{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T20:07:46Z","timestamp":1778789266147,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":55,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,10,30]],"date-time":"2020-10-30T00:00:00Z","timestamp":1604016000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Natural Science Foundation of China","award":["61972297, U1636107"],"award-info":[{"award-number":["61972297, U1636107"]}]},{"name":"National Science Foundation (NSF)","award":["CNS-1850434"],"award-info":[{"award-number":["CNS-1850434"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,10,30]]},"DOI":"10.1145\/3372297.3423341","type":"proceedings-article","created":{"date-parts":[[2021,3,4]],"date-time":"2021-03-04T16:20:42Z","timestamp":1614874842000},"page":"535-549","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":26,"title":["VAHunt: Warding Off New Repackaged Android Malware in App-Virtualization's Clothing"],"prefix":"10.1145","author":[{"given":"Luman","family":"Shi","sequence":"first","affiliation":[{"name":"Wuhan University, Wuhan, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiang","family":"Ming","sequence":"additional","affiliation":[{"name":"University of Texas at Arlington, Arlington, TX, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jianming","family":"Fu","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guojun","family":"Peng","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dongpeng","family":"Xu","sequence":"additional","affiliation":[{"name":"University of New Hampshire, Durham, NH, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kun","family":"Gao","sequence":"additional","affiliation":[{"name":"Wuhan Antiy Information Technology, Wuhan, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuanchen","family":"Pan","sequence":"additional","affiliation":[{"name":"Wuhan Antiy Information Technology, Wuhan, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,11,2]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"David Lo, and Lorenzo Cavallaro. Understanding Android App Piggybacking: A Systematic Study of Malicious Code Grafting","author":"Li Li","year":"2017","unstructured":"Li Li , Daoyuan Li , Tegawend\u00eb F. Bissyand\u00eb , Jacques Klein , Yves Le Traon , David Lo, and Lorenzo Cavallaro. Understanding Android App Piggybacking: A Systematic Study of Malicious Code Grafting . IEEE Transactions on Information Forensics and Security , 12(6), June 2017 . Li Li, Daoyuan Li, Tegawend\u00eb F. Bissyand\u00eb, Jacques Klein, Yves Le Traon, David Lo, and Lorenzo Cavallaro. Understanding Android App Piggybacking: A Systematic Study of Malicious Code Grafting. IEEE Transactions on Information Forensics and Security, 12(6), June 2017."},{"key":"e_1_3_2_2_2_1","volume-title":"December","author":"Khanmohammadi Kobra","year":"2019","unstructured":"Kobra Khanmohammadi , Neda Ebrahimi , Abdelwahab Hamou-Lhadj , and Rapha\u00ebl Khoury . Empirical Study of Android Repackaged Applications. Empirical Software Engineering, 24(6) , December 2019 . Kobra Khanmohammadi, Neda Ebrahimi, Abdelwahab Hamou-Lhadj, and Rapha\u00ebl Khoury. Empirical Study of Android Repackaged Applications. Empirical Software Engineering, 24(6), December 2019."},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2019.2901679"},{"key":"e_1_3_2_2_4_1","unstructured":"LBE Tech. How Parallel Space helps you run multiple accounts on Android. http:\/\/blog.parallelspace-app.com\/how-parallel-space-helps-you-run-multiple-accounts-on-android\/ July 2016.  LBE Tech. How Parallel Space helps you run multiple accounts on Android. http:\/\/blog.parallelspace-app.com\/how-parallel-space-helps-you-run-multiple-accounts-on-android\/ July 2016."