{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T16:15:04Z","timestamp":1783700104820,"version":"3.55.0"},"reference-count":76,"publisher":"Association for Computing Machinery (ACM)","issue":"2","license":[{"start":{"date-parts":[[2021,3,10]],"date-time":"2021-03-10T00:00:00Z","timestamp":1615334400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Research Foundation, Prime Ministers Offi, Singapore under its National Cybersecurity R&D Program","award":["NRF2018 NCR-NCR005-0001"],"award-info":[{"award-number":["NRF2018 NCR-NCR005-0001"]}]},{"name":"the Singapore National Research Foundation under NCR","award":["NRF2018NCR-NSOE004-0001"],"award-info":[{"award-number":["NRF2018NCR-NSOE004-0001"]}]},{"name":"Singapore Ministry of Education Academic Research Fund Tier 1","award":["2018-T1-002-069"],"award-info":[{"award-number":["2018-T1-002-069"]}]},{"name":"Singapore National Research Foundation under NCR","award":["NSOE003-0001"],"award-info":[{"award-number":["NSOE003-0001"]}]},{"name":"NRF Investigatorship","award":["NRFI06-2020-0022"],"award-info":[{"award-number":["NRFI06-2020-0022"]}]},{"name":"Research Grants Council of the Hong Kong Special Administrative Region, China","award":["CUHK 14210717 of the General Research Fund"],"award-info":[{"award-number":["CUHK 14210717 of the General Research Fund"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Softw. Eng. Methodol."],"published-print":{"date-parts":[[2021,4,30]]},"abstract":"<jats:p>Machine learning\u2013(ML) based approach is considered as one of the most promising techniques for Android malware detection and has achieved high accuracy by leveraging commonly used features. In practice, most of the ML classifications only provide a binary label to mobile users and app security analysts. However, stakeholders are more interested in the reason why apps are classified as malicious in both academia and industry. This belongs to the research area of interpretable ML but in a specific research domain (i.e., mobile malware detection). Although several interpretable ML methods have been exhibited to explain the final classification results in many cutting-edge Artificial Intelligent\u2013based research fields, until now, there is no study interpreting why an app is classified as malware or unveiling the domain-specific challenges.<\/jats:p>\n          <jats:p>\n            In this article, to fill this gap, we propose a novel and interpretable ML-based approach (named\n            <jats:sc>XMal<\/jats:sc>\n            ) to classify malware with high accuracy and explain the classification result meanwhile. (1) The first classification phase of\n            <jats:sc>XMal<\/jats:sc>\n            hinges multi-layer perceptron and attention mechanism and also pinpoints the key features most related to the classification result. (2) The second interpreting phase aims at automatically producing neural language descriptions to interpret the core malicious behaviors within apps. We evaluate the behavior description results by leveraging a human study and an in-depth quantitative analysis. Moreover, we further compare\n            <jats:sc>XMal<\/jats:sc>\n            with the existing interpretable ML-based methods (i.e., Drebin and LIME) to demonstrate the effectiveness of\n            <jats:sc>XMal<\/jats:sc>\n            . We find that\n            <jats:sc>XMal<\/jats:sc>\n            is able to reveal the malicious behaviors more accurately. Additionally, our experiments show that\n            <jats:sc>XMal<\/jats:sc>\n            can also interpret the reason why some samples are misclassified by ML classifiers. Our study peeks into the interpretable ML through the research of Android malware detection and analysis.