{"id":"https://openalex.org/W3161742098","doi":"https://doi.org/10.1109/tmc.2021.3079433","title":"Overlay-Based Android Malware Detection at Market Scales: Systematically Adapting to the New Technological Landscape","display_name":"Overlay-Based Android Malware Detection at Market Scales: Systematically Adapting to the New Technological Landscape","publication_year":2021,"publication_date":"2021-05-12","ids":{"openalex":"https://openalex.org/W3161742098","doi":"https://doi.org/10.1109/tmc.2021.3079433","mag":"3161742098"},"language":"en","primary_location":{"id":"doi:10.1109/tmc.2021.3079433","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tmc.2021.3079433","pdf_url":null,"source":{"id":"https://openalex.org/S69141925","display_name":"IEEE Transactions on Mobile Computing","issn_l":"1536-1233","issn":["1536-1233","1558-0660","2161-9875"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Mobile Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5076665590","display_name":"Liangyi Gong","orcid":"https://orcid.org/0000-0002-9067-8733"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Liangyi Gong","raw_affiliation_strings":["School of Software, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Software, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100357922","display_name":"Zhenhua Li","orcid":"https://orcid.org/0000-0001-7286-122X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhenhua Li","raw_affiliation_strings":["School of Software, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Software, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100701041","display_name":"Hongyi Wang","orcid":"https://orcid.org/0009-0006-0034-0074"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hongyi Wang","raw_affiliation_strings":["School of Software, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Software, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5076484228","display_name":"Hao Lin","orcid":"https://orcid.org/0000-0002-9990-5090"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hao Lin","raw_affiliation_strings":["School of Software, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"School of Software, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5003951925","display_name":"Xiaobo Ma","orcid":"https://orcid.org/0000-0002-0934-5035"},"institutions":[{"id":"https://openalex.org/I87445476","display_name":"Xi'an Jiaotong University","ror":"https://ror.org/017zhmm22","country_code":"CN","type":"education","lineage":["https://openalex.org/I87445476"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaobo Ma","raw_affiliation_strings":["Faculty of Electronic and Information Engineering, Xi&#x0027;an Jiaotong University, Xi&#x0027;an, China"],"affiliations":[{"raw_affiliation_string":"Faculty of Electronic and Information Engineering, Xi&#x0027;an Jiaotong University, Xi&#x0027;an, China","institution_ids":["https://openalex.org/I87445476"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5101877971","display_name":"Yunhao Liu","orcid":"https://orcid.org/0000-0002-6262-3313"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yunhao Liu","raw_affiliation_strings":["Global Innovation Exchange, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Global Innovation Exchange, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5076665590"],"corresponding_institution_ids":["https://openalex.org/I99065089"],"apc_list":null,"apc_paid":null,"fwci":2.0005,"has_fulltext":false,"cited_by_count":19,"citation_normalized_percentile":{"value":0.87067982,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":"21","issue":"12","first_page":"4488","last_page":"4501"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12034","display_name":"Digital and Cyber Forensics","score":0.9839000105857849,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.983299970626831,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/overlay","display_name":"Overlay","score":0.7835522294044495},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.776762843132019},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.5646724700927734},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.5519487261772156},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.5340278148651123},{"id":"https://openalex.org/keywords/phone","display_name":"Phone","score":0.516880989074707},{"id":"https://openalex.org/keywords/usability","display_name":"Usability","score":0.466838002204895},{"id":"https://openalex.org/keywords/overlay-network","display_name":"Overlay network","score":0.4508870542049408},{"id":"https://openalex.org/keywords/emulation","display_name":"Emulation","score":0.43661946058273315},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3001883625984192},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.26668262481689453},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.23013567924499512},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.2258995771408081}],"concepts":[{"id":"https://openalex.org/C136085584","wikidata":"https://www.wikidata.org/wiki/Q910289","display_name":"Overlay","level":2,"score":0.7835522294044495},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.776762843132019},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.5646724700927734},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.5519487261772156},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.5340278148651123},{"id":"https://openalex.org/C2778707766","wikidata":"https://www.wikidata.org/wiki/Q202064","display_name":"Phone","level":2,"score":0.516880989074707},{"id":"https://openalex.org/C170130773","wikidata":"https://www.wikidata.org/wiki/Q216378","display_name":"Usability","level":2,"score":0.466838002204895},{"id":"https://openalex.org/C169851745","wikidata":"https://www.wikidata.org/wiki/Q1331985","display_name":"Overlay