REVIEW 3 major objections 5 minor 57 references
An Empirical Study of Code Obfuscation Practices in the Google Play Store
T0 review · 3 major / 5 minor · reviewed 2026-08-08 · deepseek-v4-flash
Pith's one-line read This paper claims that code obfuscation in Google Play rose by about 13 percentage points from 2016 to 2023, so that a majority of the store's apps are now obfuscated.
desk verdict A valuable large-scale snapshot of Android obfuscation whose headline time trend is likely a cohort artifact from pooling two crawls by last-update date. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The machinery is a bank of supervised classifiers over 37 static APK features: the percentage of class, method, field, and string names by length (1, 2, 3, 4, >4) and by presence of special or numeric characters, plus the share of nop, goto, invoke, if, and move instructions in the DEX bytecode. A binary multilayer perceptron decides whether an app is obfuscated; three one-vs-rest random-forest classifiers decide between ProGuard, Allatori, or DashO against an 'other' class; and three more random forests decide whether identifier renaming, control-flow modification, or string encryption is present. The classifiers are trained on apps built from open-source projects and obfuscated in the lab with the three tools, then validated on unseen in-lab apps, on an obfuscated-malware set produced by a different tool, and on 50 manually labelled Play apps. This feature-based transfer is what lets the authors scale the detection to half a million real-world APKs.
What would settle it
Manually reverse-engineer a few hundred randomly selected 2023 Play APKs: if the independently measured obfuscation fraction and the ProGuard/Allatori split differ systematically from the paper's 66% and 40.92%/36.64%, then the trend is an artifact of classifier transfer.
Extended reading notes
Core claim
The central discovery is longitudinal: between 2016 and 2023 the fraction of obfuscated Google Play apps increased by about 13 percentage points, from a stable 50-55% range in 2016-2018 to about 66% in 2023, and roughly 56% of all 548,967 analyzed APKs are obfuscated. The paper attributes most obfuscation to two tools — ProGuard at 40.92% of obfuscated apps and Allatori at 36.64% — with DashO at 1.01% and a substantial 21.43% bucket of unknown tools. Identifier renaming is nearly universal among obfuscated apps (99.62%), while control-flow modification appears in 81.04% and string encryption in 62.76%, and 58.7% of obfuscated apps combine all three techniques. Obfuscation is not uniform: casino games lead at 80%, game genres generally sit above other categories, over 90% of top-1,000 apps are obfuscated, and even single-app developers moved from 45.5% to 57.2% obfuscation between the two snapshots.
Load-bearing premise
The classifiers were trained largely on APKs the authors obfuscated themselves with ProGuard, Allatori, and DashO, and the paper assumes those feature patterns represent the whole Google Play population, including apps obfuscated with unknown tools, for which the authors write there is no accurate ground-truth method.
Editorial extensions
If this is right
- Static analysis that ignores obfuscation will misread a majority of current Play apps, since 56.25% of analyzed APKs are obfuscated and the share was still rising in 2023.
- Deobfuscation research must handle combinations: 58.7% of obfuscated apps use all three main techniques, so single-technique deobfuscators cover a minority of real apps.
- Identifier renaming is the near-universal first step (99.62%), so symbol-recovery heuristics will be a prerequisite for almost any code-level analysis of Play apps.
- The large unknown-tool bucket (21.43%) means the market is not captured by the three studied tools, and detectors designed for a closed tool set will silently push new tools into the 'other' category.
- Obfuscation is no longer a signal of sophistication: single-app developers' usage rose from 45.5% to 57.2%, so small and amateur apps are now obfuscated too.
Reading between the lines
- If the trend continues past 2023, app-store security screening may need to switch from asking whether code is obfuscated to asking what the obfuscation is hiding, since benign and malicious apps both obfuscate.
- The paper does not separate library-level obfuscation from app-level obfuscation; a natural next test is to check whether the 13-point rise is driven by new default build tools rather than by deliberate developer choice.
- The 21.43% unknown-tool share is likely an undercount of commercial hardening tools that resemble ProGuard; a testable extension is to add a DexGuard-trained class and see how much of the ProGuard and 'other' buckets move.