\n          <\/jats:p>","DOI":"10.1145\/3423096","type":"journal-article","created":{"date-parts":[[2021,3,10]],"date-time":"2021-03-10T19:47:26Z","timestamp":1615405646000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":73,"title":["Why an Android App Is Classified as Malware"],"prefix":"10.1145","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0360-2248","authenticated-orcid":false,"given":"Bozhi","family":"Wu","sequence":"first","affiliation":[{"name":"Nanyang Technological University, Singapore and Peking University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9477-4100","authenticated-orcid":false,"given":"Sen","family":"Chen","sequence":"additional","affiliation":[{"name":"College of Intelligence and Computing, Tianjin University, China and NTU, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cuiyun","family":"Gao","sequence":"additional","affiliation":[{"name":"Harbin Institute of Technology (Shenzhen), China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lingling","family":"Fan","sequence":"additional","affiliation":[{"name":"College of Cyber Science, Nankai University, China and NTU, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weiping","family":"Wen","sequence":"additional","affiliation":[{"name":"Peking University, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3666-5798","authenticated-orcid":false,"given":"Michael R.","family":"Lyu","sequence":"additional","affiliation":[{"name":"Chinese University of Hong Kong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,3,10]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"Global Mobile OS Market Share in Sales to End Users from 1st Quarter 2009 to 1st Quarter 2016. 2016. Retrieved from http:\/\/www.statista.com\/statistics\/266136\/global-market-share-held-by-smartphone-operating-systems\/.  Global Mobile OS Market Share in Sales to End Users from 1st Quarter 2009 to 1st Quarter 2016. 2016. Retrieved from http:\/\/www.statista.com\/statistics\/266136\/global-market-share-held-by-smartphone-operating-systems\/."},{"key":"e_1_2_1_2_1","unstructured":"CERT. 2020. Retrieved from https:\/\/share.anva.org.cn\/web\/publicity\/listMalware.  CERT. 2020. Retrieved from https:\/\/share.anva.org.cn\/web\/publicity\/listMalware."},{"key":"e_1_2_1_3_1","unstructured":"Microsoft. 2020. Retrieved from https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/.  Microsoft. 2020. Retrieved from https:\/\/www.microsoft.com\/en-us\/wdsi\/threats\/."},{"key":"e_1_2_1_4_1","unstructured":"Symantec. 2020. Retrieved from https:\/\/www.symantec.com\/.  Symantec. 2020. Retrieved from https:\/\/www.symantec.com\/."},{"key":"e_1_2_1_5_1","unstructured":"Virustotal. 2020. Retrieved from https:\/\/www.virustotal.com\/gui\/home\/upload.  Virustotal. 2020. Retrieved from https:\/\/www.virustotal.com\/gui\/home\/upload."},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-04283-1_6"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23247"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pone.0181142"},{"key":"e_1_2_1_9_1","volume-title":"Damien Octeau, and Patrick McDaniel.","author":"Arzt Steven","year":"2014","unstructured":"Steven Arzt , Siegfried Rasthofer , Christian Fritz , Eric Bodden , Alexandre Bartel , Jacques Klein , Yves Le Traon , Damien Octeau, and Patrick McDaniel. 2014 . Flowdroid : Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps. In ACM SIGPLAN Notices, Vol. 49 . ACM , 259--269. Steven Arzt, Siegfried Rasthofer, Christian Fritz, Eric Bodden, Alexandre Bartel, Jacques Klein, Yves Le Traon, Damien Octeau, and Patrick McDaniel. 2014. Flowdroid: Precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps. In ACM SIGPLAN Notices, Vol. 49. ACM, 259--269."},{"key":"e_1_2_1_10_1","unstructured":"Dzmitry Bahdanau Kyunghyun Cho and Yoshua Bengio. 2014. Neural Machine Translation by Jointly Learning to Align and Translate. arXiv:1409.0473. Retrieved from https:\/\/arxiv.org\/abs\/1409.0473.  Dzmitry Bahdanau Kyunghyun Cho and Yoshua Bengio. 2014. Neural Machine Translation by Jointly Learning to Align and Translate. arXiv:1409.0473. Retrieved from https:\/\/arxiv.org\/abs\/1409.0473."},{"key":"e_1_2_1_11_1","unstructured":"Manjot Bilkhu Siyang Wang and Tushar Dobhal. 2019. Attention Is All You Need for Videos: Self-attention Based Video Summarization Using Universal Transformers. arXiv:1906.02792. Retrieved from https:\/\/arxiv.org\/abs\/1906.02792.  Manjot Bilkhu Siyang Wang and Tushar Dobhal. 2019. Attention Is All You Need for Videos: Self-attention Based Video Summarization Using Universal Transformers. arXiv:1906.02792. Retrieved from https:\/\/arxiv.org\/abs\/1906.02792."