{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T16:21:22Z","timestamp":1770222082412,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","license":[{"start":{"date-parts":[[2020,7,8]],"date-time":"2020-07-08T00:00:00Z","timestamp":1594166400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"Major Scientific and Technological Innovation Projects of Shandong Province, China","award":["2017CXGC0704,2018CXGC0708,2019JZZY010132"],"award-info":[{"award-number":["2017CXGC0704,2018CXGC0708,2019JZZY010132"]}]},{"name":"National Natural Science Foundation of China","award":["61902148,91546203"],"award-info":[{"award-number":["61902148,91546203"]}]},{"name":"Key Science Technology Project of Shandong Province","award":["2015GGX101046"],"award-info":[{"award-number":["2015GGX101046"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2020,7,8]]},"DOI":"10.1145\/3395351.3399346","type":"proceedings-article","created":{"date-parts":[[2020,7,22]],"date-time":"2020-07-22T04:29:10Z","timestamp":1595392150000},"page":"144-154","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":23,"title":["An empirical study of potentially malicious third-party libraries in Android apps"],"prefix":"10.1145","author":[{"given":"Zicheng","family":"Zhang","sequence":"first","affiliation":[{"name":"Shandong University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenrui","family":"Diao","sequence":"additional","affiliation":[{"name":"Shandong University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chengyu","family":"Hu","sequence":"additional","affiliation":[{"name":"Shandong University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shanqing","family":"Guo","sequence":"additional","affiliation":[{"name":"Shandong University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chaoshun","family":"Zuo","sequence":"additional","affiliation":[{"name":"The Ohio State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Li","family":"Li","sequence":"additional","affiliation":[{"name":"Monash University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2020,7,21]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Apple's App Store infected with XcodeGhost malware in China. Retrieved","year":"2020","unstructured":"2015. Apple's App Store infected with XcodeGhost malware in China. Retrieved March 1, 2020 from https:\/\/www.bbc.com\/news\/technology-34311203 2015. Apple's App Store infected with XcodeGhost malware in China. Retrieved March 1, 2020 from https:\/\/www.bbc.com\/news\/technology-34311203"},{"key":"e_1_3_2_1_2_1","unstructured":"2016. Androzoo. Retrieved March 1 2020 from https:\/\/androzoo.uni.lu\/  2016. Androzoo. Retrieved March 1 2020 from https:\/\/androzoo.uni.lu\/"},{"key":"e_1_3_2_1_3_1","unstructured":"2019. AndroPyTool. Retrieved March 1 2020 from https:\/\/github.com\/alexMyG\/AndroPyTool  2019. AndroPyTool. Retrieved March 1 2020 from https:\/\/github.com\/alexMyG\/AndroPyTool"},{"key":"e_1_3_2_1_4_1","unstructured":"2019. Androwarn. Retrieved March 1 2020 from https:\/\/github.com\/maaaaz\/androwarn  2019. Androwarn. Retrieved March 1 2020 from https:\/\/github.com\/maaaaz\/androwarn"},{"key":"e_1_3_2_1_5_1","unstructured":"2019. Argus-SAF. Retrieved March 1 2020 from https:\/\/github.com\/arguslab\/Argus-SAF  2019. Argus-SAF. Retrieved March 1 2020 from https:\/\/github.com\/arguslab\/Argus-SAF"},{"key":"e_1_3_2_1_6_1","volume-title":"Permission Requesting in Android system. Retrieved","year":"2020","unstructured":"2019. Permission Requesting in Android system. Retrieved March 1, 2020 from