{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T15:33:49Z","timestamp":1783697629568,"version":"3.55.0"},"reference-count":169,"publisher":"Association for Computing Machinery (ACM)","issue":"9","license":[{"start":{"date-parts":[[2023,1,16]],"date-time":"2023-01-16T00:00:00Z","timestamp":1673827200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2023,9,30]]},"abstract":"<jats:p>The use of mobile devices is rising daily in this technological era. A continuous and increasing number of mobile applications are constantly offered on mobile marketplaces to fulfil the needs of smartphone users. Many Android applications do not address the security aspects appropriately. This is often due to a lack of automated mechanisms to identify, test, and fix source code vulnerabilities at the early stages of design and development. Therefore, the need to fix such issues at the initial stages rather than providing updates and patches to the published applications is widely recognized. Researchers have proposed several methods to improve the security of applications by detecting source code vulnerabilities and malicious codes. This Systematic Literature Review (SLR) focuses on Android application analysis and source code vulnerability detection methods and tools by critically evaluating 118 carefully selected technical studies published between 2016 and 2022. It highlights the advantages, disadvantages, applicability of the proposed techniques, and potential improvements of those studies. Both Machine Learning (ML)-based methods and conventional methods related to vulnerability detection are discussed while focusing more on ML-based methods, since many recent studies conducted experiments with ML. Therefore, this article aims to enable researchers to acquire in-depth knowledge in secure mobile application development while minimizing the vulnerabilities by applying ML methods. Furthermore, researchers can use the discussions and findings of this SLR to identify potential future research and development directions.<\/jats:p>","DOI":"10.1145\/3556974","type":"journal-article","created":{"date-parts":[[2022,8,18]],"date-time":"2022-08-18T11:04:28Z","timestamp":1660820668000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":69,"title":["Android Source Code Vulnerability Detection: A Systematic Literature Review"],"prefix":"10.1145","volume":"55","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2278-8671","authenticated-orcid":false,"given":"Janaka","family":"Senanayake","sequence":"first","affiliation":[{"name":"Robert Gordon University, Aberdeen, UK and University of Kelaniya, Dalugama, Kelaniya, Western Province, Sri Lanka"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6430-9558","authenticated-orcid":false,"given":"Harsha","family":"Kalutarage","sequence":"additional","affiliation":[{"name":"Robert Gordon University, Aberdeen, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1146-1860","authenticated-orcid":false,"given":"Mhd Omar","family":"Al-Kadri","sequence":"additional","affiliation":[{"name":"Birmingham City University, Birmingham, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0987-2791","authenticated-orcid":false,"given":"Andrei","family":"Petrovski","sequence":"additional","affiliation":[{"name":"Robert Gordon University, Aberdeen, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7530-4119","authenticated-orcid":false,"given":"Luca","family":"Piras","sequence":"additional","affiliation":[{"name":"Middlesex