{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:33:32Z","timestamp":1783611212765,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":43,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3736205","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:30:56Z","timestamp":1755066656000},"page":"1567-1581","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["PRISM: To Fortify Widget Based User-App Data Exchanges Using Android Virtualization Framework"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-7066-6065","authenticated-orcid":false,"given":"YingTat","family":"Ng","sequence":"first","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-4095-8155","authenticated-orcid":false,"given":"Zhe","family":"Chen","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-9978-249X","authenticated-orcid":false,"given":"Haiqing","family":"Qiu","sequence":"additional","affiliation":[{"name":"Singapore Management University, singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3974-590X","authenticated-orcid":false,"given":"Xuhua","family":"Ding","sequence":"additional","affiliation":[{"name":"Singapore Management University, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"2022. Microdroid Demo App. https:\/\/android.googlesource.com\/platform\/packages\/modules\/Virtualization\/+\/refs\/heads\/android13-d1-release\/demo\/https:\/\/android.googlesource.com\/platform\/packages\/modules\/Virtualization\/+\/refs\/heads\/android13-d1-release\/demo."},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243778"},{"key":"e_1_3_3_2_4_2","volume-title":"Arm Frame Buffer Compressions (AFBC)","year":"2025","unstructured":"ARM. 2025. Arm Frame Buffer Compressions (AFBC). https:\/\/arm.com\/technologies\/graphics-technologies\/arm-frame-buffer-compression"},{"key":"e_1_3_3_2_5_2","volume-title":"New mobile malware family now also targets Belgian financial apps","author":"Beckers Jeroen","year":"2021","unstructured":"Jeroen Beckers. 2021. New mobile malware family now also targets Belgian financial apps. https:\/\/blog.nviso.eu\/2021\/05\/11\/new-malware-family-now-also-targets-belgian-financial-apps\/ https:\/\/blog.nviso.eu\/2021\/05\/11\/new-malware-family-now-also-targets-belgian-financial-apps\/."},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.62"},{"key":"e_1_3_3_2_7_2","unstructured":"Sen Chen Lingling Fan Chunyang Chen Minhui Xue Yang Liu and Lihua Xu. 2021. GUI-Squatting Attack: Automated Generation of Android Phishing Apps. IEEE Transactions on Dependable and Secure Computing 18 6 (2021) 2551\u20132568."},{"key":"e_1_3_3_2_8_2","series-title":"(ASIA CCS)","first-page":"1630","volume-title":"Proceedings of the ACM Asia Conference on Computer and Communications Security","author":"Choe Yurak","year":"2024","unstructured":"Yurak Choe, Hyungseok Yu, Taeho Kim, Shinjae Lee, Hojoon Lee, and Hyoungshick Kim. 2024. (In)visible Privacy Indicator: Security Analysis of Privacy Indicator on Android Devices. In Proceedings of the ACM Asia Conference on Computer and Communications Security(ASIA CCS). 1630\u20131643."},{"key":"e_1_3_3_2_9_2","unstructured":"Lucian Constantin. 2019. Emergent Android Banking trojan shows app overlay attacks are still effective. https:\/\/www.csoonline.com\/article\/3455136\/emergent-android-banking-trojan-shows-app-overlay-attacks-are-still-effective.html"},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/2702123.2702300"},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.39"},{"key":"e_1_3_3_2_12_2","volume-title":"Android Open Source Project","year":"2024","unstructured":"Google. 2024. Android Open Source Project. https:\/\/source.android.com\/docs\/core\/virtualization\/architecture"},{"key":"e_1_3_3_2_13_2","unstructured":"Google. 2024. Android Protected Confirmation. https:\/\/developer.android.com\/privacy-and-security\/security-android-protected-confirmation"},{"key":"e_1_3_3_2_14_2","unstructured":"Google. 2024. Android Verified Boot. https:\/\/source.android.com\/docs\/security\/features\/verifiedboot\/avb"},{"key":"e_1_3_3_2_15_2","unstructured":"Google. 2024. Device Identifier Composition Engine. https:\/\/source.android.com\/docs\/security\/features\/dice"},{"key":"e_1_3_3_2_16_2","unstructured":"Google. 2024. Microdroid : Android Open Source Project. (2024). https:\/\/source.android.com\/docs\/core\/virtualization\/microdroid"},{"key":"e_1_3_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP48549.2020.00043"},{"key":"e_1_3_3_2_18_2","first-page":"665","volume-title":"Proceedings of the 33rd USENIX Security Symposium","author":"Li Jiawei","year":"2024","unstructured":"Jiawei Li, Jian Mao, Jun Zeng, Qixiao Lin, Shaowen Feng, and Zhenkai Liang. 2024. UIHash: Detecting Similar Android UIs through Grid-Based Visual Appearance Representation. In Proceedings of the 33rd USENIX Security Symposium. 665\u2013682."},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1145\/3210240.3210330"},{"key":"e_1_3_3_2_20_2","series-title":"(S&P)","first-page":"620","volume-title":"Proceedings of the IEEE Symposium on Security and Privacy","author":"Maruyama Seita","year":"2019","unstructured":"Seita Maruyama, Satohiro Wakabayashi, and Tatsuya Mori. 2019. Tap \u2019n Ghost: A Compilation of Novel Attack Techniques against Smartphone Touchscreens. In Proceedings of the IEEE Symposium on Security and Privacy(S&P). 