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00004"},{"key":"e_1_2_1_13_1","volume-title":"GUI-squatting attack: Automated generation of Android phishing apps","author":"Chen Sen","year":"2019","unstructured":"Sen Chen , Lingling Fan , Chunyang Chen , Minhui Xue , Yang Liu , and Lihua Xu. 2019. GUI-squatting attack: Automated generation of Android phishing apps . IEEE Trans. Depend. Secure Comput . ( 2019 ). DOI:10.1109\/TDSC.2019.2956035 10.1109\/TDSC.2019.2956035 Sen Chen, Lingling Fan, Chunyang Chen, Minhui Xue, Yang Liu, and Lihua Xu. 2019. GUI-squatting attack: Automated generation of Android phishing apps. IEEE Trans. Depend. Secure Comput. (2019). DOI:10.1109\/TDSC.2019.2956035"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3377811.3380417"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236024.3275523"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.11.007"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/AI4Mobile.2019.8672691"},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897860"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2973750.2985246"},{"key":"e_1_2_1_20_1","doi-asserted-by":"crossref","unstructured":"Jianpeng Cheng Li Dong and Mirella Lapata. 2016. Long short-term memory-networks for machine reading. arXiv:1601.06733. Retrieved from https:\/\/arxiv.org\/abs\/1601.06733.  Jianpeng Cheng Li Dong and Mirella Lapata. 2016. Long short-term memory-networks for machine reading. arXiv:1601.06733. Retrieved from https:\/\/arxiv.org\/abs\/1601.06733.","DOI":"10.18653\/v1\/D16-1053"},{"key":"e_1_2_1_21_1","volume-title":"Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory","author":"Corbin Juliet","unstructured":"Juliet Corbin and Anselm Strauss . 2014. Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory . Sage . Juliet Corbin and Anselm Strauss. 2014. Basics of Qualitative Research: Techniques and Procedures for Developing Grounded Theory. Sage."},{"key":"e_1_2_1_22_1","unstructured":"Anthony Desnos et\u00a0al. 2013. Androguard\u2014Reverse Engineering Malware and Goodware Analysis of Android Applications. Retrieved from google.com\/p\/androguard.  Anthony Desnos et\u00a0al. 2013. Androguard\u2014Reverse Engineering Malware and Goodware Analysis of Android Applications. Retrieved from google.com\/p\/androguard."},{"key":"e_1_2_1_23_1","unstructured":"Finale Doshi-Velez and Been Kim. 2017. Towards a Rigorous Science of Interpretable Machine Learning. arXiv:1702.08608. Retrieved from https:\/\/arxiv.org\/abs\/1702.08608.  Finale Doshi-Velez and Been Kim. 2017. Towards a Rigorous Science of Interpretable Machine Learning. arXiv:1702.08608. Retrieved from https:\/\/arxiv.org\/abs\/1702.08608."},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238170"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2989055"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3025436"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICECCS.2019.00014"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICECCS51672.2020.00015"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/NTMS.2016.7792435"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3162625"},{"key":"e_1_2_1_31_1","volume-title":"Proceedings of the 8th International Joint Conference on Natural Language Processing (IJCNLP\u201917)","author":"Ghader Hamidreza","year":"2017","unstructured":"Hamidreza Ghader and Christof Monz . 2017 . What does attention in neural machine translation pay attention to? In Proceedings of the 8th International Joint Conference on Natural Language Processing (IJCNLP\u201917) . 30--39. Hamidreza Ghader and Christof Monz. 2017. What does attention in neural machine translation pay attention to? In Proceedings of the 8th International Joint Conference on Natural Language Processing (IJCNLP\u201917). 30--39."},{"key":"e_1_2_1_32_1","unstructured":"Google. 2019. Documentation for App Developers. Retrieved from https:\/\/developer.android.google.cn\/docs.  Google. 2019. Documentation for App Developers. Retrieved from https:\/\/developer.android.google.cn\/docs."},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the Annual Symposium on Network and Distributed System Security (NDSS\u201915)","author":"Gordon Michael I.","unstructured":"Michael I. Gordon , Deokhwan Kim , Jeff H. Perkins , Limei Gilham , Nguyen Nguyen , and Martin C. Rinard . 