University, London, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,1,16]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"publisher","DOI":"10.25007\/ajnu.v6n3a97"},{"key":"e_1_3_1_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2918202"},{"key":"e_1_3_1_4_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-78753-4_8"},{"key":"e_1_3_1_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2901739.2903508"},{"key":"e_1_3_1_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3291636"},{"key":"e_1_3_1_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/SDS.2019.8768729"},{"key":"e_1_3_1_8_2","unstructured":"Alsayra\n\t\t\t\t\t. 2020. Intelligence and Security Informatics Data Sets. Retrieved from https:\/\/www.azsecure-data.org."},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/1142\/1\/012012"},{"key":"e_1_3_1_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/2351676.2351717"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.3390\/info10100326"},{"key":"e_1_3_1_12_2","unstructured":"Android\n\t\t\t\t\t. 2021. Android Security Bulletins. Retrieved from https:\/\/source.android.com\/security\/bulletin."},{"key":"e_1_3_1_13_2","unstructured":"Android\n\t\t\t\t\t. 2021. Platform Architecture. Retrieved from https:\/\/developer.android.com\/guide\/platform."},{"key":"e_1_3_1_14_2","unstructured":"Android\n\t\t\t\t\t. 2022. Apkanalyzer. Retrieved from https:\/\/developer.android.com\/studio\/command-line\/apkanalyzer."},{"key":"e_1_3_1_15_2","unstructured":"Developers\n\t\t\t\t\t\t\tAndroid\n\t\t\t\t\t. 2022. UI\/App Exerciser Monkey. Retrieved from https:\/\/developer.android.com\/studio\/test\/other-testing-tools\/monkey."},{"key":"e_1_3_1_16_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2020.106374"},{"key":"e_1_3_1_17_2","first-page":"23","volume-title":"NDSS","author":"Arp Daniel","year":"2014","unstructured":"Daniel Arp , Michael Spreitzenbarth , Malte Hubner , Hugo Gascon , Konrad Rieck , and CERT Siemens . 2014. Drebin: Effective and explainable detection of Android malware in your pocket. In NDSS , Vol. 14. NDSS, 23\u201326. Retrieved from https:\/\/prosec.mlsec.org\/docs\/2014-ndss.pdf."},{"key":"e_1_3_1_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594299"},{"key":"e_1_3_1_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/s00165-017-0445-z"},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2015.2419611"},{"key":"e_1_3_1_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3016774"},{"key":"e_1_3_1_22_2","doi-asserted-by":"publisher","DOI":"10.5555\/3165154"},{"key":"e_1_3_1_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053004"},{"key":"e_1_3_1_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/1134285.1134500"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1145\/2046614.2046619"},{"key":"e_1_3_1_26_2","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387469"},{"key":"e_1_3_1_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.16"},{"key":"e_1_3_1_28_2","unstructured":"National Computer Network Emergency Technology Coordination\n\t\t\t\t\t\t\tCenter\n\t\t\t\t\t. 2021. China National Vulnerability Database. Retrieved from https:\/\/www.cnvd.org.cn\/."},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1088\/1742-6596\/1288\/1\/012053"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/ITOEC49072.2020.9141575"},{"key":"e_1_3_1_31_2","first-page":"659","volume-title":"24th USENIX Security Symposium (USENIX Security\u201915)","author":"Chen Kai","year":"2015","unstructured":"Kai Chen , Peng Wang , Yeonjoon Lee , XiaoFeng Wang , Nan Zhang , Heqing Huang , Wei Zou , and Peng Liu . 