- Because the features are name-length and instruction-frequency statistics, apps obfuscated only through string encryption with normal-looking identifiers could evade the detectors; building a validation set from manually labelled Play apps with diverse real-world tools would test whether 56.25% holds.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents a large-scale empirical study of code obfuscation adoption in Google Play, analyzing 548,967 APKs from two crawls (2018 and 2023) spanning last-update years 2016-2023. The authors build a bank of machine-learning classifiers to detect (i) whether an APK is obfuscated, (ii) which obfuscation tool was used (ProGuard, Allatori, DashO, or other), and (iii) which obfuscation techniques are present (identifier renaming, control-flow modification, string encryption). They report an overall 13 percentage-point increase in obfuscation between 2016 and 2023, with 56.25% of all analyzed APKs obfuscated, ProGuard and Allatori as the dominant tools, and the Casino genre the most obfuscated at 80%. They additionally report genre-wise, developer-wise, and top-k analyses showing higher obfuscation among top-ranked apps and top developers.
Significance. If the results are reliable, this would be the first large-scale longitudinal account of obfuscation adoption in Google Play, with direct implications for malware analysis, app-store policy, and developer practice. A credible measurement that obfuscation now covers a majority of Play apps and is growing would be a useful reference point for the security community. The paper has strengths: it uses a large sample, it validates classifiers on multiple held-out sets, it releases source code and models, and it draws on externally generated ground truth (F-droid projects and AndroOBFS). These strengths make the core measurement apparatus worth scrutiny rather than dismissal. However, the central longitudinal claim rests on a year-labeling and cohort-construction choice that may induce the observed trend, and the real-world validation of the classifiers is extremely thin. The headline percentages are point estimates without uncertainty quantification, and the authors themselves acknowledge the limitation that no accurate ground truth exists for real-world APKs.
major comments (3)
- [Section IV-A, Table IX, Figure 2, Section V-A] The '13% increase between 2016 and 2023' may be an artifact of how years are assigned. Year labels come from the metadata field 'last update date', and the APK pool is formed by merging two crawls with very different coverage: 1,023,521 APKs from 2018 and 395,396 from 2023, as shown in Table IX. Apps last updated in 2016 are, by construction, apps untouched for at least two years at the time of the 2018 crawl and therefore likely abandoned, whereas apps last updated in 2023 are actively maintained. The paper excludes 2019-2020 because those apps are 'more likely to be abandoned by app developers' (Section IV-A), but applies no such control to 2016-2018. The apparent increase from about 53% (2016-2018) to about 62% (2021-2023) could reflect the difference between abandoned and active apps, or between the two crawl cohorts, rather than an evolution of obfuscation practice. The claim in Section VII-B that 'overall trends we observed are unlikely to change even including those data' is asserted without evidence and does not address the cohort confound. To make the longitudinal claim load-bearing, the authors should compare apps under conditions that control for maintenance status, for example by restricting to apps updated within one year before each crawl, by tracking the same apps across both crawls, or by showing that the trend persists within each crawl when stratifying by time since last update.
- [Section III-C, Section III-D, Table VI, Section VII-B] The external validity of the headline percentages is not established. The classifiers are trained on F-droid apps manually obfuscated with ProGuard, Allatori, and DashO, plus the AndroOBFS malware set, but the only real-world validation is D4, a set of 50 manually labeled Google Play APKs (Section III-C1, Table VI). The authors themselves note that 'with real-world APKs, there is no method for accurate ground-truth establishment' (Section VII-B). With only 50 Play apps, the 92% accuracy on D4 carries a wide confidence interval, and the D4 labels were based solely on identifier-name anomalies, which may not capture other obfuscation forms. The tool and technique detectors are validated only on D6 and D8/D9, which are drawn from the same manually obfuscated F-droid and AndroOBFS distributions; no real-world validation of tool or technique identification is performed. The reported 40.92% ProGuard and 36.64% Allatori shares, and the technique breakdown in Section V-A, can therefore be substantially biased if real-world obfuscators produce feature distributions different from the training distributions. The paper should either provide a larger and more diverse real-world validation set, report bounds on the headline estimates under plausible label-error rates, or temper the claims accordingly.