},{"key":"e_1_3_2_2_5_1","volume-title":"https:\/\/github.com\/asLody\/VirtualApp","year":"2019","unstructured":"asLody. VirtualApp. https:\/\/github.com\/asLody\/VirtualApp , 2019 . asLody. VirtualApp. https:\/\/github.com\/asLody\/VirtualApp, 2019."},{"key":"e_1_3_2_2_6_1","volume-title":"https:\/\/github.com\/DroidPluginTeam\/DroidPlugin","year":"2019","unstructured":"Qihoo360. DroidPlugin. https:\/\/github.com\/DroidPluginTeam\/DroidPlugin , 2019 . Qihoo360. DroidPlugin. https:\/\/github.com\/DroidPluginTeam\/DroidPlugin, 2019."},{"key":"e_1_3_2_2_7_1","volume-title":"May","author":"C.","year":"2015","unstructured":"John C. Mobile App Virtualization: Why the Best Architecture (Should) Always Win. https:\/\/sierraware.com\/blog\/?p=75 , May 2015 . JohnC. Mobile App Virtualization: Why the Best Architecture (Should) Always Win. https:\/\/sierraware.com\/blog\/?p=75, May 2015."},{"key":"e_1_3_2_2_8_1","volume-title":"December","author":"Price Dan","year":"2019","unstructured":"Dan Price . How to Run Multiple Copies of the Same App on Android. https:\/\/www.makeuseof.com\/tag\/run-multiple-app-copies-android\/ , December 2019 . Dan Price. How to Run Multiple Copies of the Same App on Android. https:\/\/www.makeuseof.com\/tag\/run-multiple-app-copies-android\/, December 2019."},{"key":"e_1_3_2_2_9_1","volume-title":"August","author":"Birch Joe","year":"2018","unstructured":"Joe Birch . Modularizing Android Applications. https:\/\/medium.com\/google-developer-experts\/modularizing-android-applications-9e2d18f244a0 , August 2018 . Joe Birch. Modularizing Android Applications. https:\/\/medium.com\/google-developer-experts\/modularizing-android-applications-9e2d18f244a0, August 2018."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1201\/9780429262968"},{"key":"e_1_3_2_2_11_1","volume-title":"Enable multidex for apps with over 64K methods. https:\/\/developer.android.com\/studio\/build\/multidex","year":"2019","unstructured":"Google. Enable multidex for apps with over 64K methods. https:\/\/developer.android.com\/studio\/build\/multidex , 2019 . Google. Enable multidex for apps with over 64K methods. https:\/\/developer.android.com\/studio\/build\/multidex, 2019."},{"key":"e_1_3_2_2_12_1","volume-title":"PluginPhantom: New Android Trojan Abuses \"DroidPlugin\" Framework. https:\/\/dwz.cn\/tsm8kSF4","author":"Zheng Cong","year":"2016","unstructured":"Cong Zheng and Tongbo Luo . PluginPhantom: New Android Trojan Abuses \"DroidPlugin\" Framework. https:\/\/dwz.cn\/tsm8kSF4 , 2016 . Cong Zheng and Tongbo Luo. PluginPhantom: New Android Trojan Abuses \"DroidPlugin\" Framework. https:\/\/dwz.cn\/tsm8kSF4, 2016."},{"key":"e_1_3_2_2_13_1","volume-title":"January","author":"Spring Tom","year":"2017","unstructured":"Tom Spring . Apps Carrying HummingBad Variant Booted From Google Play. https:\/\/threatpost.com\/hummingbad-variant-booted-from-google-play\/123280\/ , January 2017 . Tom Spring. Apps Carrying HummingBad Variant Booted From Google Play. https:\/\/threatpost.com\/hummingbad-variant-booted-from-google-play\/123280\/, January 2017."},{"key":"e_1_3_2_2_14_1","volume-title":"BlackHat Asia","author":"Luo Tongbo","year":"2017","unstructured":"Tongbo Luo , Cong Zheng , Zhi Xu , and Xin Ouyang . Anti-Plugin : Don't Let Your App Play as an Android Plugin . BlackHat Asia , 2017 . Tongbo Luo, Cong Zheng, Zhi Xu, and Xin Ouyang. Anti-Plugin: Don't Let Your App Play as an Android Plugin. BlackHat Asia, 2017."