https:\/\/developer.android.com\/training\/permissions\/requesting 2019. Permission Requesting in Android system. Retrieved March 1, 2020 from https:\/\/developer.android.com\/training\/permissions\/requesting"},{"key":"e_1_3_2_1_7_1","unstructured":"2020. Androguard. Retrieved March 1 2020 from https:\/\/github.com\/androguard\/androguard  2020. Androguard. Retrieved March 1 2020 from https:\/\/github.com\/androguard\/androguard"},{"key":"e_1_3_2_1_8_1","unstructured":"2020. JesusFreke\/smali\/bacsmali. Retrieved March 1 2020 from https:\/\/github.com\/JesusFreke\/smali\/tree\/master\/baksmali  2020. JesusFreke\/smali\/bacsmali. Retrieved March 1 2020 from https:\/\/github.com\/JesusFreke\/smali\/tree\/master\/baksmali"},{"key":"e_1_3_2_1_9_1","unstructured":"2020. Keytool. Retrieved March 1 2020 from https:\/\/docs.oracle.com\/javase\/8\/docs\/technotes\/tools\/windows\/keytool.html  2020. Keytool. Retrieved March 1 2020 from https:\/\/docs.oracle.com\/javase\/8\/docs\/technotes\/tools\/windows\/keytool.html"},{"key":"e_1_3_2_1_10_1","unstructured":"2020. Proguard. Retrieved March 1 2020 from https:\/\/www.guardsquare.com\/en\/products\/proguard  2020. Proguard. Retrieved March 1 2020 from https:\/\/www.guardsquare.com\/en\/products\/proguard"},{"key":"e_1_3_2_1_11_1","unstructured":"2020. VirusTotal. Retrieved March 1 2020 from https:\/\/www.virustotal.com\/gui\/  2020. VirusTotal. Retrieved March 1 2020 from https:\/\/www.virustotal.com\/gui\/"},{"key":"e_1_3_2_1_12_1","first-page":"23","article-title":"Drebin: Effective and explainable detection of android malware in your pocket","volume":"14","author":"Arp Daniel","year":"2014","unstructured":"Daniel Arp , Michael Spreitzenbarth , Malte Hubner , Hugo Gascon , Konrad Rieck , and CERT Siemens . 2014 . Drebin: Effective and explainable detection of android malware in your pocket .. In Ndss , Vol. 14. 23 -- 26 . Daniel Arp, Michael Spreitzenbarth, Malte Hubner, Hugo Gascon, Konrad Rieck, and CERT Siemens. 2014. Drebin: Effective and explainable detection of android malware in your pocket.. In Ndss, Vol. 14. 23--26.","journal-title":"Ndss"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594299"},{"key":"e_1_3_2_1_14_1","volume-title":"the ACM Conference on Computer and Communications Security, CCS'12","author":"Yee Au Kathy Wain","year":"2012","unstructured":"Kathy Wain Yee Au , Yi Fan Zhou , Zhen Huang , and David Lie . 2012 . PScout: analyzing the Android permission specification . In the ACM Conference on Computer and Communications Security, CCS'12 , Raleigh, NC, USA , October 16-18, 2012. Kathy Wain Yee Au, Yi Fan Zhou, Zhen Huang, and David Lie. 2012. PScout: analyzing the Android permission specification. In the ACM Conference on Computer and Communications Security, CCS'12, Raleigh, NC, USA, October 16-18, 2012."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978333"},{"key":"e_1_3_2_1_16_1","volume-title":"Wallach","author":"Book Theodore","year":"2013","unstructured":"Theodore Book , Adam Pridgen , and Dan S . Wallach . 2013 . Longitudinal Analysis of Android Ad Library Permissions . CoRR abs\/1303.0857 (2013). arXiv:1303.0857 http:\/\/arxiv.org\/abs\/1303.0857 Theodore Book, Adam Pridgen, and Dan S. Wallach. 