{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T16:46:31Z","timestamp":1783788391935,"version":"3.55.0"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Australian Research","award":["DE170101081"],"award-info":[{"award-number":["DE170101081"]}]},{"name":"Australian Research","award":["DP180102828"],"award-info":[{"award-number":["DP180102828"]}]},{"name":"Australian Research","award":["LP150100671"],"award-info":[{"award-number":["LP150100671"]}]},{"name":"Australian Research","award":["DP180100106"],"award-info":[{"award-number":["DP180100106"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61772055"],"award-info":[{"award-number":["61772055"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2020]]},"DOI":"10.1109\/tifs.2019.2947861","type":"journal-article","created":{"date-parts":[[2019,10,16]],"date-time":"2019-10-16T20:12:41Z","timestamp":1571256761000},"page":"3401-3414","source":"Crossref","is-referenced-by-count":51,"title":["Familial Clustering for Weakly-Labeled Android Malware Using Hybrid Representation Learning"],"prefix":"10.1109","volume":"15","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4787-1658","authenticated-orcid":false,"given":"Yanxin","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yulei","family":"Sui","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0794-527X","authenticated-orcid":false,"given":"Shirui","family":"Pan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zheng","family":"Zheng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Baodi","family":"Ning","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2211-8176","authenticated-orcid":false,"given":"Ivor","family":"Tsang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wanlei","family":"Zhou","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref39","year":"2007","journal-title":"RandomForest"},{"key":"ref38","year":"2007","journal-title":"La Decision"},{"key":"ref33","year":"2010","journal-title":"Android Asset Packaging Tool"},{"key":"ref32","year":"2012","journal-title":"VirusShare"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23247"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/1541880.1541882"},{"key":"ref37","year":"2007","journal-title":"knn"},{"key":"ref36","year":"2007","journal-title":"SVM"},{"key":"ref35","year":"2007","journal-title":"MLPClassifier"},{"key":"ref34","year":"2014","journal-title":"Topological Anomaly Detection"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2016.52"},{"key":"ref27","first-page":"175","article-title":"Achieving accuracy and scalability simultaneously in detecting application clones on Android markets","author":"chen","year":"2014","journal-title":"Proc ICSE"},{"key":"ref29","first-page":"3111","article-title":"Distributed representations of words and phrases and their compositionality","author":"mikolov","year":"2013","journal-title":"Proc NIPS"},{"key":"ref2","year":"2018","journal-title":"AVTEST"},{"key":"ref1","author":"murphy","year":"2018","journal-title":"Android - Statistics & Facts"},{"key":"ref20","first-page":"246","article-title":"Hierarchical probabilistic neural network language model","volume":"5","author":"morin","year":"2005","journal-title":"Proc AISTATS"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2007.30"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884877"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-60876-1_12"},{"key":"ref23","article-title":"Rebooting research on detecting repackaged Android apps: Literature review and benchmark","author":"li","year":"0","journal-title":"IEEE Trans Softw Eng"},{"key":"ref26","first-page":"659","article-title":"Finding unknown malice in 10 seconds: Mass vetting for new threats at the Google-play scale","volume":"15","author":"chen","year":"2015","journal-title":"Proc USENIX"},{"key":"ref25","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1145\/2771783.2771795","article-title":"WuKong: A scalable and accurate two-phase approach to Android app clone detection","author":"wang","year":"2015","journal-title":"Proc ISSTA"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660359"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2879302"},{"key":"ref56","year":"2018","journal-title":"Cosine similarity"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/2736277.2741093"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939754"},{"key":"ref53","first-page":"142","article-title":"On the lack of consensus in anti-virus decisions: Metrics and insights on building ground truths of Android malware","author":"hurier","year":"2016","journal-title":"Proc DIMVA"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/2931037.2931043"},{"key":"ref10","first-page":"2111","article-title":"Network representation learning with rich text information","author":"yang","year":"2015","journal-title":"Proc IJCAI"},{"key":"ref11","first-page":"1895","article-title":"Tri-party deep network representation","author":"pan","year":"2016","journal-title":"Proc AAAI"},{"key":"ref40","year":"2007","journal-title":"sklearn"},{"key":"ref12","first-page":"1024","article-title":"Inductive representation learning on large graphs","author":"hamilton","year":"2017","journal-title":"Proc NIPS"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3220000"},{"key":"ref14","first-page":"1188","article-title":"Distributed representations of sentences and documents","author":"le","year":"2014","journal-title":"Proc ICML"},{"key":"ref15","article-title":"A comprehensive survey on graph neural networks","author":"wu","year":"2019","journal-title":"arXiv 1901 00596"},{"key":"ref16","first-page":"192","article-title":"Android malware clustering through malicious payload mining","author":"li","year":"2017","journal-title":"Proc RAID"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2833443"},{"key":"ref18","first-page":"1","article-title":"Learning factorized multimodal representations","author":"tsai","year":"2019","journal-title":"Proc ICLR"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/2623330.2623732"},{"key":"ref4","first-page":"14","author":"kuo","year":"2005","journal-title":"The Common Malware Enumeration Initiative"},{"key":"ref3","year":"1991","journal-title":"Caro naming convention"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2017.57"},{"key":"ref5","first-page":"230","article-title":"AVCLASS: A tool for massive malware labeling","author":"sebasti\u00e1n","year":"2016","journal-title":"Proc RAID"},{"key":"ref8","year":"2009","journal-title":"Pluralityvoting"},{"key":"ref7","year":"2018","journal-title":"VirusTotal"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-11203-9_10"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2013.50"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23353"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.50"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2866319"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/3097983.3098026"},{"key":"ref42","year":"2019","journal-title":"Command and Control Server (c&c)"},{"key":"ref41","year":"2016","journal-title":"TriAda"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/2635868.2635869"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-04283-1_6"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/8833568\/08871171.pdf?arnumber=8871171","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,4,27]],"date-time":"2022-04-27T17:00:15Z","timestamp":1651078815000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8871171\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"references-count":56,"URL":"https:\/\/doi.org\/10.1109\/tifs.2019.2947861","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]}}}