- [Section V, Tables VI-VIII and XI] All headline percentages are reported as point estimates without any uncertainty quantification. For example, Figure 2 plots yearly obfuscation percentages, and Table XI reports top-k percentages to two decimal places, yet no confidence intervals, standard errors, or sensitivity analyses are given. Because each percentage is the output of a classifier with known misclassification rates on held-out data, and because the samples are large but not exhaustive, the absence of uncertainty intervals makes it difficult to judge whether differences such as the 13-point trend, or the differences between genres in Figure 5, are statistically meaningful. The authors should at least report binomial confidence intervals for the large-sample percentages and, where possible, propagate classifier error rates into the final estimates.
minor comments (5)
- [Section IV-A, Table IX] The table would benefit from a column showing the number of analyzed APKs as a percentage of available APKs for each year, since the sampling rate differs widely (e.g., 2016 has 74,817 of 174,136 analyzed, while 2023 has 65,543 of 65,697 analyzed).
- [Section VII-B] The limitation paragraph says the 2019-2020 exclusion is unlikely to change overall trends, but this is not supported by any sensitivity analysis; either provide such an analysis or soften the claim to acknowledge that the trend is measured only on the 2016-2018 and 2021-2023 cohorts.
- [Section III-D, Table VIII] In the D9 rows, precision values of 1.00 for IR, CF, and SE are suspiciously perfect and suggest the AndroOBFS labels may align very closely with the feature thresholds; a short explanation or discussion of why precision is exactly 1.00 would help readers interpret these results.
- [Section V-A, Figure 4] The category labels in Figure 4 (e.g., 'Only IR', 'IR & CF') are embedded in the figure body, while the legend below contains only 'Category' and numeric row labels; this makes the figure hard to read, and the numeric rows should be clearly associated with their category names.
- [General] The paper repeatedly calls the study 'first of its kind' (Abstract, Section VI-B), but OBFUSCAN is cited as a prior large-scale investigation of obfuscation use in Google Play; the novelty claim should be phrased more precisely, e.g., as the first to cover multiple tools and techniques over an eight-year span.
Circularity Check
No central circularity: the main measurements come from classifiers trained on externally generated F-droid and AndroOBFS ground truth; only the D4 Play-store validation is self-referential.
-
self definitional
[Section III-C.1 (Datasets for Obfuscation Detector, dataset D4)]
"To strengthen the validation of our obfuscation detector, we also randomly selected 50 APKs from the Google Play Store and manually labelled them. We examined the identifier names of each APK to identify any anomalies or deviations in natural language. APKs were labelled as obfuscated if anomalies were observed in the identifier names; otherwise, they were labelled as non-obfuscated."
The D4 ground-truth label is defined by 'anomalies ... in the identifier names', which is exactly the signal captured by the classifier's identifier features (Table II: percentages of class/method/field names by length, special characters, and numeric characters). Thus D4 does not independently validate the detector on real-world Play apps; it only checks that the classifier reproduces a label derived from the same identifier-name cue. The paper uses the D4 result (92% accuracy in Table VI) as evidence that the detector is suitable for the large-scale Play-store analysis, so this validation step is partly circular.
full rationale
The paper's derivation chain is otherwise self-contained against external ground truth. The obfuscation, tool, and technique classifiers are trained on manually built APKs from F-droid (obfuscation enabled/disabled with known tools) and on the externally published AndroOBFS malware dataset, then applied to 548,967 Play-store APKs. The reported 56.25% obfuscated figure and the 13% 2016-2023 increase are predictions from those externally trained models, not quantities defined by the models' own inputs. The use of the authors' previous crawl [41], [42] as the source of the 2018 snapshot is a data-provenance self-citation, not a load-bearing circular argument. The skeptic's cohort-artifact concern about 'last update date' pooling across two unbalanced crawls is a validity threat, not a circularity: the trend could be biased without being logically forced by the paper's definitions. The only genuine circular element is the D4 manual validation set, whose labels are generated from the same identifier-name anomaly cue that dominates the classifier features, making the 92% real-world accuracy claim partially self-confirming. Because this validation is supplementary rather than the basis of the main trend numbers, the appropriate score is 2 rather than higher.