2013. Longitudinal Analysis of Android Ad Library Permissions. CoRR abs\/1303.0857 (2013). arXiv:1303.0857 http:\/\/arxiv.org\/abs\/1303.0857"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2568225.2568286"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.29"},{"key":"e_1_3_2_1_19_1","volume-title":"Dangerous Permissions and Groups. Retrieved","author":"Dangerous Permissions and Groups 2019.","year":"2020","unstructured":"Dangerous Permissions and Groups 2019. Dangerous Permissions and Groups. Retrieved March 1, 2020 from https:\/\/developer.android.com\/guide\/topics\/security\/permissions.html#normal-dangerous Dangerous Permissions and Groups 2019. Dangerous Permissions and Groups. Retrieved March 1, 2020 from https:\/\/developer.android.com\/guide\/topics\/security\/permissions.html#normal-dangerous"},{"key":"e_1_3_2_1_20_1","volume-title":"FraudDroid: Automated Ad Fraud Detection for Android Apps. In The 26th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC\/FSE","author":"Dong Feng","year":"2018","unstructured":"Feng Dong , Haoyu Wang , Li Li , Yao Guo , Tegawend\u00e9 F Bissyand\u00e9 , Tianming Liu , Guoai Xu , and Jacques Klein . 2018 . FraudDroid: Automated Ad Fraud Detection for Android Apps. In The 26th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC\/FSE 2018). Feng Dong, Haoyu Wang, Li Li, Yao Guo, Tegawend\u00e9 F Bissyand\u00e9, Tianming Liu, Guoai Xu, and Jacques Klein. 2018. FraudDroid: Automated Ad Fraud Detection for Android Apps. In The 26th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC\/FSE 2018)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2619091"},{"key":"e_1_3_2_1_22_1","volume-title":"USENIX Security Symposium","volume":"30","author":"Felt Adrienne Porter","year":"2011","unstructured":"Adrienne Porter Felt , Helen J Wang , Alexander Moshchuk , Steve Hanna , and Erika Chin . 2011 . Permission Re-Delegation: Attacks and Defenses .. In USENIX Security Symposium , Vol. 30 . 88. Adrienne Porter Felt, Helen J Wang, Alexander Moshchuk, Steve Hanna, and Erika Chin. 2011. Permission Re-Delegation: Attacks and Defenses.. In USENIX Security Symposium, Vol. 30. 88."},{"key":"e_1_3_2_1_23_1","volume-title":"An Analysis of Pre-installed Android Software. CoRR abs\/1905.02713","author":"Gamba Julien","year":"2019","unstructured":"Julien Gamba , Mohammed Rashed , Abbas Razaghpanah , Juan Tapiador , and Narseo Vallina-Rodriguez . 2019. An Analysis of Pre-installed Android Software. CoRR abs\/1905.02713 ( 2019 ). arXiv:1905.02713 http:\/\/arxiv.org\/abs\/1905.02713 Julien Gamba, Mohammed Rashed, Abbas Razaghpanah, Juan Tapiador, and Narseo Vallina-Rodriguez. 2019. An Analysis of Pre-installed Android Software. CoRR abs\/1905.02713 (2019). arXiv:1905.02713 http:\/\/arxiv.org\/abs\/1905.02713"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2185448.2185464"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN.2014.6911805"},{"key":"e_1_3_2_1_26_1","volume-title":"Dating with Scambots: Understanding the Ecosystem of Fraudulent Dating Applications","author":"Hu Yangyu","year":"2019","unstructured":"Yangyu Hu , Haoyu Wang , Yajin Zhou , Yao Guo , Li Li , Bingxuan Luo , and Fangren Xu. 2019. Dating with Scambots: Understanding the Ecosystem of Fraudulent Dating Applications . IEEE Transactions on Dependable and Secure Computing (TDSC) ( 2019 ). Yangyu Hu, Haoyu Wang, Yajin Zhou, Yao Guo, Li Li, Bingxuan Luo, and Fangren Xu. 2019. Dating with Scambots: Understanding the Ecosystem of Fraudulent Dating Applications. IEEE Transactions on Dependable and Secure Computing (TDSC) (2019)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.5555\/2818754.2818791"},{"key":"e_1_3_2_1_28_1","volume-title":"Rebooting Research on Detecting Repackaged Android Apps: Literature Review and Benchmark","author":"Li Li","year":"2019","unstructured":"Li Li , Tegawend\u00e9 F Bissyand\u00e9 , and Jacques Klein . 