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3203422.3203425"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3309697.3331517"},{"key":"e_1_3_2_2_17_1","volume-title":"Risky: Shared-Everything Threat Mitigation in Dual-Instance Apps. In Proceedings of the 17th ACM International Conference on Mobile Systems, Applications, and Services (Mobisys'19)","author":"Shi Luman","year":"2019","unstructured":"Luman Shi , Jianming Fu , Zhengwei Guo , and Jiang Ming . \" Jekyll and Hyde\" is Risky: Shared-Everything Threat Mitigation in Dual-Instance Apps. In Proceedings of the 17th ACM International Conference on Mobile Systems, Applications, and Services (Mobisys'19) , 2019 . Luman Shi, Jianming Fu, Zhengwei Guo, and Jiang Ming. \"Jekyll and Hyde\" is Risky: Shared-Everything Threat Mitigation in Dual-Instance Apps. In Proceedings of the 17th ACM International Conference on Mobile Systems, Applications, and Services (Mobisys'19), 2019."},{"key":"e_1_3_2_2_18_1","volume-title":"Heng Yin. Parallel Space Traveling: A Security Analysis of App-Level Virtualization in Android. In Proceedings of the 25th ACM Symposium on Access Control Models and Technologies (SACMAT'20)","author":"Dai Deshun","year":"2020","unstructured":"Deshun Dai , Ruixuan Li , Junwei Tang , Ali Davanian , and Heng Yin. Parallel Space Traveling: A Security Analysis of App-Level Virtualization in Android. In Proceedings of the 25th ACM Symposium on Access Control Models and Technologies (SACMAT'20) , 2020 . Deshun Dai, Ruixuan Li, Junwei Tang, Ali Davanian, and Heng Yin. Parallel Space Traveling: A Security Analysis of App-Level Virtualization in Android. In Proceedings of the 25th ACM Symposium on Access Control Models and Technologies (SACMAT'20), 2020."},{"key":"e_1_3_2_2_19_1","volume-title":"Peng Ning. Detecting Repackaged Smartphone Applications in Third-Party Android Marketplaces. In Proceedings of the 2nd ACM Conference on Data and Application Security and Privacy (CODASPY'12)","author":"Zhou Wu","year":"2012","unstructured":"Wu Zhou , Yajin Zhou , Xuxian Jiang , and Peng Ning. Detecting Repackaged Smartphone Applications in Third-Party Android Marketplaces. In Proceedings of the 2nd ACM Conference on Data and Application Security and Privacy (CODASPY'12) , 2012 . Wu Zhou, Yajin Zhou, Xuxian Jiang, and Peng Ning. Detecting Repackaged Smartphone Applications in Third-Party Android Marketplaces. In Proceedings of the 2nd ACM Conference on Data and Application Security and Privacy (CODASPY'12), 2012."},{"key":"e_1_3_2_2_20_1","volume-title":"Scalable Detection of Piggybacked Mobile Applications. In Proceedings of the 3rd ACM Conference on Data and Application Security and Privacy (CODASPY'13)","author":"Zhou Wu","year":"2013","unstructured":"Wu Zhou , Yajin Zhou , Michael Grace , Xuxian Jiang , and Shihong Zou . Fast , Scalable Detection of Piggybacked Mobile Applications. In Proceedings of the 3rd ACM Conference on Data and Application Security and Privacy (CODASPY'13) , 2013 . Wu Zhou, Yajin Zhou, Michael Grace, Xuxian Jiang, and Shihong Zou. Fast, Scalable Detection of Piggybacked Mobile Applications. In Proceedings of the 3rd ACM Conference on Data and Application Security and Privacy (CODASPY'13), 2013."},{"key":"e_1_3_2_2_21_1","volume-title":"Proceedings of the 18th European Symposium on Research in Computer Security (ESORICS'13)","author":"Crussell Jonathan","year":"2013","unstructured":"Jonathan Crussell , Clint Gibler , and Hao Chen . AnDarwin : Scalable Detection of Semantically Similar Android Applications. In Jason Crampton, Sushil Jajodia, and Keith Mayes, editors , Proceedings of the 18th European Symposium on Research in Computer Security (ESORICS'13) , 2013 . Jonathan Crussell, Clint Gibler, and Hao Chen. AnDarwin: Scalable Detection of Semantically Similar Android Applications. In Jason Crampton, Sushil Jajodia, and Keith Mayes, editors, Proceedings of the 18th European Symposium on Research in Computer Security (ESORICS'13), 2013."