Assumptions & free parameters
free parameters (2)
- Probability threshold of 0.5 =
0.5
- Model hyperparameters =
grid-searched, final values not reported
assumptions (4)
- domain assumption Androguard extracts class names, method names, field names, strings, and instruction frequencies from DEX files accurately enough for the 37 features.
- domain assumption Apps from F-droid, obfuscated with the three selected tools, are representative enough of Google Play obfuscation to train transferable classifiers.
- domain assumption The 'last update date' metadata field is an adequate proxy for assigning an app to a year for trend analysis.
- domain assumption Obfuscation is detectable from the set of 37 static features (identifier lengths, special characters, instruction ratios).
Cite this review
Pith. "Pith review of An Empirical Study of Code Obfuscation Practices in the Google Play Store." pith.science (2026). https://pith.science/paper/47YTF57Y
@misc{pith2026250204636,
author = {Pith},
title = {Pith review of: An Empirical Study of Code Obfuscation Practices in the Google Play Store},
year = {2026},
howpublished = {\url{https://pith.science/paper/47YTF57Y}},
note = {Machine review of arXiv:2502.04636}
}
read the original abstract
The Android ecosystem is vulnerable to issues such as app repackaging, counterfeiting, and piracy, threatening both developers and users. To mitigate these risks, developers often employ code obfuscation techniques. However, while effective in protecting legitimate applications, obfuscation also hinders security investigations as it is often exploited for malicious purposes. As such, it is important to understand code obfuscation practices in Android apps. In this paper, we analyze over 500,000 Android APKs from Google Play, spanning an eight-year period, to investigate the evolution and prevalence of code obfuscation techniques. First, we propose a set of classifiers to detect obfuscated code, tools, and techniques and then conduct a longitudinal analysis to identify trends. Our results show a 13% increase in obfuscation from 2016 to 2023, with ProGuard and Allatori as the most commonly used tools. We also show that obfuscation is more prevalent in top-ranked apps and gaming genres such as Casino apps. To our knowledge, this is the first large-scale study of obfuscation adoption in the Google Play Store, providing insights for developers and security analysts.
Figures
Figures from the paper (4 more)
Reference graph
Works this paper leans on
-
[1]
State of obfuscation: A longitudinal study of code obfuscation practices in Google Play Store,
A. Niroshan, S. Seneviratne, and A. Seneviratne, “State of obfuscation: A longitudinal study of code obfuscation practices in Google Play Store,” to appear in Proceedings of the 40th ACM/SIGAPP Symposium on Applied Computing (SAC) , 2025
work page 2025
- [2]
-
[3]
Number of Android applications on the Google Play Store — appbrain,
“Number of Android applications on the Google Play Store — appbrain,” AppBrain, 05 2024. [Online]. Available: https://www. appbrain.com/stats/number-of-android-apps
work page 2024
-
[4]
Android security assessment: A review, taxonomy and research gap study,
S. Garg and N. Baliyan, “Android security assessment: A review, taxonomy and research gap study,” Computers & Security , vol. 100, p. 102087, 2021. [Online]. Available: https://www.sciencedirect.com/ science/article/pii/S0167404820303606
work page 2021
-
[5]
Detecting repackaged smart- phone applications in third-party Android marketplaces,
W. Zhou, Y . Zhou, X. Jiang, and P. Ning, “Detecting repackaged smart- phone applications in third-party Android marketplaces,” in Proceedings of the second ACM conference on Data and Application Security and Privacy, 2012, pp. 317–326