620\u2013637."},{"key":"e_1_3_3_2_21_2","unstructured":"Charlie Osborne. 2020. This new Android mobile malware targets banks financial services across Europe. https:\/\/www.zdnet.com\/article\/this-new-android-mobile-malware-is-striking-banks-financial-services-across-europe\/ https:\/\/www.zdnet.com\/article\/this-new-android-mobile-malware-is-striking-banks-financial-services-across-europe\/."},{"key":"e_1_3_3_2_22_2","unstructured":"Amer Owaida. 2020. Critical Android flaw lets attackers hijack almost any app steal data. https:\/\/www.welivesecurity.com\/2020\/05\/27\/critical-android-flaw-lets-attackers-hijack-almost-any-app-steal-data\/"},{"key":"e_1_3_3_2_23_2","volume-title":"Time to update: Google\u2019s Android updates fixes 41 flaws, five critical","author":"Palmer Danny","year":"2022","unstructured":"Danny Palmer. 2022. Time to update: Google\u2019s Android updates fixes 41 flaws, five critical. https:\/\/www.zdnet.com\/article\/android-security-google-updates-fix-these-five-critical-vulnerabilities\/ https:\/\/www.zdnet.com\/article\/android-security-google-updates-fix-these-five-critical-vulnerabilities\/."},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3458864.3467887"},{"key":"e_1_3_3_2_25_2","volume-title":"Screen Recorder - XRecorder","author":"Play Google","year":"2025","unstructured":"Google Play. 2025. Screen Recorder - XRecorder. https:\/\/play.google.com\/store\/apps\/details?id=videoeditor.videorecorder.screenrecorder"},{"key":"e_1_3_3_2_26_2","volume-title":"Twilight: Blue light filter","author":"Play Google","year":"2025","unstructured":"Google Play. 2025. Twilight: Blue light filter. https:\/\/play.google.com\/store\/apps\/details?id=com.urbandroid.lux"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243785"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2017.23529"},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.5555\/2831143.2831203"},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3081333.3081346"},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"crossref","unstructured":"Emil Stefanov Marten\u00a0van Dijk Elaine Shi T-H\u00a0Hubert Chan Christopher Fletcher Ling Ren Xiangyao Yu and Srinivas Devadas. 2018. Path ORAM: an extremely simple oblivious RAM protocol. Journal of the ACM (JACM) 65 4 (2018) 1\u201326.","DOI":"10.1145\/3177872"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/2766498.2766508"},{"key":"e_1_3_3_2_33_2","first-page":"415","volume-title":"Proceedings of the 29th USENIX Security Symposium","author":"Tuncay Guliz\u00a0Seray","year":"2020","unstructured":"Guliz\u00a0Seray Tuncay, Jingyu Qian, and Carl\u00a0A Gunter. 2020. See no evil: Phishing for permissions with false transparency. In Proceedings of the 29th USENIX Security Symposium. 415\u2013432."},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.36"},{"key":"e_1_3_3_2_35_2","first-page":"137","volume-title":"Proceedings of the 31st USENIX Security Symposium","author":"Wang Kai","year":"2022","unstructured":"Kai Wang, Richard Mitev, Chen Yan, Xiaoyu Ji, Ahmad-Reza Sadeghi, and Wenyuan Xu. 2022. GhostTouch: Targeted Attacks on Touchscreens without Physical Touch. In Proceedings of the 31st USENIX Security Symposium. 137\u2013140."},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.24097"},{"key":"e_1_3_3_2_37_2","series-title":"(USENIX ATC)","first-page":"321","volume-title":"Proceedings of the USENIX Annual Technical Conference","author":"Wendlandt Dan","year":"2008","unstructured":"Dan Wendlandt and Adrian Perrig. 2008. Perspectives: Improving SSH-style Host Authentication with Multi-Path Probing. In Proceedings of the USENIX Annual Technical Conference(USENIX ATC). 321\u2013334."},{"key":"e_1_3_3_2_38_2","series-title":"(NDSS)","first-page":"139","volume-title":"Proceedings of the Network and Distributed System Security Symposium","author":"Williams Peter","year":"2008","unstructured":"Peter Williams and Radu Sion. 2008. Usable PIR. In Proceedings of the Network and Distributed System Security Symposium(NDSS). 139\u2013152."},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3307334.3326094"},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3210240.3210338"},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3292006.3300035"},{"key":"e_1_3_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897897"},{"key":"e_1_3_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.42"},{"key":"e_1_3_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.27"}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3736205","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:30:35Z","timestamp":1755070235000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3736205"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":43,"alternative-id":["10.1145\/3708821.3736205","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3736205","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}