2015. Finding unknown malice in 10 seconds: Mass vetting for new threats at the Google-Play scale. In 24th USENIX Security Symposium (USENIX Security\u201915) . USENIX Association, Washington, D.C., 659\u2013674. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity15\/technical-sessions\/presentation\/chen-kai."},{"key":"e_1_3_1_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/3180445.3180453"},{"key":"e_1_3_1_33_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCI.2018.8441295"},{"key":"e_1_3_1_34_2","unstructured":"The MITRE\n\t\t\t\t\t\t\tCorporation\n\t\t\t\t\t. 2021. Common Vulnerability and Exposures. Retrieved from https:\/\/www.cve.org\/."},{"key":"e_1_3_1_35_2","unstructured":"The MITRE\n\t\t\t\t\t\t\tCorporation\n\t\t\t\t\t. 2021. Common Weakness Enumeration. Retrieved from https:\/\/cwe.mitre.org\/."},{"key":"e_1_3_1_36_2","unstructured":"Mendeley\n\t\t\t\t\t\t\tData\n\t\t\t\t\t. 2020. Anrdoid Permission Dataset. Retrieved from https:\/\/data.mendeley.com\/datasets\/b4mxg7ydb7\/3."},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3197231.3197238"},{"key":"e_1_3_1_38_2","unstructured":"Ethics Advanced Technology Ltd.\n\t\t\t\t\t\t\t(EATL)\n\t\t\t\t\t. 2021. EATL App Store. Retrieved from http:\/\/eatlapps.com\/apps\/store."},{"issue":"1","key":"e_1_3_1_39_2","first-page":"23","article-title":"A systematic literature review of software vulnerability detection","volume":"10","author":"Eberendu Adanma Cecilia","year":"2022","unstructured":"Adanma Cecilia Eberendu , Valentine Ikechukwu Udegbe , Edmond Onwubiko Ezennorom , Anita Chinonso Ibegbulam , Titus Ifeanyi Chinebu , et\u00a0al. 2022. A systematic literature review of software vulnerability detection. Eur. J. Comp. Sci. Inf. Technol. 10, 1 (2022), 23\u201337. Retrieved from https:\/\/tudr.org\/id\/eprint\/284.","journal-title":"Eur. J. Comp. Sci. Inf. Technol."},{"key":"e_1_3_1_40_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102395"},{"key":"e_1_3_1_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653691"},{"key":"e_1_3_1_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382205"},{"key":"e_1_3_1_43_2","doi-asserted-by":"publisher","DOI":"10.1145\/2523514.2523539"},{"key":"e_1_3_1_44_2","unstructured":"Flankerhqd\n\t\t\t\t\t. 2016. JAADAS: Joint Advanced Application Defect Assessment for Android Application. Retrieved from https:\/\/github.com\/flankerhqd\/JAADAS."},{"key":"e_1_3_1_45_2","unstructured":"Python Software\n\t\t\t\t\t\t\tFoundation\n\t\t\t\t\t. 2019. Androguard. Retrieved from https:\/\/pypi.org\/project\/androguard\/."},{"key":"e_1_3_1_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/3376121"},{"key":"e_1_3_1_47_2","unstructured":"Erich\n\t\t\t\t\t\t\tGamma\n\t\t\t\t\t. 2022. JHotDraw. Retrieved from https:\/\/sourceforge.net\/projects\/jhotdraw\/."},{"key":"e_1_3_1_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2019.2956690"},{"key":"e_1_3_1_49_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2019.04.019"},{"key":"e_1_3_1_50_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-65610-2_6"},{"key":"e_1_3_1_51_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.102087"},{"key":"e_1_3_1_52_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2021.100372"},{"key":"e_1_3_1_53_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10207-016-0343-z"},{"key":"e_1_3_1_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3092566"},{"key":"e_1_3_1_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/3417113.3422188"},{"key":"e_1_3_1_56_2","doi-asserted-by":"publisher","DOI":"10.1145\/2307636.2307663"},{"key":"e_1_3_1_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/2857705.2857720"},{"key":"e_1_3_1_58_2","unstructured":"Ben\n\t\t\t\t\t\t\tGruver\n\t\t\t\t\t. 2022. Smali. Retrieved from https:\/\/github.com\/JesusFreke\/smali."