{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T21:02:24Z","timestamp":1776200544456,"version":"3.50.1"},"reference-count":48,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1016\/j.jisa.2026.104451","type":"journal-article","created":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T22:34:20Z","timestamp":1774650860000},"page":"104451","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["A novel detection method for unknown android malware via image representation"],"prefix":"10.1016","volume":"99","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4616-6519","authenticated-orcid":false,"given":"Shi","family":"Dong","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-5077-2116","authenticated-orcid":false,"given":"Longhui","family":"Shu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3388-0094","authenticated-orcid":false,"given":"Junjie","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.jisa.2026.104451_bib0001","unstructured":"GoogleGoogle Play Store: number of apps2025. https:\/\/www.statista.com\/statistics\/26621\/number-of-available-applications-in-the-google-play-store\/."},{"key":"10.1016\/j.jisa.2026.104451_bib0002","unstructured":"AV-TEST-The Independent IT-Security Institute. AV-ATLAS - Malware & PUA. https:\/\/portal.av-atlas.org\/malware\/statistics."},{"issue":"2","key":"10.1016\/j.jisa.2026.104451_bib0003","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3574158","article-title":"Demystifying hidden sensitive operations in android apps","volume":"32","author":"Sun","year":"2023","journal-title":"ACM Trans Softw Eng Method"},{"key":"10.1016\/j.jisa.2026.104451_bib0004","doi-asserted-by":"crossref","first-page":"182","DOI":"10.1016\/j.cose.2019.02.005","article-title":"Rethinking anti-emulation techniques for large-scale software deployment","volume":"83","author":"Jang","year":"2019","journal-title":"Comput Secur"},{"issue":"1","key":"10.1016\/j.jisa.2026.104451_bib0005","doi-asserted-by":"crossref","first-page":"617","DOI":"10.1109\/TCYB.2022.3164625","article-title":"Cyber code intelligence for android malware detection","volume":"53","author":"Qiu","year":"2022","journal-title":"IEEE Trans Cybern"},{"key":"10.1016\/j.jisa.2026.104451_bib0006","doi-asserted-by":"crossref","first-page":"32765","DOI":"10.1109\/ACCESS.2019.2891588","article-title":"A machine learning framework for domain generation algorithm-based malware detection","volume":"7","author":"Li","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104451_bib0007","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102833","article-title":"An in-depth review of machine learning based android malware detection","author":"Muzaffar","year":"2022","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104451_bib0008","doi-asserted-by":"crossref","first-page":"124579","DOI":"10.1109\/ACCESS.2020.3006143","article-title":"A review of android malware detection approaches based on machine learning","volume":"8","author":"Liu","year":"2020","journal-title":"IEEE Access"},{"issue":"5","key":"10.1016\/j.jisa.2026.104451_bib0009","doi-asserted-by":"crossref","first-page":"1330","DOI":"10.1109\/TETCI.2023.3281833","article-title":"Android malware detection methods based on convolutional neural network: a survey","volume":"7","author":"Shu","year":"2023","journal-title":"IEEE Trans Emerging Topics Comput Intell"},{"issue":"4","key":"10.1016\/j.jisa.2026.104451_bib0010","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3092566","article-title":"Software vulnerability analysis and discovery using machine-learning and data-mining techniques: a survey","volume":"50","author":"Ghaffarian","year":"2017","journal-title":"ACM Comput Surv (CSUR)"},{"key":"10.1016\/j.jisa.2026.104451_bib0011","doi-asserted-by":"crossref","DOI":"10.1016\/j.cosrev.2021.100365","article-title":"A survey of android application and malware hardening","volume":"39","author":"Sihag","year":"2021","journal-title":"Comput Sci Rev"},{"key":"10.1016\/j.jisa.2026.104451_bib0012","doi-asserted-by":"crossref","DOI":"10.1016\/j.sysarc.2022.102452","article-title":"Camodroid: an android application analysis environment resilient against sandbox evasion","volume":"125","author":"Faghihi","year":"2022","journal-title":"J Syst Archit"},{"key":"10.1016\/j.jisa.2026.104451_bib0013","unstructured":"Webb G.I., Lee L.K., Petitjean F., Goethals B.. Understanding concept drift. arXiv preprint arXiv: 1704003622017;."