work page 2012
-
[6]
A survey on various threats and current state of security in Android platform,
P. Bhat and K. Dutta, “A survey on various threats and current state of security in Android platform,”ACM Computing Surveys (CSUR), vol. 52, no. 1, pp. 1–35, 2019
work page 2019
-
[7]
Survey on reverse-engineering tools for Android mobile devices,
A. Albakri, H. Fatima, M. Mohammed, A. Ahmed, A. Ali, A. Ali, and N. M. Elzein, “Survey on reverse-engineering tools for Android mobile devices,” Mathematical Problems in Engineering , vol. 2022, pp. 1–7, 2022
work page 2022
-
[8]
Android Code Protection via Obfuscation Techniques: Past, Present and Future Directions
P. Faruki, H. Fereidooni, V . Laxmi, M. Conti, and M. Gaur, “Android code protection via obfuscation techniques: past, present and future directions,” arXiv preprint arXiv:1611.10231 , 2016
work page Pith review arXiv 2016
Show all 57 references
-
[9]
The rise of obfuscated Android malware and impacts on detection methods,
W. F. Elsersy, A. Feizollah, and N. B. Anuar, “The rise of obfuscated Android malware and impacts on detection methods,” PeerJ Computer Science, vol. 8, p. e907, 2022
2022
-
[10]
A survey of Android application and malware hardening,
V . Sihag, M. Vardhan, and P. Singh, “A survey of Android application and malware hardening,” Computer Science Review, vol. 39, p. 100365, 2021. [Online]. Available: https://www.sciencedirect.com/ science/article/pii/S1574013721000058
2021
-
[11]
Light up that droid! on the effectiveness of static analysis features against app obfuscation for Android malware detection,
B. Molina-Coronado, A. Ruggia, U. Mori, A. Merlo, A. Mendiburu, and J. Miguel-Alonso, “Light up that droid! on the effectiveness of static analysis features against app obfuscation for Android malware detection,” Journal of Network and Computer Applications , vol. 235, p. 104094, 2025
2025
-
[12]
Tabbed out: Subverting the Android custom tab security model,
P. Beer, M. Squarcina, L. Veronese, and M. Lindorfer, “Tabbed out: Subverting the Android custom tab security model,” in 2024 IEEE Symposium on Security and Privacy (SP) . IEEE Computer Society, 2024, pp. 105–105
2024
-
[13]
PTPDroid: Detecting violated user privacy disclosures to third-parties of Android apps,
Z. Tan and W. Song, “PTPDroid: Detecting violated user privacy disclosures to third-parties of Android apps,” in 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE). IEEE, 2023, pp. 473–485
2023
-
[14]
A comprehensive study of learning-based Android malware detectors under challenging environments,
C. Gao, G. Huang, H. Li, B. Wu, Y . Wu, and W. Yuan, “A comprehensive study of learning-based Android malware detectors under challenging environments,” in Proceedings of the 46th IEEE/ACM International Conference on Software Engineering , 2024, pp. 1–13
2024
-
[15]
Not your average app: A large-scale privacy analysis of Android browsers,
A. Pradeep, A. Feal, J. Gamba, A. Rao, M. Lindorfer, N. Vallina- Rodriguez, and D. Choffnes, “Not your average app: A large-scale privacy analysis of Android browsers,”arXiv preprint arXiv:2212.03615, 2022
2022 arXiv
-
[16]
Enhancing malware detection for Android apps: Detecting fine-granularity malicious components,
Z. Liu, L. F. Zhang, and Y . Tang, “Enhancing malware detection for Android apps: Detecting fine-granularity malicious components,” in 2023 38th IEEE/ACM International Conference on Automated Software Engineering (ASE). IEEE, 2023, pp. 1212–1224
2023
-
[17]
Malwhiteout: Reducing label errors in Android malware detection,
L. Wang, H. Wang, X. Luo, and Y . Sui, “Malwhiteout: Reducing label errors in Android malware detection,” in Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineer- ing, 2022, pp. 1–13
2022
-
[18]
