{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:32:09Z","timestamp":1783791129587,"version":"3.55.0"},"reference-count":40,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T00:00:00Z","timestamp":1751328000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Natural ScienceFoundation of China","award":["62125205"],"award-info":[{"award-number":["62125205"]}]},{"name":"National Natural ScienceFoundation of China","award":["U23A20303"],"award-info":[{"award-number":["U23A20303"]}]},{"DOI":"10.13039\/501100015401","name":"Key Research and Development Projects of Shaanxi Province","doi-asserted-by":"publisher","award":["2023KXJ-190"],"award-info":[{"award-number":["2023KXJ-190"]}],"id":[{"id":"10.13039\/501100015401","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100015401","name":"Key Research and Development Projects of Shaanxi Province","doi-asserted-by":"publisher","award":["2024GX-YBXM-072"],"award-info":[{"award-number":["2024GX-YBXM-072"]}],"id":[{"id":"10.13039\/501100015401","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100018925","name":"Overseas Expertise Introduction Center for Discipline Innovation of Food Nutrition and Human Health","doi-asserted-by":"publisher","award":["B16037"],"award-info":[{"award-number":["B16037"]}],"id":[{"id":"10.13039\/501100018925","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007268","name":"Washington University in St. Louis","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100007268","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,7]]},"DOI":"10.1109\/tdsc.2024.3525049","type":"journal-article","created":{"date-parts":[[2025,1,6]],"date-time":"2025-01-06T14:59:35Z","timestamp":1736175575000},"page":"3208-3223","source":"Crossref","is-referenced-by-count":5,"title":["Understanding the Bad Development Practices of Android Custom Permissions in the Wild"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-3260-4530","authenticated-orcid":false,"given":"Xiaohan","family":"Zhang","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks and School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6196-7598","authenticated-orcid":false,"given":"Zhiyuan","family":"Yu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Washington University in St. Louis, St. Louis, MO, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5583-4155","authenticated-orcid":false,"given":"Xinghua","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks and School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5603-1322","authenticated-orcid":false,"given":"Cen","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9116-2694","authenticated-orcid":false,"given":"Cong","family":"Sun","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks and School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0670-2161","authenticated-orcid":false,"given":"Ning","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Engineering, Washington University in St. Louis, St. Louis, MO, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3491-8146","authenticated-orcid":false,"given":"Robert H.","family":"Deng","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2976556"},{"key":"ref2","first-page":"468","article-title":"AndroZoo: Collecting millions of Android apps for the research community","volume-title":"Proc. IEEE\/ACM 13th Work. Conf. Mining Softw. Repositories","author":"Allix"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382222"},{"key":"ref4","article-title":"[mail.ru android] typo in permission name allows to write contacts without user knowledge","year":"2022"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2015.69"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053004"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387469"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/1999995.2000018"},{"key":"ref9","volume-title":"Qualitative Inquiry and Research Design: Choosing Among Five Approaches","author":"Creswell","year":"2016"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/MOBILESoft.2017.24"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653691"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897914"},{"key":"ref13","article-title":"Permission re-delegation: Attacks and defenses","volume-title":"Proc. 20th USENIX Secur. Symp.","author":"Felt"},{"key":"ref14","article-title":"Common vulnerability scoring system version 4.0","year":"2024"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00013"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23089"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.03.011"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2017.41"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3230833.3232825"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.48"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/2931037.2931044"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00070"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2014.6883666"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2017.12"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382223"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/2420950.2420958"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.30"},{"key":"ref28","first-page":"543","article-title":"Effective inter-component communication mapping in Android: An essential step towards holistic security analysis","volume-title":"Proc. 22nd USENIX Secur. Symp.","author":"Octeau"},{"key":"ref29","first-page":"603","article-title":"50 ways to leak your data: An exploration of apps\u2019 circumvention of the Android permissions system","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Reardon"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-021-05875-1"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00126"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23210"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1925805.1925818"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2019.00035"},{"key":"ref35","article-title":"Evolution-aware runtime permission misuse detection for Android apps","author":"Wang","year":"2022"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3148258"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3183575"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238164"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560607"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516689"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11077775\/10826575.pdf?arnumber=10826575","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,14]],"date-time":"2025-07-14T17:45:28Z","timestamp":1752515128000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10826575\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7]]},"references-count":40,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2024.3525049","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7]]}}}