network","level":3,"score":0.4508870542049408},{"id":"https://openalex.org/C149810388","wikidata":"https://www.wikidata.org/wiki/Q5374873","display_name":"Emulation","level":2,"score":0.43661946058273315},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3001883625984192},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.26668262481689453},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.23013567924499512},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.2258995771408081},{"id":"https://openalex.org/C50522688","wikidata":"https://www.wikidata.org/wiki/Q189833","display_name":"Economic growth","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tmc.2021.3079433","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tmc.2021.3079433","pdf_url":null,"source":{"id":"https://openalex.org/S69141925","display_name":"IEEE Transactions on Mobile Computing","issn_l":"1536-1233","issn":["1536-1233","1558-0660","2161-9875"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Mobile Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/9","score":0.5299999713897705,"display_name":"Industry, innovation and infrastructure"}],"awards":[{"id":"https://openalex.org/G1448634523","display_name":null,"funder_award_id":"61822205","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2586125334","display_name":null,"funder_award_id":"61972313","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3084395662","display_name":null,"funder_award_id":"61632020","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5461702903","display_name":null,"funder_award_id":"61902211","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7288596857","display_name":null,"funder_award_id":"61632013","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":33,"referenced_works":["https://openalex.org/W59191864","https://openalex.org/W1486263771","https://openalex.org/W1582716752","https://openalex.org/W1594031697","https://openalex.org/W1971739358","https://openalex.org/W2016216904","https://openalex.org/W2055184282","https://openalex.org/W2101800210","https://openalex.org/W2148519244","https://openalex.org/W2151182669","https://openalex.org/W2158874007","https://openalex.org/W2163643194","https://openalex.org/W2407386804","https://openalex.org/W2589988760","https://openalex.org/W2604020447","https://openalex.org/W2616594753","https://openalex.org/W2700054830","https://openalex.org/W2712617220","https://openalex.org/W2734718887","https://openalex.org/W2900275727","https://openalex.org/W2949464457","https://openalex.org/W2951413859","https://openalex.org/W2962909855","https://openalex.org/W2966009283","https://openalex.org/W3009677746","https://openalex.org/W3021426193","https://openalex.org/W3115449059","https://openalex.org/W6602454150","https://openalex.org/W6629083256","https://openalex.org/W6683921424","https://openalex.org/W6684531041","https://openalex.org/W6738424942","https://openalex.org/W6843735874"],"related_works":["https://openalex.org/W89955905","https://openalex.org/W2717179875","https://openalex.org/W4249118297","https://openalex.org/W2126533264","https://openalex.org/W2042060105","https://openalex.org/W1637847238","https://openalex.org/W2122565901","https://openalex.org/W2041341978","https://openalex.org/W4312334973","https://openalex.org/W1963923654"],"abstract_inverted_index":{"Android":[0,147],"<i>overlay</i>":[1],"enables":[2],"one":[3,142],"app":[4,95,148],"to":[5,30,62,86,136],"draw":[6],"over":[7],"other":[8],"apps":[9,28,204],"by":[10,26,74],"creating":[11],"an":[12,195],"extra":[13],"<monospace>View</monospace>":[14,19],"layer":[15],"atop":[16],"the":[17,42,47,55,94,102,133,144],"host":[18],",":[20],"which":[21,68],"nevertheless":[22],"can":[23,70,106],"be":[24,72],"exploited":[25],"malicious":[27,128],"(malware)":[29],"attack":[31],"users.":[32],"To":[33,77],"combat":[34],"this":[35,110,113],"threat,":[36],"prior":[37],"countermeasures":[38],"concentrate":[39],"on":[40],"restricting":[41],"capabilities":[43,103],"of":[44,66,90,104,122,143,198],"overlays":[45,105],"at":[46],"OS":[48],"level":[49],"while":[50],"sacrificing":[51],"overlays\u2019":[52],"usability;":[53],"recently,":[54],"overlay":[56,123],"mechanism":[57],"has":[58],"been":[59],"substantially":[60],"updated":[61],"prevent":[63],"a":[64,81,118],"variety":[65],"attacks,":[67],"however":[69],"still":[71],"evaded":[73],"considerable":[75],"adversaries.":[76],"address":[78],"these":[79],"shortcomings,":[80],"more":[82],"pragmatic":[83],"approach":[84],"is":[85],"enable":[87],"<i>early":[88],"detection</i>":[89],"overlay-based":[91,139],"malware":[92,140],"during":[93],"market":[96],"review":[97],"process,":[98],"so":[99],"that":[100],"all":[101],"stay":[107],"unchanged.":[108],"For":[109],"purpose,":[111],"in":[112,125,157],"paper":[114],"we":[115,152],"first":[116],"conduct":[117],"large-scale":[119],"comparative":[120],"study":[121],"characteristics":[124],"benign":[126],"and":[127,130,164,175,179],"apps,":[129],"then":[131],"implement":[132],"OverlayChecker":[134],"system":[135],"automatically":[137],"detect":[138],"for":[141],"world\u2019s":[145],"largest":[146],"stores.":[149],"In":[150],"particular,":[151],"have":[153],"made":[154],"systematic":[155],"efforts":[156],"feature":[158],"engineering,":[159],"UI":[160],"exploration,":[161],"emulation":[162],"architecture,":[163],"run-time":[165],"environment,":[166],"thus":[167],"maintaining":[168],"high":[169],"detection":[170],"accuracy":[171],"(97":[172],"percent":[173,177],"precision":[174],"97":[176],"recall)":[178],"short":[180],"per-app":[181],"scan":[182],"time":[183],"(":[184],"<inline-formula><tex-math":[185,199],"notation=\"LaTeX\">$\\sim$</tex-math></inline-formula>":[186,200],"1.7":[187],"minutes)":[188],"with":[189],"only":[190],"two":[191],"commodity":[192],"servers,":[193],"under":[194],"intensive":[196],"workload":[197],"10K":[201],"newly":[202],"submitted":[203],"per":[205],"day.":[206]},"counts_by_year":[{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":6},{"year":2023,"cited_by_count":6},{"year":2022,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