Uncovering and exploiting hidden apis in mobile super apps,
C. Wang, Y . Zhang, and Z. Lin, “Uncovering and exploiting hidden apis in mobile super apps,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security , 2023, pp. 2471–2485
2023
-
[19]
MalCertain: Enhancing deep neural network based Android malware detection by tackling prediction uncertainty,
H. Li, G. Xu, L. Wang, X. Xiao, X. Luo, G. Xu, and H. Wang, “MalCertain: Enhancing deep neural network based Android malware detection by tackling prediction uncertainty,” in Proceedings of the IEEE/ACM 46th International Conference on Software Engineering , 2024, pp. 1–13
2024
-
[20]
No privacy among spies: Assessing the functionality and 12 insecurity of consumer Android spyware apps,
E. Liu, S. Rao, S. Havron, G. Ho, S. Savage, G. M. V oelker, and D. McCoy, “No privacy among spies: Assessing the functionality and 12 insecurity of consumer Android spyware apps,” Proceedings on Privacy Enhancing Technologies, 2023
2023
-
[21]
Attention! your copied data is under monitoring: A systematic study of clipboard usage in Android apps,
Y . Chen, R. Tang, C. Zuo, X. Zhang, L. Xue, X. Luo, and Q. Zhao, “Attention! your copied data is under monitoring: A systematic study of clipboard usage in Android apps,” in Proceedings of the 46th IEEE/ACM International Conference on Software Engineering , 2024, pp. 1–13
2024
-
[22]
Understanding Android obfuscation techniques: A large- scale investigation in the wild,
S. Dong, M. Li, W. Diao, X. Liu, J. Liu, Z. Li, F. Xu, K. Chen, X. Wang, and K. Zhang, “Understanding Android obfuscation techniques: A large- scale investigation in the wild,” in Security and Privacy in Commu- nication Networks: 14th International Conference, SecureComm 2018,...
2018
-
[23]
Fast identification of obfuscation and mobile advertising in mobile malware,
M. K ¨uhnel, M. Smieschek, and U. Meyer, “Fast identification of obfuscation and mobile advertising in mobile malware,” in 2015 IEEE Trustcom/BigDataSE/ISPA, vol. 1. IEEE, 2015, pp. 214–221
2015
-
[24]
A framework for iden- tifying obfuscation techniques applied to Android apps using machine learning
M. Park, G. You, S.-j. Cho, M. Park, and S. Han, “A framework for iden- tifying obfuscation techniques applied to Android apps using machine learning.” J. Wirel. Mob. Networks Ubiquitous Comput. Dependable Appl., vol. 10, no. 4, pp. 22–30, 2019
2019
-
[25]
Who changed you? obfuscator identification for Android,
Y . Wang and A. Rountev, “Who changed you? obfuscator identification for Android,” in 2017 IEEE/ACM 4th International Conference on Mobile Software Engineering and Systems (MOBILESoft). IEEE, 2017, pp. 154–164
2017
-
[26]
A large scale investigation of obfuscation use in Google Play,
D. Wermke, N. Huaman, Y . Acar, B. Reaves, P. Traynor, and S. Fahl, “A large scale investigation of obfuscation use in Google Play,” in Pro- ceedings of the 34th annual computer security applications conference , 2018, pp. 222–235
2018
-
[27]
Java obfuscator and Android app optimizer — ProGuard,
“Java obfuscator and Android app optimizer — ProGuard,” www.guardsquare.com. [Online]. Available: https://www.guardsquare. com/proguard
-
[28]
Allatori java obfuscator - professional java obfuscation,
“Allatori java obfuscator - professional java obfuscation,” allatori.com. [Online]. Available: https://allatori.com/
-
[29]
Android application forensics: A survey of obfuscation, obfuscation detection and deobfuscation techniques and their impact on investigations,
X. Zhang, F. Breitinger, E. Luechinger, and S. O’Shaughnessy, “Android application forensics: A survey of obfuscation, obfuscation detection and deobfuscation techniques and their impact on investigations,” Forensic Science International: Digital Investigation , vol. 39, p. 30...