},{"key":"e_1_3_2_2_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2568225.2568286"},{"key":"e_1_3_2_2_23_1","volume-title":"Peng Liu. ViewDroid: Towards Obfuscation-Resilient Mobile Application Repackaging Detection. In Proceedings of the 2014 ACM Conference on Security and Privacy in Wireless & Mobile Networks (WiSec'14)","author":"Zhang Fangfang","year":"2014","unstructured":"Fangfang Zhang , Heqing Huang , Sencun Zhu , Dinghao Wu , and Peng Liu. ViewDroid: Towards Obfuscation-Resilient Mobile Application Repackaging Detection. In Proceedings of the 2014 ACM Conference on Security and Privacy in Wireless & Mobile Networks (WiSec'14) , 2014 . Fangfang Zhang, Heqing Huang, Sencun Zhu, Dinghao Wu, and Peng Liu. ViewDroid: Towards Obfuscation-Resilient Mobile Application Repackaging Detection. In Proceedings of the 2014 ACM Conference on Security and Privacy in Wireless & Mobile Networks (WiSec'14), 2014."},{"key":"e_1_3_2_2_24_1","volume-title":"Raina Samuel. Self-Hiding Behavior in Android Apps: Detection and Characterization. In Proceedings of the 40th International Conference on Software Engineering (ICSE'18)","author":"Shan Zhiyong","year":"2018","unstructured":"Zhiyong Shan , Iulian Neamtiu , and Raina Samuel. Self-Hiding Behavior in Android Apps: Detection and Characterization. In Proceedings of the 40th International Conference on Software Engineering (ICSE'18) , 2018 . Zhiyong Shan, Iulian Neamtiu, and Raina Samuel. Self-Hiding Behavior in Android Apps: Detection and Characterization. In Proceedings of the 40th International Conference on Software Engineering (ICSE'18), 2018."},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594299"},{"key":"e_1_3_2_2_26_1","unstructured":"Antiy AVL Mobile Security. Guarding the Security of Mobile Intelligence Era. https:\/\/www.avlsec.com\/en\/home [online].  Antiy AVL Mobile Security. Guarding the Security of Mobile Intelligence Era. https:\/\/www.avlsec.com\/en\/home [online]."},{"key":"e_1_3_2_2_27_1","volume-title":"Virtual Machines: Versatile Platforms for Systems and Processes (The Morgan Kaufmann Series in Computer Architecture and Design)","author":"Smith Jim","year":"2005","unstructured":"Jim Smith and Ravi Nair . Virtual Machines: Versatile Platforms for Systems and Processes (The Morgan Kaufmann Series in Computer Architecture and Design) . Morgan Kaufmann Publishers Inc ., San Francisco, CA, USA, 2005 . Jim Smith and Ravi Nair. Virtual Machines: Versatile Platforms for Systems and Processes (The Morgan Kaufmann Series in Computer Architecture and Design). Morgan Kaufmann Publishers Inc., San Francisco, CA, USA, 2005."},{"key":"e_1_3_2_2_28_1","unstructured":"VMware. VMware Workstation. https:\/\/www.vmware.com\/ [online].  VMware. VMware Workstation. https:\/\/www.vmware.com\/ [online]."},{"key":"e_1_3_2_2_29_1","volume-title":"Fast and Portable Dynamic Translator. In Proceedings of the 2005 Annual Conference on USENIX Annual Technical Conference (ATC'05)","author":"Bellard Fabrice","year":"2005","unstructured":"Fabrice Bellard . QEMU , a Fast and Portable Dynamic Translator. In Proceedings of the 2005 Annual Conference on USENIX Annual Technical Conference (ATC'05) , 2005 . Fabrice Bellard. QEMU, a Fast and Portable Dynamic Translator. In Proceedings of the 2005 Annual Conference on USENIX Annual Technical Conference (ATC'05), 2005."},{"key":"e_1_3_2_2_30_1","volume-title":"Styp-Rekowsky. Boxify: Full-fledged App Sandboxing for Stock Android. In Proceedings of the 24th USENIX Conference on Security Symposium (USENIX Security'15)","author":"Backes Michael","year":"2015","unstructured":"Michael Backes , Sven Bugiel , Christian Hammer , Oliver Schranz , and Philipp von Styp-Rekowsky. Boxify: Full-fledged App Sandboxing for Stock Android. In Proceedings of the 24th USENIX Conference on Security Symposium (USENIX Security'15) , 2015 . Michael Backes, Sven Bugiel, Christian Hammer, Oliver Schranz, and Philipp von Styp-Rekowsky. Boxify: Full-fledged App Sandboxing for Stock Android. In Proceedings of the 24th USENIX Conference on Security Symposium (USENIX Security'15), 2015."