},{"key":"e_1_3_1_59_2","unstructured":"Ciaran\n\t\t\t\t\t\t\tGultnieks\n\t\t\t\t\t. 2022. F-Droid\u2014Free and Open Source Android App Repository. Retrieved from https:\/\/f-droid.org\/."},{"key":"e_1_3_1_60_2","doi-asserted-by":"publisher","DOI":"10.1007\/s13198-020-01036-0"},{"key":"e_1_3_1_61_2","doi-asserted-by":"publisher","DOI":"10.1145\/3238147.3238197"},{"key":"e_1_3_1_62_2","unstructured":"Raimund\n\t\t\t\t\t\t\tHocke\n\t\t\t\t\t. 2022. RaiMan\u2019s Sikulix. http:\/\/sikulix.com\/."},{"key":"e_1_3_1_63_2","unstructured":"Huawei\n\t\t\t\t\t. 2022. AppGallery. Retrieved from https:\/\/appgallery.huawei.com\/Featured."},{"key":"e_1_3_1_64_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICICT.2017.8320163"},{"key":"e_1_3_1_65_2","unstructured":"Google\n\t\t\t\t\t\t\tInc.\n\t\t\t\t\t2020. Google Play. Retrieved from https:\/\/play.google.com\/."},{"key":"e_1_3_1_66_2","volume-title":"Software Abstractions: Logic, Language, and Analysis","author":"Jackson Daniel","year":"2012","unstructured":"Daniel Jackson . 2012. Software Abstractions: Logic, Language, and Analysis . The MIT Press, Cambridge, MA, London, England."},{"key":"e_1_3_1_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/ECACE.2019.8679493"},{"key":"e_1_3_1_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/2557547.2557549"},{"key":"e_1_3_1_69_2","unstructured":"Kaggle\n\t\t\t\t\t. 2020. Google Playstore Appsin Kaggle. Retrieved from https:\/\/www.kaggle.com\/gauthamp10\/google-playstore-apps."},{"key":"e_1_3_1_70_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11235-017-0296-1"},{"key":"e_1_3_1_71_2","doi-asserted-by":"publisher","DOI":"10.3390\/sym13010035"},{"issue":"2004","key":"e_1_3_1_72_2","first-page":"1","article-title":"Procedures for performing systematic reviews","volume":"33","author":"Kitchenham Barbara","year":"2004","unstructured":"Barbara Kitchenham . 2004. Procedures for performing systematic reviews. Keele, UK, Keele Univ. 33, 2004 (2004), 1\u201326. Retrieved from https:\/\/www.researchgate.net\/profile\/Barbara-Kitchenham\/publication\/228756057_Procedures_for_Performing_Systematic_Reviews\/links\/618cfae961f09877207f8471\/Procedures-for-Performing-Systematic-Reviews.pdf.","journal-title":"Keele, UK, Keele Univ."},{"key":"e_1_3_1_73_2","doi-asserted-by":"publisher","DOI":"10.1109\/TR.2018.2865733"},{"key":"e_1_3_1_74_2","doi-asserted-by":"publisher","DOI":"10.3390\/info12050185"},{"key":"e_1_3_1_75_2","unstructured":"Argus\n\t\t\t\t\t\t\tLab\n\t\t\t\t\t. 2020. Android Malware Dataset. Retrieved from http:\/\/amd.arguslab.org\/."},{"key":"e_1_3_1_76_2","unstructured":"XYSEC\n\t\t\t\t\t\t\tLabs\n\t\t\t\t\t. 2016. Devknox\u2014Security plugin for Android Studio. Retrieved from https:\/\/devknox.io\/."},{"key":"e_1_3_1_77_2","unstructured":"Patrick\n\t\t\t\t\t\t\tLam Eric\n\t\t\t\t\t\t\tBodden Ondrej\n\t\t\t\t\t\t\tLhot\u00e1k and \n\t\t\t\t\t\t\tLaurie\n\t\t\t\t\t\t\tHendren\n\t\t\t\t\t\t. 2011. The Soot framework for Java program analysis: a retrospective. Retrieved from http:\/\/soot-oss.github.io\/soot\/."