2019. Rebooting Research on Detecting Repackaged Android Apps: Literature Review and Benchmark . IEEE Transactions on Software Engineering (TSE) ( 2019 ). Li Li, Tegawend\u00e9 F Bissyand\u00e9, and Jacques Klein. 2019. Rebooting Research on Detecting Repackaged Android Apps: Literature Review and Benchmark. IEEE Transactions on Software Engineering (TSE) (2019)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2016.52"},{"key":"e_1_3_2_1_30_1","volume-title":"On Identifying and Explaining Similarities in Android Apps. Journal of Computer Science and Technology (JCST)","author":"Li Li","year":"2019","unstructured":"Li Li , Tegawend\u00e9 F Bissyand\u00e9 , Haoyu Wang , and Jacques Klein . 2019. On Identifying and Explaining Similarities in Android Apps. Journal of Computer Science and Technology (JCST) ( 2019 ). Li Li, Tegawend\u00e9 F Bissyand\u00e9, Haoyu Wang, and Jacques Klein. 2019. On Identifying and Explaining Similarities in Android Apps. Journal of Computer Science and Technology (JCST) (2019)."},{"key":"e_1_3_2_1_31_1","volume-title":"David Lo, and Lorenzo Cavallaro.","author":"Li Li","year":"2017","unstructured":"Li Li , Daoyuan Li , Tegawend\u00e9 F Bissyand\u00e9 , Jacques Klein , Yves Le Traon , David Lo, and Lorenzo Cavallaro. 2017 . Understanding Android App Piggybacking: A Systematic Study of Malicious Code Grafting. IEEE Transactions on Information Forensics & Security (TIFS) ( 2017). Li Li, Daoyuan Li, Tegawend\u00e9 F Bissyand\u00e9, Jacques Klein, Yves Le Traon, David Lo, and Lorenzo Cavallaro. 2017. Understanding Android App Piggybacking: A Systematic Study of Malicious Code Grafting. IEEE Transactions on Information Forensics & Security (TIFS) (2017)."},{"key":"e_1_3_2_1_32_1","volume-title":"Revisiting the Impact of Common Libraries for Android-related Investigations. Journal of Systems and Software (JSS)","author":"Li Li","year":"2019","unstructured":"Li Li , Timoth\u00e9e Riom , Tegawend\u00e9 F Bissyand\u00e9 , Haoyu Wang , Jacques Klein , and Yves Le Traon . 2019. Revisiting the Impact of Common Libraries for Android-related Investigations. Journal of Systems and Software (JSS) ( 2019 ). Li Li, Timoth\u00e9e Riom, Tegawend\u00e9 F Bissyand\u00e9, Haoyu Wang, Jacques Klein, and Yves Le Traon. 2019. Revisiting the Impact of Common Libraries for Android-related Investigations. Journal of Systems and Software (JSS) (2019)."},{"key":"e_1_3_2_1_33_1","volume-title":"LibD: Scalable and Precise Third-Party Library Detection in Android Markets. In 2017 IEEE\/ACM 39th International Conference on Software Engineering (ICSE). 335--346","author":"Li M.","unstructured":"M. Li , W. Wang , P. Wang , S. Wang , D. Wu , J. Liu , R. Xue , and W. Huo . 2017 . LibD: Scalable and Precise Third-Party Library Detection in Android Markets. In 2017 IEEE\/ACM 39th International Conference on Software Engineering (ICSE). 335--346 . M. Li, W. Wang, P. Wang, S. Wang, D. Wu, J. Liu, R. Xue, and W. Huo. 2017. LibD: Scalable and Precise Third-Party Library Detection in Android Markets. In 2017 IEEE\/ACM 39th International Conference on Software Engineering (ICSE). 335--346."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2889160.2889178"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1142\/9789813273238_0066"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2018.12.006"},{"key":"e_1_3_2_1_37_1","volume-title":"Dark Hazard: Learning-based, Large-Scale Discovery of Hidden Sensitive Operations in Android Apps.. In NDSS.","author":"Pan Xiaorui","year":"2017","unstructured":"Xiaorui Pan , Xueqiang Wang , Yue Duan , XiaoFeng Wang , and Heng Yin . 