},{"key":"e_1_3_2_2_31_1","volume-title":"Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM'15)","author":"Bianchi Antonio","year":"2015","unstructured":"Antonio Bianchi , Yanick Fratantonio , Christopher Kruegel , and Giovanni Vigna . NJAS : Sandboxing Unmodified Applications in non-rooted Devices Running stock Android . In Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM'15) , 2015 . Antonio Bianchi, Yanick Fratantonio, Christopher Kruegel, and Giovanni Vigna. NJAS: Sandboxing Unmodified Applications in non-rooted Devices Running stock Android. In Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices (SPSM'15), 2015."},{"key":"e_1_3_2_2_32_1","volume-title":"Erich Stuntebeck. DroidPill: Pwn Your Daily-Use Apps. In Proceedings of the 12nd ACM ASIA Conference on Computer and Communications Security (ASIACCS'17)","author":"Xuan Chaoting","year":"2017","unstructured":"Chaoting Xuan , Gong Chen , and Erich Stuntebeck. DroidPill: Pwn Your Daily-Use Apps. In Proceedings of the 12nd ACM ASIA Conference on Computer and Communications Security (ASIACCS'17) , 2017 . Chaoting Xuan, Gong Chen, and Erich Stuntebeck. DroidPill: Pwn Your Daily-Use Apps. In Proceedings of the 12nd ACM ASIA Conference on Computer and Communications Security (ASIACCS'17), 2017."},{"key":"e_1_3_2_2_33_1","volume-title":"Jean-Pierre Hubaux. HideMyApp: Hiding the Presence of Sensitive Apps on Android. In Proceedings of the 28th USENIX Conference on Security Symposium (USENIX Security'19)","author":"Anh Pham Thi Van","year":"2019","unstructured":"Thi Van Anh Pham , Italo Ivan Dacosta Petrocelli , Eleonora Losiouk , John Stephan , K\u00e9vin Huguenin , and Jean-Pierre Hubaux. HideMyApp: Hiding the Presence of Sensitive Apps on Android. In Proceedings of the 28th USENIX Conference on Security Symposium (USENIX Security'19) , 2019 . Thi Van Anh Pham, Italo Ivan Dacosta Petrocelli, Eleonora Losiouk, John Stephan, K\u00e9vin Huguenin, and Jean-Pierre Hubaux. HideMyApp: Hiding the Presence of Sensitive Apps on Android. In Proceedings of the 28th USENIX Conference on Security Symposium (USENIX Security'19), 2019."},{"key":"e_1_3_2_2_34_1","volume-title":"Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications. In Proceedings of the 21th Network and Distributed System Security Symposium (NDSS'14)","author":"Poeplau Sebastian","year":"2014","unstructured":"Sebastian Poeplau , Yanick Fratantonio , Antonio Bianchi , Christopher Kruegel , and Giovanni Vigna . Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications. In Proceedings of the 21th Network and Distributed System Security Symposium (NDSS'14) , 2014 . Sebastian Poeplau, Yanick Fratantonio, Antonio Bianchi, Christopher Kruegel, and Giovanni Vigna. Execute This! Analyzing Unsafe and Malicious Dynamic Code Loading in Android Applications. In Proceedings of the 21th Network and Distributed System Security Symposium (NDSS'14), 2014."},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2017.14"},{"key":"e_1_3_2_2_36_1","unstructured":"Pew Research Center. An Analysis of Android App Permissions. http:\/\/www.pewinternet.org\/2015\/11\/10\/an-analysis-of-android-app-permissions\/ 2015.  Pew Research Center. An Analysis of Android App Permissions. http:\/\/www.pewinternet.org\/2015\/11\/10\/an-analysis-of-android-app-permissions\/ 2015."},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/2568225.2568301"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274707"},{"key":"e_1_3_2_2_39_1","volume-title":"Intents and Intent Filters. https:\/\/developer.android.com\/guide\/components\/intents-filters","year":"2019","unstructured":"Google. Intents and Intent Filters. https:\/\/developer.android.com\/guide\/components\/intents-filters , 2019 . Google. Intents and Intent Filters. https:\/\/developer.android.com\/guide\/components\/intents-filters, 2019."