":"6","author":"Liu","year":"2012","journal-title":"ACM Transactions on Knowledge Discovery from Data"},{"key":"10.1016\/j.eswa.2026.132961_bib0029","doi-asserted-by":"crossref","first-page":"124579","DOI":"10.1109\/ACCESS.2020.3006143","article-title":"A review of android malware detection approaches based on machine learning","volume":"8","author":"Liu","year":"2020","journal-title":"IEEE Access"},{"issue":"10","key":"10.1016\/j.eswa.2026.132961_bib0030","doi-asserted-by":"crossref","first-page":"1399","DOI":"10.1016\/S0893-6080(99)00073-8","article-title":"Ensemble learning via negative correlation","volume":"12","author":"Liu","year":"1999","journal-title":"Neural Networks"},{"key":"10.1016\/j.eswa.2026.132961_bib0031","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2025.129446","article-title":"Cadroid: A cross-combination attention based framework for android malware detection","volume":"297","author":"Ma","year":"2026","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132961_bib0032","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2024.124633","article-title":"A lightweight deep learning-based android malware detection framework","volume":"255","author":"Ma","year":"2024","journal-title":"Expert Systems with Applications"},{"issue":"86","key":"10.1016\/j.eswa.2026.132961_bib0033","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"van der Maaten","year":"2008","journal-title":"Journal of Machine Learning Research"},{"issue":"3","key":"10.1016\/j.eswa.2026.132961_bib0034","doi-asserted-by":"crossref","first-page":"424","DOI":"10.1016\/j.icte.2021.09.003","article-title":"A Bayesian probability model for android malware detection","volume":"8","author":"Mat","year":"2022","journal-title":"ICT Express"},{"issue":"29","key":"10.1016\/j.eswa.2026.132961_bib0035","doi-asserted-by":"crossref","first-page":"861","DOI":"10.21105\/joss.00861","article-title":"Umap: Uniform manifold approximation and projection","volume":"3","author":"McInnes","year":"2018","journal-title":"Journal of Open Source Software"},{"key":"10.1016\/j.eswa.2026.132961_bib0036","series-title":"Proceedings of the seventh ACM on conference on data and application security and privacy","first-page":"301","article-title":"Deep android malware detection","author":"McLaughlin","year":"2017"},{"key":"10.1016\/j.eswa.2026.132961_bib0037","doi-asserted-by":"crossref","DOI":"10.1016\/j.pmcj.2023.101849","article-title":"Efficient concept drift handling for batch android malware detection models","volume":"96","author":"Molina-Coronado","year":"2023","journal-title":"Pervasive and Mobile Computing"},{"key":"10.1016\/j.eswa.2026.132961_bib0038","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102996","article-title":"Towards a fair comparison and realistic evaluation framework of android malware detectors based on static analysis and machine learning","volume":"124","author":"Molina-Coronado","year":"2023","journal-title":"Computers & Security"},{"key":"10.1016\/j.eswa.2026.132961_bib0039","doi-asserted-by":"crossref","DOI":"10.1016\/j.jnca.2024.104094","article-title":"Light up that droid! on the effectiveness of static analysis features against app obfuscation for android malware detection","volume":"235","author":"Molina-Coronado","year":"2025","journal-title":"Journal of Network and Computer Applications"},{"key":"10.1016\/j.eswa.2026.132961_bib0040","series-title":"Advances in neural information processing systems","article-title":"Insights on representational similarity in neural networks with canonical correlation","volume":"vol. 31","author":"Morcos","year":"2018"},{"key":"10.1016\/j.eswa.2026.132961_bib0041","series-title":"When does label smoothing help?","author":"M\u00fcller","year":"2019"},{"key":"10.1016\/j.eswa.2026.132961_bib0042","series-title":"Advances in neural information processing systems","article-title":"When does label smoothing help?","volume":"vol. 32","author":"M\u00fcller","year":"2019"},{"issue":"1","key":"10.1016\/j.eswa.2026.132961_bib0043","doi-asserted-by":"crossref","first-page":"291","DOI":"10.1007\/s10462-021-10033-z","article-title":"A review on weight initialization strategies for neural networks","volume":"55","author":"Narkhede","year":"2022","journal-title":"Artificial Intelligence Review"},{"key":"10.1016\/j.eswa.2026.132961_bib0044","doi-asserted-by":"crossref","DOI":"10.1016\/j.iswa.2023.200318","article-title":"Dl-amdet: Deep learning-based malware detector for android","volume":"21","author":"Nasser","year":"2024","journal-title":"Intelligent Systems with Applications"},{"issue":"2","key":"10.1016\/j.eswa.2026.132961_bib0045","doi-asserted-by":"crossref","DOI":"10.1145\/3313391","article-title":"Mamadroid: Detecting android malware by