2015. Information flow analysis of Android applications in DroidSafe . In Proceedings of the Annual Symposium on Network and Distributed System Security (NDSS\u201915) . Michael I. Gordon, Deokhwan Kim, Jeff H. Perkins, Limei Gilham, Nguyen Nguyen, and Martin C. Rinard. 2015. Information flow analysis of Android applications in DroidSafe. In Proceedings of the Annual Symposium on Network and Distributed System Security (NDSS\u201915)."},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the 24th USENIX Security Symposium (USENIX Security\u201915)","author":"Graziano Mariano","year":"2015","unstructured":"Mariano Graziano , Davide Canali , Leyla Bilge , Andrea Lanzi , and Davide Balzarotti . 2015 . Needles in a haystack: Mining information from public dynamic analysis sandboxes for malware intelligence . In Proceedings of the 24th USENIX Security Symposium (USENIX Security\u201915) . 1057--1072. Mariano Graziano, Davide Canali, Leyla Bilge, Andrea Lanzi, and Davide Balzarotti. 2015. Needles in a haystack: Mining information from public dynamic analysis sandboxes for malware intelligence. In Proceedings of the 24th USENIX Security Symposium (USENIX Security\u201915). 1057--1072."},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3236009"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243792"},{"key":"e_1_2_1_37_1","unstructured":"Weiwei Hu and Ying Tan. 2017. Generating adversarial malware examples for black-box attacks based on GAN. arXiv:1702.05983. Retrieved from https:\/\/arxiv.org\/abs\/1702.05983.  Weiwei Hu and Ying Tan. 2017. Generating adversarial malware examples for black-box attacks based on GAN. arXiv:1702.05983. Retrieved from https:\/\/arxiv.org\/abs\/1702.05983."},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2866319"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVCG.2014.2346482"},{"key":"e_1_2_1_40_1","unstructured":"Yusi Lei Sen Chen Lingling Fan Fu Song and Yang Liu. 2020. Advanced evasion attacks and mitigations on practical ML-based phishing website classifiers. arXiv:2004.06954. Retrieved from https:\/\/arxiv.org\/abs\/2004.06954.  Yusi Lei Sen Chen Lingling Fan Fu Song and Yang Liu. 2020. Advanced evasion attacks and mitigations on practical ML-based phishing website classifiers. arXiv:2004.06954. Retrieved from https:\/\/arxiv.org\/abs\/2004.06954."},{"key":"e_1_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2017.2789219"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2015.48"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/948109.948149"},{"key":"e_1_2_1_44_1","unstructured":"Zachary C. Lipton. 2016. The mythos of model interpretability. arXiv:1606.03490. Retrieved from https:\/\/arxiv.org\/abs\/1606.03490.  Zachary C. Lipton. 2016. The mythos of model interpretability. arXiv:1606.03490. Retrieved from https:\/\/arxiv.org\/abs\/1606.03490."},{"key":"e_1_2_1_45_1","volume-title":"Lundberg and Su-In Lee","author":"Scott","year":"2017","unstructured":"Scott M. Lundberg and Su-In Lee . 2017 . A unified approach to interpreting model predictions. In Advances in Neural Information Processing Systems . 4765--4774. Scott M. Lundberg and Su-In Lee. 2017. A unified approach to interpreting model predictions. In Advances in Neural Information Processing Systems. 4765--4774."},{"key":"e_1_2_1_46_1","volume-title":"Manning","author":"Luong Minh-Thang","year":"2015","unstructured":"Minh-Thang Luong , Hieu Pham , and Christopher D . Manning . 2015 . Effective approaches to attention-based neural machine translation. arXiv:1508.04025. Retrieved from https:\/\/arxiv.org\/abs\/1508.04025. Minh-Thang Luong, Hieu Pham, and Christopher D. Manning. 2015. Effective approaches to attention-based neural machine translation. arXiv:1508.04025. Retrieved from https:\/\/arxiv.org\/abs\/1508.04025."},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3029806.3029823"},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.23919\/EUSIPCO.2018.8553598"},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.artint.2018.07.007"},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.dsp.2017.10.011"},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICTAI.2013.53"},{"key":"e_1_2_1_52_1","volume-title":"Proceedings of the National Conference on Artificial Intelligence","volume":"21","author":"Poulin Brett","year":"2006","unstructured":"Brett Poulin , Roman Eisner , Duane Szafron , Paul Lu , Russell Greiner , David S Wishart , Alona Fyshe , Brandon Pearcy , Cam MacDonell , and John Anvik . 