},{"key":"e_1_3_2_2_40_1","volume-title":"https:\/\/androidaapt.com\/","author":"Android","year":"2019","unstructured":"Android AAPT. https:\/\/androidaapt.com\/ , 2019 . Android AAPT. https:\/\/androidaapt.com\/, 2019."},{"key":"e_1_3_2_2_41_1","volume-title":"http:\/\/manpages.ubuntu.com\/manpages\/xenial\/man1\/dexdump.1.html","author":"Android","year":"2019","unstructured":"Android dexdump. http:\/\/manpages.ubuntu.com\/manpages\/xenial\/man1\/dexdump.1.html , 2019 . Android dexdump. http:\/\/manpages.ubuntu.com\/manpages\/xenial\/man1\/dexdump.1.html, 2019."},{"key":"e_1_3_2_2_42_1","volume-title":"Proceedings of the 25th ACM SIGSAC Conference on Computer and Communications Security (CCS'18)","author":"Chao-Chun Cheng Chris","year":"2018","unstructured":"Chris Chao-Chun Cheng , Chen Shi , Neil Zhenqiang Gong , and Yong Guan . EviHunter : Identifying Digital Evidence in the Permanent Storage of Android Devices via Static Analysis . In Proceedings of the 25th ACM SIGSAC Conference on Computer and Communications Security (CCS'18) , 2018 . Chris Chao-Chun Cheng, Chen Shi, Neil Zhenqiang Gong, and Yong Guan. EviHunter: Identifying Digital Evidence in the Permanent Storage of Android Devices via Static Analysis. In Proceedings of the 25th ACM SIGSAC Conference on Computer and Communications Security (CCS'18), 2018."},{"key":"e_1_3_2_2_43_1","volume-title":"Google Developer Content Policy. https:\/\/play.google.com\/about\/developer-content-policy.html","year":"2020","unstructured":"Google. Google Developer Content Policy. https:\/\/play.google.com\/about\/developer-content-policy.html , 2020 . Google. Google Developer Content Policy. https:\/\/play.google.com\/about\/developer-content-policy.html, 2020."},{"key":"e_1_3_2_2_44_1","volume-title":"Nasty Android Malware that Infected Millions Returns to Google Play Store. https:\/\/thehackernews.com\/2017\/01\/hummingbad-android-malware.html","author":"Khandelwal Swati","year":"2017","unstructured":"Swati Khandelwal . Nasty Android Malware that Infected Millions Returns to Google Play Store. https:\/\/thehackernews.com\/2017\/01\/hummingbad-android-malware.html , 2017 . Swati Khandelwal. Nasty Android Malware that Infected Millions Returns to Google Play Store. https:\/\/thehackernews.com\/2017\/01\/hummingbad-android-malware.html, 2017."},{"key":"e_1_3_2_2_45_1","volume-title":"Chinese Ad Company That Turned Out to Be a Cyber Crime Group Is Back with \"a Whale of a Tale\". https:\/\/wccftech.com\/hummingwhale-android-malware\/","author":"Shaikh Rafia","year":"2017","unstructured":"Rafia Shaikh . Chinese Ad Company That Turned Out to Be a Cyber Crime Group Is Back with \"a Whale of a Tale\". https:\/\/wccftech.com\/hummingwhale-android-malware\/ , 2017 . Rafia Shaikh. Chinese Ad Company That Turned Out to Be a Cyber Crime Group Is Back with \"a Whale of a Tale\". https:\/\/wccftech.com\/hummingwhale-android-malware\/, 2017."},{"key":"e_1_3_2_2_46_1","volume-title":"A New Trend in Android Adware: Abusing Android Plugin Frameworks. https:\/\/researchcenter.paloaltonetworks.com\/2017\/03\/unit42-new-trend-android-adware-abusing-android-plugin-frameworks\/","author":"Zheng Cong","year":"2017","unstructured":"Cong Zheng , Wenjun Hu , and Zhi Xu . A New Trend in Android Adware: Abusing Android Plugin Frameworks. https:\/\/researchcenter.paloaltonetworks.com\/2017\/03\/unit42-new-trend-android-adware-abusing-android-plugin-frameworks\/ , 2017 . Cong Zheng, Wenjun Hu, and Zhi Xu. A New Trend in Android Adware: Abusing Android Plugin Frameworks. https:\/\/researchcenter.paloaltonetworks.com\/2017\/03\/unit42-new-trend-android-adware-abusing-android-plugin-frameworks\/, 2017."