},{"issue":"6","key":"10.1016\/j.jisa.2026.104451_bib0014","first-page":"1","article-title":"A survey of android malware detection with deep neural models","volume":"53","author":"Qiu","year":"2020","journal-title":"ACM Comput Surv(CSUR)"},{"key":"10.1016\/j.jisa.2026.104451_bib0015","doi-asserted-by":"crossref","first-page":"181102","DOI":"10.1109\/ACCESS.2020.3028370","article-title":"Review of android malware detection based on deep learning","volume":"8","author":"Wang","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104451_bib0016","article-title":"A comprehensive survey on deep learning based malware detection techniques","volume":"47","author":"Gopinath","year":"2023","journal-title":"Comput Sci Rev"},{"issue":"1","key":"10.1016\/j.jisa.2026.104451_bib0017","doi-asserted-by":"crossref","first-page":"683","DOI":"10.1007\/s10489-022-03523-2","article-title":"Self-attention based convolutional-LSTM for android malware detection using network traffics grayscale image","volume":"53","author":"Shen","year":"2023","journal-title":"Appl Intell"},{"key":"10.1016\/j.jisa.2026.104451_bib0018","doi-asserted-by":"crossref","first-page":"354","DOI":"10.1016\/j.patcog.2017.10.013","article-title":"Recent advances in convolutional neural networks","volume":"77","author":"Gu","year":"2018","journal-title":"Pattern Recognit"},{"issue":"1","key":"10.1016\/j.jisa.2026.104451_bib0019","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1109\/TPAMI.2022.3152247","article-title":"A survey on vision transformer","volume":"45","author":"Han","year":"2022","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"10.1016\/j.jisa.2026.104451_bib0020","doi-asserted-by":"crossref","first-page":"428","DOI":"10.1109\/ACCESS.2024.3519524","article-title":"A survey on adversarial attacks for malware analysis","volume":"13","author":"Aryal","year":"2024","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104451_bib0021","series-title":"Adversary-aware machine learning models for malware detection systems","author":"Darwaish","year":"2022"},{"key":"10.1016\/j.jisa.2026.104451_bib0022","series-title":"Proceedings of the 19th international conference on availability, reliability and security","first-page":"1","article-title":"Image-based detection and classification of android malware through CNN models","author":"Aldini","year":"2024"},{"issue":"2","key":"10.1016\/j.jisa.2026.104451_bib0023","doi-asserted-by":"crossref","first-page":"157","DOI":"10.1007\/s11416-019-00346-7","article-title":"Deep learning for image-based mobile malware detection","volume":"16","author":"Mercaldo","year":"2020","journal-title":"J Comput Virology Hacking Techniques"},{"issue":"1","key":"10.1016\/j.jisa.2026.104451_bib0024","doi-asserted-by":"crossref","first-page":"172","DOI":"10.3390\/app12010172","article-title":"Ransomware detection using the dynamic analysis and machine learning: a survey and research directions","volume":"12","author":"Urooj","year":"2021","journal-title":"Appl Sci"},{"key":"10.1016\/j.jisa.2026.104451_bib0025","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103177","article-title":"Recmal: rectify the malware family label via hybrid analysis","volume":"128","author":"Yang","year":"2023","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104451_bib0026","doi-asserted-by":"crossref","first-page":"599","DOI":"10.1016\/j.neucom.2018.09.102","article-title":"Learning to detect android malware via opcode sequences","volume":"396","author":"Pekta\u015f","year":"2020","journal-title":"Neurocomputing"},{"key":"10.1016\/j.jisa.2026.104451_bib0027","doi-asserted-by":"crossref","first-page":"24240","DOI":"10.1109\/ACCESS.2022.3156083","article-title":"Deep-layer clustering to identify permission usage patterns of android app categories","volume":"10","author":"Namrud","year":"2022","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104451_bib0028","series-title":"NDSS","first-page":"50","article-title":"Hey, you, get off of my market: detecting malicious apps in official and alternative android markets","volume":"vol. 25","author":"Zhou","year":"2012"},{"key":"10.1016\/j.jisa.2026.104451_bib0029","series-title":"Ndss","first-page":"23","article-title":"Drebin: effective and explainable detection of android malware in your pocket","volume":"vol. 14","author":"Arp","year":"2014"},{"key":"10.1016\/j.jisa.2026.104451_bib0030","series-title":"Proceedings of the 10th international conference on mobile systems, applications, and services","first-page":"281","article-title":"RiskRanker: scalable and accurate zero-day android malware detection","author":"Grace","year":"2012"},{"key":"10.1016\/j.jisa.2026.104451_bib0031","series-title":"Proceedings of the 6th international conference on security of information and networks","first-page":"152","article-title":"Androsimilar: robust statistical feature signature for android malware detection","author":"Faruki","year":"2013"},{"key":"10.1016\/j.jisa.2026.104451_bib0032","series-title":"Proceedings of the 22nd ACM SIGSOFT international symposium on foundations of software engineering","first-page":"576","article-title":"ApposCopy: semantics-based detection of android malware through static analysis","author":"Feng","year":"2014"},{"key":"10.1016\/j.jisa.2026.104451_bib0033","unstructured":"Feng Y., Bastani O., Martins R., Dillig I., Anand S.. Automated synthesis of semantic malware signatures using maximum satisfiability. arXiv preprint arXiv: 1608062542016;."