2006 . Visual explanation of evidence with additive classifiers . In Proceedings of the National Conference on Artificial Intelligence , Vol. 21 . MIT Press, Cambridge, MA , 1999. Brett Poulin, Roman Eisner, Duane Szafron, Paul Lu, Russell Greiner, David S Wishart, Alona Fyshe, Brandon Pearcy, Cam MacDonell, and John Anvik. 2006. Visual explanation of evidence with additive classifiers. In Proceedings of the National Conference on Artificial Intelligence, Vol. 21. MIT Press, Cambridge, MA, 1999."},{"key":"e_1_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1145\/2484313.2484355"},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939778"},{"key":"e_1_2_1_55_1","unstructured":"Wojciech Samek Thomas Wiegand and Klaus-Robert M\u00fcller. 2017. Explainable artificial intelligence: Understanding visualizing and interpreting deep learning models. arXiv:1708.08296. Retrieved from https:\/\/arxiv.org\/abs\/1708.08296.  Wojciech Samek Thomas Wiegand and Klaus-Robert M\u00fcller. 2017. Explainable artificial intelligence: Understanding visualizing and interpreting deep learning models. arXiv:1708.08296. Retrieved from https:\/\/arxiv.org\/abs\/1708.08296."},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884833"},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23145"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE-SEIP.2019.00028"},{"key":"e_1_2_1_59_1","volume-title":"Proceedings of the 2011 IEEE Conference on Visual Analytics Science and Technology (VAST\u201911)","author":"Den Elzen Stef Van","unstructured":"Stef Van Den Elzen and Jarke J . van Wijk. 2011. Baobabview: Interactive construction and analysis of decision trees . In Proceedings of the 2011 IEEE Conference on Visual Analytics Science and Technology (VAST\u201911) . IEEE, 151--160. Stef Van Den Elzen and Jarke J. van Wijk. 2011. Baobabview: Interactive construction and analysis of decision trees. In Proceedings of the 2011 IEEE Conference on Visual Analytics Science and Technology (VAST\u201911). IEEE, 151--160."},{"key":"e_1_2_1_60_1","unstructured":"Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan N. Gomez \u0141ukasz Kaiser and Illia Polosukhin. 2017. Attention is all you need. In Advances in Neural Information Processing Systems. 5998--6008.  Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan N. Gomez \u0141ukasz Kaiser and Illia Polosukhin. 2017. Attention is all you need. In Advances in Neural Information Processing Systems. 5998--6008."},{"key":"e_1_2_1_61_1","unstructured":"Lilian Weng. 2018. Attention? Attention! from http:\/\/lilianweng.github.io\/lil-log\/2018\/06\/24\/attention-attention.html.  Lilian Weng. 2018. Attention? Attention! from http:\/\/lilianweng.github.io\/lil-log\/2018\/06\/24\/attention-attention.html."},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23164"},{"key":"e_1_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/AsiaJCIS.2012.18"},{"key":"e_1_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2016.03.004"},{"key":"e_1_2_1_65_1","volume-title":"Proceedings of the International Conference on Machine Learning. 2048--2057","author":"Xu Kelvin","year":"2015","unstructured":"Kelvin Xu , Jimmy Ba , Ryan Kiros , Kyunghyun Cho , Aaron Courville , Ruslan Salakhudinov , Rich Zemel , and Yoshua Bengio . 2015 . Show, attend and tell: Neural image caption generation with visual attention . In Proceedings of the International Conference on Machine Learning. 2048--2057 . Kelvin Xu, Jimmy Ba, Ryan Kiros, Kyunghyun Cho, Aaron Courville, Ruslan Salakhudinov, Rich Zemel, and Yoshua Bengio. 2015. Show, attend and tell: Neural image caption generation with visual attention. In Proceedings of the International Conference on Machine Learning. 2048--2057."},{"key":"e_1_2_1_66_1","volume-title":"Proceedings of the 32nd International Conference on Machine Learning (ICML\u201915)","author":"Xu Kelvin","year":"2015","unstructured":"Kelvin Xu , Jimmy Ba , Ryan Kiros , Kyunghyun Cho , Aaron C. Courville , Ruslan Salakhutdinov , Richard S. Zemel , and Yoshua Bengio . 