},{"key":"e_1_3_2_2_47_1","unstructured":"Aswathi B.L. Sensitivity Specificity Accuracy and the relationship between them. http:\/\/www.lifenscience.com\/bioinformatics\/sensitivity-specificity-accuracy-and 2009.  Aswathi B.L. Sensitivity Specificity Accuracy and the relationship between them. http:\/\/www.lifenscience.com\/bioinformatics\/sensitivity-specificity-accuracy-and 2009."},{"key":"e_1_3_2_2_48_1","volume-title":"Shallow Copy and Deep Copy. https:\/\/javapapers.com\/core-java\/java-clone-shallow-copy-and-deep-copy\/","author":"Clone Java","year":"2014","unstructured":"Joe. Java Clone , Shallow Copy and Deep Copy. https:\/\/javapapers.com\/core-java\/java-clone-shallow-copy-and-deep-copy\/ , 2014 . Joe. Java Clone, Shallow Copy and Deep Copy. https:\/\/javapapers.com\/core-java\/java-clone-shallow-copy-and-deep-copy\/, 2014."},{"key":"e_1_3_2_2_49_1","volume-title":"SafetyNet Attestation API. https:\/\/developer.android.com\/training\/safetynet\/attestation","year":"2019","unstructured":"Google. SafetyNet Attestation API. https:\/\/developer.android.com\/training\/safetynet\/attestation , 2019 . Google. SafetyNet Attestation API. https:\/\/developer.android.com\/training\/safetynet\/attestation, 2019."},{"key":"e_1_3_2_2_50_1","volume-title":"Dinghao Wu. Adaptive Unpacking of Android Apps. In Proceedings of the 39th International Conference on Software Engineering (ICSE'17)","author":"Xue Lei","year":"2017","unstructured":"Lei Xue , Xiapu Luo , Le Yu , Shuai Wang , and Dinghao Wu. Adaptive Unpacking of Android Apps. In Proceedings of the 39th International Conference on Software Engineering (ICSE'17) , 2017 . Lei Xue, Xiapu Luo, Le Yu, Shuai Wang, and Dinghao Wu. Adaptive Unpacking of Android Apps. In Proceedings of the 39th International Conference on Software Engineering (ICSE'17), 2017."},{"key":"e_1_3_2_2_51_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23296"},{"key":"e_1_3_2_2_52_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24177-7_15"},{"key":"e_1_3_2_2_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363193"},{"key":"e_1_3_2_2_54_1","volume-title":"Xposed Module Repository. https:\/\/repo.xposed.info\/","year":"2019","unstructured":"rovo89. Xposed Module Repository. https:\/\/repo.xposed.info\/ , 2019 . rovo89. Xposed Module Repository. https:\/\/repo.xposed.info\/, 2019."},{"key":"e_1_3_2_2_55_1","volume-title":"Malware posing as dual instance app steals users' Twitter credentials. https:\/\/blog.avast.com\/malware-posing-as-dual-instance-app-steals-users-twitter-credentials","author":"Intelligence Team Avast Threat","year":"2016","unstructured":"Avast Threat Intelligence Team . Malware posing as dual instance app steals users' Twitter credentials. https:\/\/blog.avast.com\/malware-posing-as-dual-instance-app-steals-users-twitter-credentials , 2016 . Avast Threat Intelligence Team. Malware posing as dual instance app steals users' Twitter credentials. https:\/\/blog.avast.com\/malware-posing-as-dual-instance-app-steals-users-twitter-credentials, 2016."}],"event":{"name":"CCS '20: 2020 ACM SIGSAC Conference on Computer and Communications Security","location":"Virtual Event USA","acronym":"CCS '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3423341","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3372297.3423341","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:02:20Z","timestamp":1750197740000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3372297.3423341"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,10,30]]},"references-count":55,"alternative-id":["10.1145\/3372297.3423341","10.1145\/3372297"],"URL":"https:\/\/doi.org\/10.1145\/3372297.3423341","relation":{},"subject":[],"published":{"date-parts":[[2020,10,30]]},"assertion":[{"value":"2020-11-02","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}