},{"key":"10.1016\/j.jisa.2026.104451_bib0034","series-title":"Proceedings of the 11th ACM on asia conference on computer and communications security","first-page":"365","article-title":"Mystique: evolving android malware for auditing anti-malware tools","author":"Meng","year":"2016"},{"key":"10.1016\/j.jisa.2026.104451_bib0035","doi-asserted-by":"crossref","first-page":"1222","DOI":"10.1007\/s10664-017-9539-8","article-title":"A multi-view context-aware approach to android malware detection and malicious code localization","volume":"23","author":"Narayanan","year":"2018","journal-title":"Emp Softw Eng"},{"key":"10.1016\/j.jisa.2026.104451_bib0036","doi-asserted-by":"crossref","DOI":"10.1016\/j.asoc.2020.106089","article-title":"An adaptive framework against android privilege escalation threats using deep learning and semi-supervised approaches","volume":"89","author":"Sharmeen","year":"2020","journal-title":"Appl Soft Comput"},{"key":"10.1016\/j.jisa.2026.104451_bib0037","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102670","article-title":"Robust deep learning early alarm prediction model based on the behavioural smell for android malware","volume":"116","author":"Amer","year":"2022","journal-title":"Comput Secur"},{"issue":"3","key":"10.1016\/j.jisa.2026.104451_bib0038","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3442588","article-title":"Intdroid: android malware detection based on API intimacy analysis","volume":"30","author":"Zou","year":"2021","journal-title":"ACM Trans Softw Eng Methodol (TOSEM)"},{"key":"10.1016\/j.jisa.2026.104451_bib0039","doi-asserted-by":"crossref","first-page":"147156","DOI":"10.1109\/ACCESS.2019.2946392","article-title":"A3CM: automatic capability annotation for android malware","volume":"7","author":"Qiu","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104451_bib0040","unstructured":"Mariconti E., Onwuzurike L., Andriotis P., De Cristofaro E., Ross G., Stringhini G.. Mamadroid: Detecting android malware by building markov chains of behavioral models. arXiv preprint arXiv: 1612044332016;."},{"key":"10.1016\/j.jisa.2026.104451_bib0041","series-title":"2016 International conference on cyber security and protection of digital services (cyber security)","first-page":"1","article-title":"N-Opcode analysis for android malware classification and categorization","author":"Kang","year":"2016"},{"issue":"5","key":"10.1016\/j.jisa.2026.104451_bib0042","doi-asserted-by":"crossref","first-page":"7744","DOI":"10.1109\/TII.2024.3363016","article-title":"Android malware detection method based on CNN and DNN bybrid mechanism","volume":"20","author":"Dong","year":"2024","journal-title":"IEEE Trans Ind Inf"},{"key":"10.1016\/j.jisa.2026.104451_bib0043","article-title":"Enhanced unknown android malware detection using LG-PN: a local\u2013global fusion approach in prototypical networks","volume":"91","author":"Shu","year":"2025","journal-title":"J Infn Secur Appl"},{"issue":"12","key":"10.1016\/j.jisa.2026.104451_bib0044","doi-asserted-by":"crossref","first-page":"21816","DOI":"10.1109\/JIOT.2024.3376635","article-title":"Advancing malware detection in network traffic with self-paced class incremental learning","volume":"11","author":"Xu","year":"2024","journal-title":"IEEE Internet Things J"},{"key":"10.1016\/j.jisa.2026.104451_bib0045","doi-asserted-by":"crossref","first-page":"2999","DOI":"10.1109\/TIFS.2024.3516565","article-title":"MalFSCIL: a few-shot class-incremental learning approach for malware detection","volume":"20","author":"Chai","year":"2024","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"10.1016\/j.jisa.2026.104451_bib0046","series-title":"International conference on machine learning","first-page":"10347","article-title":"Training data-efficient image transformers & distillation through attention","author":"Touvron","year":"2021"},{"key":"10.1016\/j.jisa.2026.104451_bib0047","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","first-page":"558","article-title":"Bag of tricks for image classification with convolutional neural networks","author":"He","year":"2019"},{"key":"10.1016\/j.jisa.2026.104451_bib0048","series-title":"Proceedings of the IEEE conference on computer vision and pattern recognition","first-page":"4510","article-title":"MobileNetv2: inverted residuals and linear bottlenecks","author":"Sandler","year":"2018"}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626000815?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626000815?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,4,14]],"date-time":"2026-04-14T20:06:48Z","timestamp":1776197208000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2214212626000815"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":48,"alternative-id":["S2214212626000815"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104451","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A novel detection method for unknown android malware via image representation","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104451","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"104451"}}