2015 . Show, attend and tell: Neural image caption generation with visual attention . In Proceedings of the 32nd International Conference on Machine Learning (ICML\u201915) . 2048--2057. Kelvin Xu, Jimmy Ba, Ryan Kiros, Kyunghyun Cho, Aaron C. Courville, Ruslan Salakhutdinov, Richard S. Zemel, and Yoshua Bengio. 2015. Show, attend and tell: Neural image caption generation with visual attention. In Proceedings of the 32nd International Conference on Machine Learning (ICML\u201915). 2048--2057."},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00040"},{"key":"e_1_2_1_68_1","unstructured":"Lok Kwong Yan and Heng Yin. 2012. Droidscope: Seamlessly reconstructing the os and Dalvik semantic views for dynamic Android malware analysis. In Presented as Part of the Proceedings of the 21st USENIX Security Symposium (USENIX Security\u201912). 569--584.  Lok Kwong Yan and Heng Yin. 2012. Droidscope: Seamlessly reconstructing the os and Dalvik semantic views for dynamic Android malware analysis. In Presented as Part of the Proceedings of the 21st USENIX Security Symposium (USENIX Security\u201912). 569--584."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N16-1174"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2013.88"},{"key":"e_1_2_1_71_1","volume-title":"Cybersecurity Systems for Human Cognition Augmentation","author":"Yu Wei","unstructured":"Wei Yu , Linqiang Ge , Guobin Xu , and Xinwen Fu. 2014. Towards neural network based malware detection on Android mobile devices . In Cybersecurity Systems for Human Cognition Augmentation . Springer , 99--117. Wei Yu, Linqiang Ge, Guobin Xu, and Xinwen Fu. 2014. Towards neural network based malware detection on Android mobile devices. In Cybersecurity Systems for Human Cognition Augmentation. Springer, 99--117."},{"key":"e_1_2_1_72_1","first-page":"114","article-title":"Droiddetector: Android malware characterization and detection using deep learning. Tsinghua Sci","volume":"21","author":"Yuan Zhenlong","year":"2016","unstructured":"Zhenlong Yuan , Yongqiang Lu , and Yibo Xue . 2016 . Droiddetector: Android malware characterization and detection using deep learning. Tsinghua Sci . Technol. 21 , 1 (2016), 114 -- 123 . Zhenlong Yuan, Yongqiang Lu, and Yibo Xue. 2016. Droiddetector: Android malware characterization and detection using deep learning. Tsinghua Sci. Technol. 21, 1 (2016), 114--123.","journal-title":"Technol."},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01237-3_8"},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/2435349.2435377"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.16"},{"key":"e_1_2_1_76_1","first-page":"50","article-title":"Hey, you, get off of my market: Detecting malicious apps in official and alternative Android markets","volume":"25","author":"Zhou Yajin","year":"2012","unstructured":"Yajin Zhou , Zhi Wang , Wu Zhou , and Xuxian Jiang . 2012 . Hey, you, get off of my market: Detecting malicious apps in official and alternative Android markets . In Proceedings of the NDSS , Vol. 25. 50 -- 52 . Yajin Zhou, Zhi Wang, Wu Zhou, and Xuxian Jiang. 2012. Hey, you, get off of my market: Detecting malicious apps in official and alternative Android markets. In Proceedings of the NDSS, Vol. 25. 50--52.","journal-title":"Proceedings of the NDSS"}],"container-title":["ACM Transactions on Software Engineering and Methodology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3423096","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3423096","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:56Z","timestamp":1750195496000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3423096"}},"subtitle":["Toward Malware Classification Interpretation"],"short-title":[],"issued":{"date-parts":[[2021,3,10]]},"references-count":76,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2021,4,30]]}},"alternative-id":["10.1145\/3423096"],"URL":"https:\/\/doi.org\/10.1145\/3423096","relation":{},"ISSN":["1049-331X","1557-7392"],"issn-type":[{"value":"1049-331X","type":"print"},{"value":"1557-7392","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,3,10]]},"assertion":[{"value":"2020-04-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-09-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-03-10","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}