2021
-
[30]
Obfuscation detection in Android applications using deep learning,
M. Conti, P. Vinod, and A. Vitella, “Obfuscation detection in Android applications using deep learning,” Journal of Information Security and Applications, vol. 70, p. 103311, 2022
2022
-
[31]
A survey of obfuscation and deobfuscation techniques in Android code protection,
R. Guo, Q. Liu, M. Zhang, N. Hu, and H. Lu, “A survey of obfuscation and deobfuscation techniques in Android code protection,” in 2022 7th IEEE International Conference on Data Science in Cyberspace (DSC) . IEEE, 2022, pp. 40–47
2022
-
[32]
Detection of obfuscation techniques in Android applications,
A. Bacci, A. Bartoli, F. Martinelli, E. Medvet, and F. Mercaldo, “Detection of obfuscation techniques in Android applications,” in Proceedings of the 13th International Conference on Availability, Reliability and Security , ser. ARES ’18. New York, NY , USA: Association for Co...
2018
-
[33]
Obfusifier: Obfuscation-resistant Android malware detection system,
Z. Li, J. Sun, Q. Yan, W. Srisa-An, and Y . Tsutano, “Obfusifier: Obfuscation-resistant Android malware detection system,” in Security and Privacy in Communication Networks: 15th EAI International Con- ference, SecureComm 2019, Orlando, FL, USA, October 23-25, 2019, Proceeding...
2019
-
[34]
Androdet: An adaptive Android obfuscation detector,
O. Mirzaei, J. M. de Fuentes, J. Tapiador, and L. Gonzalez-Manzano, “Androdet: An adaptive Android obfuscation detector,” Future Genera- tion Computer Systems , vol. 90, pp. 240–261, 2019
2019
-
[35]
Android obfuscation and java security with DashO,
“Android obfuscation and java security with DashO,” www.preemptive.com, 03 2023. [Online]. Available: https: //www.preemptive.com/products/dasho/
2023
-
[36]
Obfuscapk: An open-source black-box obfuscation tool for Android apps,
S. Aonzo, G. C. Georgiu, L. Verderame, and A. Merlo, “Obfuscapk: An open-source black-box obfuscation tool for Android apps,” SoftwareX, vol. 11, p. 100403, 2020. [Online]. Available: https: //www.sciencedirect.com/science/article/pii/S2352711019302791
2020
-
[37]
AndroOBFS: Time- tagged obfuscated Android malware dataset with family information,
S. Kumar, D. Mishra, B. Panda, and S. K. Shukla, “AndroOBFS: Time- tagged obfuscated Android malware dataset with family information,”
-
[38]
Android app security and obfuscation — DexGuard,
“Android app security and obfuscation — DexGuard,” www.guardsquare.com. [Online]. Available: https://www.guardsquare. com/dexguard
-
[39]
Androguard documentation,
A. Desnos and G. Gueguen, “Androguard documentation,” Obtenido de Androguard, 2018
2018
-
[40]
F-droid - free and open source Android app repository,
“F-droid - free and open source Android app repository,” f-droid.org. [Online]. Available: https://f-droid.org/en/
-
[41]
A multi-modal neural embeddings approach for detecting mobile counterfeit apps: A case study on Google Play Store,
N. Karunanayake, J. Rajasegaran, A. Gunathillake, S. Seneviratne, and G. Jourjon, “A multi-modal neural embeddings approach for detecting mobile counterfeit apps: A case study on Google Play Store,” IEEE Transactions on Mobile Computing , vol. 21, no. 1, 2022
2022
-
[42]
A multi-modal neural embeddings approach for detecting mobile counterfeit apps,
J. Rajasegaran, N. Karunanayake, A. Gunathillake, S. Seneviratne, and G. Jourjon, “A multi-modal neural embeddings approach for detecting mobile counterfeit apps,” in The World Wide Web Conference, 2019, pp. 3165–3171
2019
-
[43]
Android studio,
“Android studio,” Android Developers. [Online]. Available: https://developer.android.com/build/releases/past-releases/ agp-3-4-0-release-notes
-
[44]
Early detection of spam mobile apps,
S. Seneviratne, A. Seneviratne, M. A. Kaafar, A. Mahanti, and P. Mo- hapatra, “Early detection of spam mobile apps,” in Proceedings of the 24th International Conference on World Wide Web , 2015, pp. 949–959
2015
-
[45]