2017 . Dark Hazard: Learning-based, Large-Scale Discovery of Hidden Sensitive Operations in Android Apps.. In NDSS. Xiaorui Pan, Xueqiang Wang, Yue Duan, XiaoFeng Wang, and Heng Yin. 2017. Dark Hazard: Learning-based, Large-Scale Discovery of Hidden Sensitive Operations in Android Apps.. In NDSS."},{"key":"e_1_3_2_1_38_1","volume-title":"Mobile Operating System Market Share Worldwide. Retrieved","author":"Statcounter","year":"2020","unstructured":"Statcounter 2020. Mobile Operating System Market Share Worldwide. Retrieved March 1, 2020 from http:\/\/gs.statcounter.com\/os-market-share\/mobile\/worldwide Statcounter 2020. Mobile Operating System Market Share Worldwide. Retrieved March 1, 2020 from http:\/\/gs.statcounter.com\/os-market-share\/mobile\/worldwide"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2771783.2771795"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23171"},{"key":"e_1_3_2_1_41_1","volume-title":"Characterizing malicious Android apps by mining topic-specific data flow signatures. Information and Software Technology","author":"Yang Xinli","year":"2017","unstructured":"Xinli Yang , David Lo , Li Li , Xin Xia , Tegawend\u00e9 F Bissyand\u00e9 , and Jacques Klein . 2017. Characterizing malicious Android apps by mining topic-specific data flow signatures. Information and Software Technology ( 2017 ). Xinli Yang, David Lo, Li Li, Xin Xia, Tegawend\u00e9 F Bissyand\u00e9, and Jacques Klein. 2017. Characterizing malicious Android apps by mining topic-specific data flow signatures. Information and Software Technology (2017)."},{"key":"e_1_3_2_1_42_1","first-page":"141","article-title":"Detecting third-party libraries in Android applications with high precision and recall. In 2018 IEEE 25th International Conference on Software Analysis","volume":"00","author":"Zhang Y.","year":"2018","unstructured":"Y. Zhang , J. Dai , X. Zhang , S. Huang , Z. Yang , M. Yang , and H. Chen . 2018 . Detecting third-party libraries in Android applications with high precision and recall. In 2018 IEEE 25th International Conference on Software Analysis , Evolution and Reengineering (SANER) , Vol. 00. 141 -- 152 . Y. Zhang, J. Dai, X. Zhang, S. Huang, Z. Yang, M. Yang, and H. Chen. 2018. Detecting third-party libraries in Android applications with high precision and recall. In 2018 IEEE 25th International Conference on Software Analysis, Evolution and Reengineering (SANER), Vol. 00. 141--152.","journal-title":"Evolution and Reengineering (SANER)"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.16"}],"event":{"name":"WiSec '20: 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks","location":"Linz Austria","acronym":"WiSec '20","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control","SIGMOBILE ACM Special Interest Group on Mobility of Systems, Users, Data and Computing"]},"container-title":["Proceedings of the 13th ACM Conference on Security and Privacy in Wireless and Mobile Networks"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3395351.3399346","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3395351.3399346","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T22:38:34Z","timestamp":1750199914000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3395351.3399346"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,7,8]]},"references-count":43,"alternative-id":["10.1145\/3395351.3399346","10.1145\/3395351"],"URL":"https:\/\/doi.org\/10.1145\/3395351.3399346","relation":{},"subject":[],"published":{"date-parts":[[2020,7,8]]},"assertion":[{"value":"2020-07-21","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}