},{"key":"e_1_3_1_78_2","doi-asserted-by":"publisher","DOI":"10.1145\/3077286.3077288"},{"key":"e_1_3_1_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2017.2789219"},{"key":"e_1_3_1_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/2931037.2931044"},{"key":"e_1_3_1_81_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2017.04.001"},{"key":"e_1_3_1_82_2","unstructured":"Yu-Cheng\n\t\t\t\t\t\t\tLin\n\t\t\t\t\t. 2015. AndroBugs. Retrieved from https:\/\/github.com\/AndroBugs\/."},{"key":"e_1_3_1_83_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2017.60"},{"key":"e_1_3_1_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2015.103"},{"key":"e_1_3_1_85_2","unstructured":"LinkedIn\n\t\t\t\t\t. 2015. Quick Android Review Kit (QARK). Retrieved from https:\/\/github.com\/linkedin\/qark\/."},{"key":"e_1_3_1_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3006143"},{"key":"e_1_3_1_87_2","doi-asserted-by":"publisher","DOI":"10.1145\/3544968"},{"key":"e_1_3_1_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISDFS.2019.8757523"},{"key":"e_1_3_1_89_2","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.ECOOP.2019.21"},{"key":"e_1_3_1_90_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66399-9_13"},{"key":"e_1_3_1_91_2","doi-asserted-by":"publisher","DOI":"10.1145\/2516760.2516768"},{"key":"e_1_3_1_92_2","doi-asserted-by":"publisher","DOI":"10.1145\/3021460.3021485"},{"key":"e_1_3_1_93_2","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(20)30028-2"},{"key":"e_1_3_1_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/QRS-C.2019.00033"},{"key":"e_1_3_1_95_2","doi-asserted-by":"publisher","DOI":"10.1145\/3448609"},{"key":"e_1_3_1_96_2","doi-asserted-by":"publisher","DOI":"10.24251\/HICSS.2021.839"},{"key":"e_1_3_1_97_2","unstructured":"Microsoft\n\t\t\t\t\t. 2022. Microsoft Malware Classification Challenge (Big 2015). Retrieved from https:\/\/www.kaggle.com\/c\/malware-classification\/."},{"key":"e_1_3_1_98_2","doi-asserted-by":"publisher","DOI":"10.1145\/3127005.3127010"},{"key":"e_1_3_1_99_2","doi-asserted-by":"publisher","DOI":"10.5555\/3370272.3370279"},{"issue":"10","key":"e_1_3_1_100_2","first-page":"2856","article-title":"Feature engineering based on hybrid features for malware detection over Android framework","volume":"12","author":"Nawaz Aqeel","year":"2021","unstructured":"Aqeel Nawaz et\u00a0al. 2021. Feature engineering based on hybrid features for malware detection over Android framework. Turk. J. Comput. Math. Educ. 12, 10 (2021), 2856\u20132864. Retrieved from https:\/\/www.turcomat.org\/index.php\/turkbilmat\/article\/view\/4931.","journal-title":"Turk. J. Comput. Math. Educ."},{"key":"e_1_3_1_101_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133977"},{"key":"e_1_3_1_102_2","unstructured":"University of\n\t\t\t\t\t\t\tBristol\n\t\t\t\t\t. 2021. Cyber Security Body of Knowledge. Retrieved from https:\/\/www.cybok.org\/tree\/#sps."},{"key":"e_1_3_1_103_2","unstructured":"University of New\n\t\t\t\t\t\t\tBrunswick\n\t\t\t\t\t. 2020. CICMaldroid Dataset. Retrieved from https:\/\/www.unb.ca\/cic\/datasets\/maldroid-2020.html."},{"key":"e_1_3_1_104_2","unstructured":"National Institute of\n\t\t\t\t\t\t\tStandards\n\t\t\t\t\t\t and \n\t\t\t\t\t\t\tTechnology\n\t\t\t\t\t\t. 2021. National Vulnerability Database. Retrieved from https:\/\/nvd.nist.gov\/vuln."},{"key":"e_1_3_1_105_2","unstructured":"National Institute of\n\t\t\t\t\t\t\tStandards\n\t\t\t\t\t\t and \n\t\t\t\t\t\t\tTechnology\n\t\t\t\t\t\t. 2021. Software Assurance Metrics And Tool Evaluation (SAMATE). Retrieved from https:\/\/www.nist.gov\/itl\/ssd\/software-quality-group\/samate."