Software protection on the go: A large-scale empirical study on mobile app obfuscation,
P. Wang, Q. Bao, L. Wang, S. Wang, Z. Chen, T. Wei, and D. Wu, “Software protection on the go: A large-scale empirical study on mobile app obfuscation,” in Proceedings of the 40th International Conference on Software Engineering , 2018, pp. 26–36
2018
-
[46]
A large-scale empirical study on the effects of code obfuscations on Android apps and anti-malware products,
M. Hammad, J. Garcia, and S. Malek, “A large-scale empirical study on the effects of code obfuscations on Android apps and anti-malware products,” in Proceedings of the 40th international conference on software engineering, 2018, pp. 421–431
2018
-
[47]
Characterizing the use of code obfuscation in malicious and benign Android apps,
U. Karg ´en, N. Mauthe, and N. Shahmehri, “Characterizing the use of code obfuscation in malicious and benign Android apps,” in Proceedings of the 18th International Conference on Availability, Reliability and Security, 2023, pp. 1–12
2023
-
[48]
On the evaluation of Android malware detectors against code-obfuscation techniques,
U. Nawaz, M. Aleem, and J. C.-W. Lin, “On the evaluation of Android malware detectors against code-obfuscation techniques,” PeerJ Com- puter Science, vol. 8, p. e1002, 2022
2022
-
[49]
Impact of code obfuscation on Android malware detection based on static and dynamic analysis
A. Bacci, A. Bartoli, F. Martinelli, E. Medvet, F. Mercaldo, C. A. Visaggio et al. , “Impact of code obfuscation on Android malware detection based on static and dynamic analysis.” in ICISSP, 2018, pp. 379–385
2018
-
[50]
Statistical deob- fuscation of Android applications,
B. Bichsel, V . Raychev, P. Tsankov, and M. Vechev, “Statistical deob- fuscation of Android applications,” in Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security , 2016, pp. 343–355
2016
-
[51]
Anti-proguard: Towards automated deobfuscation of Android apps,
R. Baumann, M. Protsenko, and T. M ¨uller, “Anti-proguard: Towards automated deobfuscation of Android apps,” in Proceedings of the 4th Workshop on Security in Highly Connected IT Systems , 2017, pp. 7–12
2017
-
[52]
Deoptfuscator: Defeating advanced control-flow obfuscation using Android runtime (art),
G. You, G. Kim, S. Han, M. Park, and S.-J. Cho, “Deoptfuscator: Defeating advanced control-flow obfuscation using Android runtime (art),” IEEE Access, vol. 10, pp. 61 426–61 440, 2022
2022
-
[53]
Orlis: Obfuscation- resilient library detection for Android,
Y . Wang, H. Wu, H. Zhang, and A. Rountev, “Orlis: Obfuscation- resilient library detection for Android,” in Proceedings of the 5th International Conference on Mobile Software Engineering and Systems , 2018, pp. 13–23
2018
-
[54]
Automated third-party library detection for Android ap- plications: Are we there yet?
X. Zhan, L. Fan, T. Liu, S. Chen, L. Li, H. Wang, Y . Xu, X. Luo, and Y . Liu, “Automated third-party library detection for Android ap- plications: Are we there yet?” in Proceedings of the 35th IEEE/ACM International Conference on Automated Software Engineering, 2020, pp. 919–930
2020
-
[55]
Libid: reliable identi- fication of obfuscated third-party Android libraries,
J. Zhang, A. R. Beresford, and S. A. Kollmann, “Libid: reliable identi- fication of obfuscated third-party Android libraries,” in Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis, 2019, pp. 55–65
2019
-
[56]
LibScan: Towards more precise Third-Party library identification for Android applications,
Y . Wu, C. Sun, D. Zeng, G. Tan, S. Ma, and P. Wang, “LibScan: Towards more precise Third-Party library identification for Android applications,” in 32nd USENIX Security Symposium (USENIX Security 23) , 2023, pp. 3385–3402. 13 VIII. B IOGRAPHIES Akila Niroshan (Student Member,...
2023
-
[2022]
Available: https://dx.doi.org/10.21227/9ptx-5d17
[Online]. Available: https://dx.doi.org/10.21227/9ptx-5d17
Reviewed August 8, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.