building markov chains of behavioral models (Extended version)","volume":"22","author":"Onwuzurike","year":"2019","journal-title":"ACM Transactions on Privacy and Security"},{"key":"10.1016\/j.eswa.2026.132961_bib0046","doi-asserted-by":"crossref","first-page":"178","DOI":"10.1016\/j.neucom.2022.01.062","article-title":"Explaining adversarial vulnerability with a data sparsity hypothesis","volume":"495","author":"Paknezhad","year":"2022","journal-title":"Neurocomputing"},{"key":"10.1016\/j.eswa.2026.132961_bib0047","series-title":"28th USENIX security symposium (USENIX security 19)","first-page":"729","article-title":"TESSERACT: Eliminating experimental bias in malware classification across space and time","author":"Pendlebury","year":"2019"},{"issue":"6","key":"10.1016\/j.eswa.2026.132961_bib0048","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3417978","article-title":"A survey of android malware detection with deep neural models","volume":"53","author":"Qiu","year":"2021","journal-title":"ACM Computing Surveys"},{"key":"10.1016\/j.eswa.2026.132961_bib0049","unstructured":"Ruder, S. (2016). An overview of gradient descent optimization algorithms. 10.48550\/ARXIV.1609.04747."},{"key":"10.1016\/j.eswa.2026.132961_bib0050","unstructured":"Secure, E. L. o., & (ELSA), S. A. I. (2025). Cybersecurity - robust android malware detection benchmark. https:\/\/benchmarks.elsa-ai.eu\/?ch=6&com=introduction. Accessed: 2025-06-13."},{"key":"10.1016\/j.eswa.2026.132961_bib0051","unstructured":"Secure, I. C. o., & SaTML, T. M. L. I. (2025). Robust android malware detection competition. https:\/\/ramd-competition.github.io\/."},{"key":"10.1016\/j.eswa.2026.132961_bib0052","series-title":"Proceedings of the 33rd international conference on neural information processing systems","article-title":"Adversarial training for free!","author":"Shafahi","year":"2019"},{"issue":"1","key":"10.1016\/j.eswa.2026.132961_bib0053","doi-asserted-by":"crossref","first-page":"955","DOI":"10.1007\/s10586-017-0981-6","article-title":"Android malware detection method based on naive bayes and permission correlation algorithm","volume":"21","author":"Shang","year":"2018","journal-title":"Cluster Computing"},{"key":"10.1016\/j.eswa.2026.132961_bib0054","doi-asserted-by":"crossref","first-page":"84","DOI":"10.1016\/j.inffus.2021.11.011","article-title":"Tabular data: Deep learning is not all you need","volume":"81","author":"Shwartz-Ziv","year":"2022","journal-title":"Information Fusion"},{"key":"10.1016\/j.eswa.2026.132961_bib0055","unstructured":"Xu, B., Wang, N., Chen, T., & Li, M. (2015). Empirical evaluation of rectified activations in convolutional network. 10.48550\/ARXIV.1505.00853."},{"key":"10.1016\/j.eswa.2026.132961_bib0056","series-title":"2021\u202fIEEE\/CVF Conference on computer vision and pattern recognition (CVPR)","first-page":"14294","article-title":"Positive-congruent training: Towards regression-free model updates","author":"Yan","year":"2021"},{"key":"10.1016\/j.eswa.2026.132961_bib0057","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"3903","article-title":"Revisiting knowledge distillation via label smoothing regularization","author":"Yuan","year":"2020"},{"key":"10.1016\/j.eswa.2026.132961_bib0058","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1016\/j.eswa.2019.04.064","article-title":"A multi-level deep learning system for malware detection","volume":"133","author":"Zhong","year":"2019","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.eswa.2026.132961_bib0059","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.120952","article-title":"A multi-model ensemble learning framework for imbalanced android malware detection","volume":"234","author":"Zhu","year":"2023","journal-title":"Expert Systems with Applications"}],"container-title":["Expert Systems with Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426018737?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0957417426018737?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T21:09:32Z","timestamp":1780434572000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0957417426018737"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":59,"alternative-id":["S0957417426018737"],"URL":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132961","relation":{},"ISSN":["0957-4174"],"issn-type":[{"value":"0957-4174","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"DeepTrust: Multi-step classification through dissimilar adversarial representations for robust android malware detection","name":"articletitle","label":"Article Title"},{"value":"Expert Systems with Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.eswa.2026.132961","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"132961"}}