},{"key":"e_1_3_1_106_2","unstructured":"National Institute of\n\t\t\t\t\t\t\tStandards\n\t\t\t\t\t\t and \n\t\t\t\t\t\t\tTechnology\n\t\t\t\t\t\t. 2021. Static Analysis Tool Exposition (SATE) IV. Retrieved from https:\/\/www.nist.gov\/itl\/ssd\/software-quality-group\/static-analysis-tool-exposition-sate-iv."},{"key":"e_1_3_1_107_2","unstructured":"Botnet Research Team of Xi\u2019an Jiaotong\n\t\t\t\t\t\t\tUniversity\n\t\t\t\t\t. 2022. SandDroid\u2014An automatic Android application analysis system. Retrieved from http:\/\/sanddroid.xjtu.edu.cn\/."},{"key":"e_1_3_1_108_2","doi-asserted-by":"publisher","DOI":"10.1145\/3313391"},{"key":"e_1_3_1_109_2","unstructured":"OpenSecurity\n\t\t\t\t\t. 2015. Mobile Security Framework (MobSF). Retrieved from https:\/\/github.com\/MobSF\/Mobile-Security-Framework-MobSF."},{"key":"e_1_3_1_110_2","doi-asserted-by":"publisher","DOI":"10.1136\/bmj.n71"},{"key":"e_1_3_1_111_2","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2017.7884659"},{"key":"e_1_3_1_112_2","unstructured":"Bob\n\t\t\t\t\t\t\tPan\n\t\t\t\t\t. 2022. dex2jar. Retrieved from https:\/\/github.com\/pxb1988\/dex2jar."},{"key":"e_1_3_1_113_2","doi-asserted-by":"publisher","DOI":"10.1145\/3094243.3094245"},{"key":"e_1_3_1_114_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-15-9647-6_95"},{"key":"e_1_3_1_115_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR.2019.00064"},{"key":"e_1_3_1_116_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00094"},{"key":"e_1_3_1_117_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.2998043"},{"key":"e_1_3_1_118_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASEW52652.2021.00020"},{"key":"e_1_3_1_119_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-019-09749-y"},{"key":"e_1_3_1_120_2","unstructured":"Renas\n\t\t\t\t\t. 2016. RobotiumTech\/robotium: Android UI Testing. Retrieved from https:\/\/github.com\/RobotiumTech\/robotium."},{"key":"e_1_3_1_121_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_2"},{"key":"e_1_3_1_122_2","unstructured":"Vlad\n\t\t\t\t\t\t\tRoubtsov\n\t\t\t\t\t. 2005. EMMA: a free Java code coverage tool. Retrieved from http:\/\/emma.sourceforge.net\/."},{"key":"e_1_3_1_123_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICMLA.2018.00120"},{"key":"e_1_3_1_124_2","doi-asserted-by":"publisher","DOI":"10.1145\/2523649.2523678"},{"key":"e_1_3_1_125_2","unstructured":"Virus\n\t\t\t\t\t\t\tSamples\n\t\t\t\t\t. 2020. Github Malware Dataset. Retrieved from https:\/\/github.com\/topics\/malware-dataset."},{"key":"e_1_3_1_126_2","doi-asserted-by":"publisher","DOI":"10.1109\/I-SMAC47947.2019.9032440"},{"key":"e_1_3_1_127_2","unstructured":"360\n\t\t\t\t\t\t\tSecurity\n\t\t\t\t\t. 2022. Qihoo. Retrieved from http:\/\/zhushou.360.cn\/."},{"key":"e_1_3_1_128_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics10131606"},{"key":"e_1_3_1_129_2","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3527290"},{"key":"e_1_3_1_130_2","unstructured":"Janaka\n\t\t\t\t\t\t\tSenanayake Harsha\n\t\t\t\t\t\t\tKalutarage Mhd Omar\n\t\t\t\t\t\t\tAl-Kadri Andrei\n\t\t\t\t\t\t\tPetrovski and \n\t\t\t\t\t\t\tLuca\n\t\t\t\t\t\t\tPiras\n\t\t\t\t\t\t. 2022. LVDAndro: Labelled Vulnerability Dataset on Android Source Code. Retrieved from https:\/\/github.com\/softwaresec-labs\/LVDAndro."},{"key":"e_1_3_1_131_2","doi-asserted-by":"publisher","DOI":"10.1109\/SCSE53661.2021.9568333"},{"key":"e_1_3_1_132_2","doi-asserted-by":"publisher","DOI":"10.5121\/ijdkp.2018.8503"},{"key":"e_1_3_1_133_2","unstructured":"A.\n\t\t\t\t\t\t\tShabtai Y.\n\t\t\t\t\t\t\tFledel U.\n\t\t\t\t\t\t\tKanonov Y.