{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2020:I2GMVIS73NWFWN6BZJX5V6WCM6","short_pith_number":"pith:I2GMVIS7","canonical_record":{"source":{"id":"2001.08399","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2020-01-23T07:51:59Z","cross_cats_sorted":[],"title_canon_sha256":"a9947b5adf09de3f05f093ff9ed8b7610452ebf26d57877695483ff3baae6877","abstract_canon_sha256":"45b8cbbda42eb42b2ed79149ebc76fe2c9d3f6b889d3ab7ba268be7924af8659"},"schema_version":"1.0"},"canonical_sha256":"468ccaa25fdb6c5b37c1ca6fdafac2679720307c8adceaf194f75fe33ac01ea1","source":{"kind":"arxiv","id":"2001.08399","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2001.08399","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"arxiv_version","alias_value":"2001.08399v1","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2001.08399","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"pith_short_12","alias_value":"I2GMVIS73NWF","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"pith_short_16","alias_value":"I2GMVIS73NWFWN6B","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"pith_short_8","alias_value":"I2GMVIS7","created_at":"2026-07-05T00:35:12Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2020:I2GMVIS73NWFWN6BZJX5V6WCM6","target":"record","payload":{"canonical_record":{"source":{"id":"2001.08399","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2020-01-23T07:51:59Z","cross_cats_sorted":[],"title_canon_sha256":"a9947b5adf09de3f05f093ff9ed8b7610452ebf26d57877695483ff3baae6877","abstract_canon_sha256":"45b8cbbda42eb42b2ed79149ebc76fe2c9d3f6b889d3ab7ba268be7924af8659"},"schema_version":"1.0"},"canonical_sha256":"468ccaa25fdb6c5b37c1ca6fdafac2679720307c8adceaf194f75fe33ac01ea1","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:35:12.807628Z","signature_b64":"k/oLqxqbDLi+ss1lEUvKCHlfneofdMp8BWgNUjj+E2TSe07/kJsOpG+wWEcaYat0yLc+Qe92qP77Aqf7jXibDQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"468ccaa25fdb6c5b37c1ca6fdafac2679720307c8adceaf194f75fe33ac01ea1","last_reissued_at":"2026-07-05T00:35:12.807250Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:35:12.807250Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"2001.08399","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T00:35:12Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"As7DmtaZO5lQwWzPKqWI1CPMx7dzW5QmErKYx0rYVnDhEC9qufg3HdCe6LLbDd4YX/qFPxGGUJiOUP8CejfyDg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-06T02:16:56.512129Z"},"content_sha256":"4996dc62f3efcf6c8c9aa8ad43e67931ddd80d970534aaea0eb7bb40b8a0997a","schema_version":"1.0","event_id":"sha256:4996dc62f3efcf6c8c9aa8ad43e67931ddd80d970534aaea0eb7bb40b8a0997a"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2020:I2GMVIS73NWFWN6BZJX5V6WCM6","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"An Android Application Risk Evaluation Framework Based on Minimum Permission Set Identification","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.SE","authors_text":"Jianmao Xiao, Qiang He, Shizhan Chen, Xiao Xue, Zhiyong Feng","submitted_at":"2020-01-23T07:51:59Z","abstract_excerpt":"Android utilizes a security mechanism that requires apps to request permission for accessing sensitive user data, e.g., contacts and SMSs, or certain system features, e.g., camera and Internet access. However, Android apps tend to be overprivileged, i.e., they often request more permissions than necessary. This raises the security problem of overprivilege. To alleviate the overprivilege problem, this paper proposes MPDroid, an approach that combines static analysis and collaborative filtering to identify the minimum permissions for an Android app based on its app description and API usage. Giv"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2001.08399","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2001.08399/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-05T00:35:12Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"2J9ExCt1GpGQo8alek4FGUg66ijeLtkfsASBxJdk0jhfA8BrdmcmA0pmrfexQUmsJe3Vq3xBfrOq542MC76TCw==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-06T02:16:56.512710Z"},"content_sha256":"e79878bae1995a18a90803a75edb1fa7c1878827fc9e5e510820c01a02050aea","schema_version":"1.0","event_id":"sha256:e79878bae1995a18a90803a75edb1fa7c1878827fc9e5e510820c01a02050aea"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/I2GMVIS73NWFWN6BZJX5V6WCM6/bundle.json","state_url":"https://pith.science/pith/I2GMVIS73NWFWN6BZJX5V6WCM6/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/I2GMVIS73NWFWN6BZJX5V6WCM6/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-06T02:16:56Z","links":{"resolver":"https://pith.science/pith/I2GMVIS73NWFWN6BZJX5V6WCM6","bundle":"https://pith.science/pith/I2GMVIS73NWFWN6BZJX5V6WCM6/bundle.json","state":"https://pith.science/pith/I2GMVIS73NWFWN6BZJX5V6WCM6/state.json","well_known_bundle":"https://pith.science/.well-known/pith/I2GMVIS73NWFWN6BZJX5V6WCM6/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2020:I2GMVIS73NWFWN6BZJX5V6WCM6","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"45b8cbbda42eb42b2ed79149ebc76fe2c9d3f6b889d3ab7ba268be7924af8659","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2020-01-23T07:51:59Z","title_canon_sha256":"a9947b5adf09de3f05f093ff9ed8b7610452ebf26d57877695483ff3baae6877"},"schema_version":"1.0","source":{"id":"2001.08399","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"2001.08399","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"arxiv_version","alias_value":"2001.08399v1","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2001.08399","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"pith_short_12","alias_value":"I2GMVIS73NWF","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"pith_short_16","alias_value":"I2GMVIS73NWFWN6B","created_at":"2026-07-05T00:35:12Z"},{"alias_kind":"pith_short_8","alias_value":"I2GMVIS7","created_at":"2026-07-05T00:35:12Z"}],"graph_snapshots":[{"event_id":"sha256:e79878bae1995a18a90803a75edb1fa7c1878827fc9e5e510820c01a02050aea","target":"graph","created_at":"2026-07-05T00:35:12Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/2001.08399/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"Android utilizes a security mechanism that requires apps to request permission for accessing sensitive user data, e.g., contacts and SMSs, or certain system features, e.g., camera and Internet access. However, Android apps tend to be overprivileged, i.e., they often request more permissions than necessary. This raises the security problem of overprivilege. To alleviate the overprivilege problem, this paper proposes MPDroid, an approach that combines static analysis and collaborative filtering to identify the minimum permissions for an Android app based on its app description and API usage. Giv","authors_text":"Jianmao Xiao, Qiang He, Shizhan Chen, Xiao Xue, Zhiyong Feng","cross_cats":[],"headline":"","license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2020-01-23T07:51:59Z","title":"An Android Application Risk Evaluation Framework Based on Minimum Permission Set Identification"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2001.08399","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:4996dc62f3efcf6c8c9aa8ad43e67931ddd80d970534aaea0eb7bb40b8a0997a","target":"record","created_at":"2026-07-05T00:35:12Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"45b8cbbda42eb42b2ed79149ebc76fe2c9d3f6b889d3ab7ba268be7924af8659","cross_cats_sorted":[],"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2020-01-23T07:51:59Z","title_canon_sha256":"a9947b5adf09de3f05f093ff9ed8b7610452ebf26d57877695483ff3baae6877"},"schema_version":"1.0","source":{"id":"2001.08399","kind":"arxiv","version":1}},"canonical_sha256":"468ccaa25fdb6c5b37c1ca6fdafac2679720307c8adceaf194f75fe33ac01ea1","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"468ccaa25fdb6c5b37c1ca6fdafac2679720307c8adceaf194f75fe33ac01ea1","first_computed_at":"2026-07-05T00:35:12.807250Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-05T00:35:12.807250Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"k/oLqxqbDLi+ss1lEUvKCHlfneofdMp8BWgNUjj+E2TSe07/kJsOpG+wWEcaYat0yLc+Qe92qP77Aqf7jXibDQ==","signature_status":"signed_v1","signed_at":"2026-07-05T00:35:12.807628Z","signed_message":"canonical_sha256_bytes"},"source_id":"2001.08399","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:4996dc62f3efcf6c8c9aa8ad43e67931ddd80d970534aaea0eb7bb40b8a0997a","sha256:e79878bae1995a18a90803a75edb1fa7c1878827fc9e5e510820c01a02050aea"],"state_sha256":"6dcd132a62935c54b59371a74cf9048ea29d1b9756978772b7c56772c1d3f0de"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"Khjc09Zlo5fxohHe9iwtOHY6HzOehAxzYU3mvKezWqY8qS+J7VXWbmHycU5s2hywDSnrHtURWIhHUxROX2ofAQ==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-06T02:16:56.519457Z","bundle_sha256":"6a163fb031f7210914284afab5a9f320c92c369733e8b77d468b8f2f215959e4"}}