\n\t\t\t\t\t\t\tElovici and \n\t\t\t\t\t\t\tS.\n\t\t\t\t\t\t\tDolev\n\t\t\t\t\t\t. 2009. Google Android: A State-of-the-art Review of Security Mechanisms. arxiv:0912.5101 [cs.CR]."},{"key":"e_1_3_1_134_2","doi-asserted-by":"publisher","DOI":"10.1109\/NSysS.2017.7885802"},{"key":"e_1_3_1_135_2","first-page":"397","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Sikder Amit Kumar","year":"2017","unstructured":"Amit Kumar Sikder , Hidayet Aksu , and A. Selcuk Uluagac . 2017. 6thSense: A context-aware sensor-based attack detector for smart devices. In 26th USENIX Security Symposium (USENIX Security 17) . USENIX Association, 397\u2013414. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/sikder."},{"key":"e_1_3_1_136_2","unstructured":"Statcounter\n\t\t\t\t\t. 2021. Mobile Operating System Market Share Worldwide. Retrieved from https:\/\/gs.statcounter.com\/os-market-share\/mobile\/worldwide\/%20."},{"key":"e_1_3_1_137_2","unstructured":"Statista\n\t\t\t\t\t. 2021. Number of mobile phone users worldwide from 2016 to 2023 (in billions). Retrieved from https:\/\/www.statista.com\/statistics\/330695\/number-of-smartphone-users-worldwide\/."},{"key":"e_1_3_1_138_2","unstructured":"Steppa\n\t\t\t\t\t. 2020. Intel Security\/MacAfee. Retrieved from https:\/\/steppa.ca\/portfolio-view\/malware-threat-intel-datasets\/."},{"key":"e_1_3_1_139_2","doi-asserted-by":"publisher","DOI":"10.1109\/DASC-PICom-DataCom-CyberSciTec.2017.24"},{"key":"e_1_3_1_140_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2020.102483"},{"key":"e_1_3_1_141_2","unstructured":"Shenzhen Tencent Computer\n\t\t\t\t\t\t\tSystem\n\t\t\t\t\t. 2018. YingYongBao. Retrieved from https:\/\/android.myapp.com\/."},{"key":"e_1_3_1_142_2","doi-asserted-by":"publisher","DOI":"10.1145\/3411764.3445616"},{"key":"e_1_3_1_143_2","doi-asserted-by":"publisher","DOI":"10.1007\/s11235- 019-00575-7"},{"key":"e_1_3_1_144_2","doi-asserted-by":"publisher","DOI":"10.26599\/TST.2019.9010067"},{"key":"e_1_3_1_145_2","unstructured":"Sergey\n\t\t\t\t\t\t\tTarasevich\n\t\t\t\t\t. 2022. Android Universal Image Loader. Retrieved from https:\/\/github.com\/nostra13\/Android-Universal-Image-Loader."},{"key":"e_1_3_1_146_2","unstructured":"APKPure\n\t\t\t\t\t\t\tTeam\n\t\t\t\t\t. 2020. APKPure. Retrieved from https:\/\/m.apkpure.com\/."},{"key":"e_1_3_1_147_2","unstructured":"Tracxn\n\t\t\t\t\t\t\tTechnologies\n\t\t\t\t\t. 2021. AppChina. Retrieved from https:\/\/tracxn.com\/d\/companies\/appchina.com\/."},{"key":"e_1_3_1_148_2","unstructured":"Beijing Zhuoyixunchang\n\t\t\t\t\t\t\tTechnology\n\t\t\t\t\t. 2020. Wandoujia App Market. Retrieved from https:\/\/www.wandoujia.com\/apps\/."},{"key":"e_1_3_1_149_2","unstructured":"Tencent\n\t\t\t\t\t. 2020. Tencent PC Manager. Retrieved from https:\/\/www.pcmgr-global.com\/."},{"key":"e_1_3_1_150_2","unstructured":"Impact Cyber\n\t\t\t\t\t\t\tTrust\n\t\t\t\t\t. 2020. Contagio. Retrieved from https:\/\/www.impactcybertrust.org\/dataset_view?idDataset=1273."},{"key":"e_1_3_1_151_2","unstructured":"Connor\n\t\t\t\t\t\t\tTumbleson\n\t\t\t\t\t\t and \n\t\t\t\t\t\t\tRyszard\n\t\t\t\t\t\t\tWi\u015bniewski\n\t\t\t\t\t\t. 2010. Apktool V2.5.0\u2014A tool for reverse engineering Android apk files. Retrieved from https:\/\/ibotpeaches.github.io\/Apktool\/."},{"key":"e_1_3_1_152_2","unstructured":"Raja\n\t\t\t\t\t\t\tVallee-Rai\n\t\t\t\t\t\t and \n\t\t\t\t\t\t\tLaurie J.\n\t\t\t\t\t\t\tHendren\n\t\t\t\t\t\t. 1998. Jimple: Simplifying Java Bytecode for Analyses and Transformations."},{"key":"e_1_3_1_153_2","unstructured":"VirusShare\n\t\t\t\t\t. 2020. VirusShare\u2014Because Sharing is Caring. Retrieved from https:\/\/virusshare.com\/."},{"key":"e_1_3_1_154_2","unstructured":"Wala\n\t\t\t\t\t. 2022. T. J. Watson Libraries for Analysis. Retrieved from http:\/\/wala.sourceforge.net\/."},{"key":"e_1_3_1_155_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2020.110609"},{"key":"e_1_3_1_156_2","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660357"},{"key":"e_1_3_1_157_2","doi-asserted-by":"publisher","DOI":"10.1145\/3106237.3106294"},{"key":"e_1_3_1_158_2","doi-asserted-by":"publisher","DOI":"10.1002\/spe.2774"},{"key":"e_1_3_1_159_2","unstructured":"Christian\n\t\t\t\t\t\t\tWilliams\n\t\t\t\t\t. 2017. Roboelectric. Retrieved from http:\/\/robolectric.org\/."},{"key":"e_1_3_1_160_2","doi-asserted-by":"publisher","DOI":"10.1145\/2601248.2601268"},{"key":"e_1_3_1_161_2","doi-asserted-by":"publisher","DOI":"10.1109\/CompComm.2017.8322752"},{"key":"e_1_3_1_162_2","first-page":"539","volume-title":"21st USENIX Security Symposium (USENIX Security\u201912)","author":"Xu Rubin","year":"2012","unstructured":"Rubin Xu , Hassen Sa\u00efdi , and Ross Anderson . 2012. Aurasium: Practical policy enforcement for Android applications. In 21st USENIX Security Symposium (USENIX Security\u201912) . USENIX Association, 539\u2013552. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity12\/technical-sessions\/presentation\/xu_rubin."},{"key":"e_1_3_1_163_2","first-page":"569","volume-title":"21st USENIX Security Symposium (USENIX Security\u201912)","author":"Yan Lok Kwong","year":"2012","unstructured":"Lok Kwong Yan and Heng Yin . 2012. DroidScope: Seamlessly reconstructing the OS and Dalvik semantic views for dynamic Android malware analysis. In 21st USENIX Security Symposium (USENIX Security\u201912) . USENIX Association, 569\u2013584. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity12\/technical-sessions\/presentation\/yan."},{"key":"e_1_3_1_164_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2017.04.007"},{"key":"e_1_3_1_165_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00150"},{"key":"e_1_3_1_166_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-64701-2_13"},{"key":"e_1_3_1_167_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2019.00030"},{"key":"e_1_3_1_168_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.16"},{"key":"e_1_3_1_169_2","first-page":"50","volume-title":"NDSS","author":"Zhou Yajin","year":"2012","unstructured":"Yajin Zhou , Zhi Wang , Wu Zhou , and Xuxian Jiang . 2012. Hey, you, get off of my market: Detecting malicious apps in official and alternative Android markets. In NDSS , Vol. 25. NDSS, 50\u201352."},{"key":"e_1_3_1_170_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICISCE.2017.124."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3556974","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3556974","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T22:48:52Z","timestamp":1750286932000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3556974"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,16]]},"references-count":169,"journal-issue":{"issue":"9","published-print":{"date-parts":[[2023,9,30]]}},"alternative-id":["10.1145\/3556974"],"URL":"https:\/\/doi.org\/10.1145\/3556974","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1,16]]},"assertion":[{"value":"2021-12-04","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-08-08","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-01-16","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}