{"id":"https://openalex.org/W3016369654","doi":"https://doi.org/10.1145/3371924","title":"Assessing and Improving Malware Detection Sustainability through App Evolution Studies","display_name":"Assessing and Improving Malware Detection Sustainability through App Evolution Studies","publication_year":2020,"publication_date":"2020-03-04","ids":{"openalex":"https://openalex.org/W3016369654","doi":"https://doi.org/10.1145/3371924","mag":"3016369654"},"language":"en","primary_location":{"id":"doi:10.1145/3371924","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3371924","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3371924","source":{"id":"https://openalex.org/S142627899","display_name":"ACM Transactions on Software Engineering and Methodology","issn_l":"1049-331X","issn":["1049-331X","1557-7392"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Software Engineering and Methodology","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"bronze","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3371924","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5076081056","display_name":"Haipeng Cai","orcid":"https://orcid.org/0000-0002-5224-9970"},"institutions":[{"id":"https://openalex.org/I72951846","display_name":"Washington State University","ror":"https://ror.org/05dk0ce17","country_code":"US","type":"education","lineage":["https://openalex.org/I72951846"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Haipeng Cai","raw_affiliation_strings":["School of Electrical Engineering and Computer Science, Washington State University, Pullman, WA"],"affiliations":[{"raw_affiliation_string":"School of Electrical Engineering and Computer Science, Washington State University, Pullman, WA","institution_ids":["https://openalex.org/I72951846"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":["https://openalex.org/A5076081056"],"corresponding_institution_ids":["https://openalex.org/I72951846"],"apc_list":null,"apc_paid":null,"fwci":12.324,"has_fulltext":true,"cited_by_count":121,"citation_normalized_percentile":{"value":0.99218139,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":100},"biblio":{"volume":"29","issue":"2","first_page":"1","last_page":"28"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9860000014305115,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9758999943733215,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8950843811035156},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8047482371330261},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.762448251247406},{"id":"https://openalex.org/keywords/retraining","display_name":"Retraining","score":0.7076559066772461},{"id":"https://openalex.org/keywords/android-malware","display_name":"Android malware","score":0.655994176864624},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.5655837059020996},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.53525310754776},{"id":"https://openalex.org/keywords/profiling","display_name":"Profiling (computer programming)","score":0.5236310958862305},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3161502480506897},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.12259924411773682}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8950843811035156},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8047482371330261},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.762448251247406},{"id":"https://openalex.org/C2778712577","wikidata":"https://www.wikidata.org/wiki/Q3505966","display_name":"Retraining","level":2,"score":0.7076559066772461},{"id":"https://openalex.org/C2989133298","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android malware","level":3,"score":0.655994176864624},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5655837059020996},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.53525310754776},{"id":"https://openalex.org/C187191949","wikidata":"https://www.wikidata.org/wiki/Q1138496","display_name":"Profiling (computer programming)","level":2,"score":0.5236310958862305},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3161502480506897},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.12259924411773682},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.0},{"id":"https://openalex.org/C155202549","wikidata":"https://www.wikidata.org/wiki/Q178803","display_name":"International trade","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3371924","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3371924","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3371924","source":{"id":"https://openalex.org/S142627899","display_name":"ACM Transactions on Software Engineering and Methodology","issn_l":"1049-331X","issn":["1049-331X","1557-7392"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Software Engineering and Methodology","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1145/3371924","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3371924","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3371924","source":{"id":"https://openalex.org/S142627899","display_name":"ACM Transactions on Software Engineering and Methodology","issn_l":"1049-331X","issn":["1049-331X","1557-7392"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Software Engineering and Methodology","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1451157337","display_name":null,"funder_award_id":"CCF-1936522","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G848032724","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3016369654.pdf","grobid_xml":"https://content.openalex.org/works/W3016369654.grobid-xml"},"referenced_works_count":58,"referenced_works":["https://openalex.org/W81879861","https://openalex.org/W121173099","https://openalex.org/W1647869403","https://openalex.org/W1902482618","https://openalex.org/W1943233084","https://openalex.org/W1956767865","https://openalex.org/W1964241047","https://openalex.org/W1990649188","https://openalex.org/W2007857904","https://openalex.org/W2026875669","https://openalex.org/W2041276426","https://openalex.org/W2060537671","https://openalex.org/W2070386561","https://openalex.org/W2078197322","https://openalex.org/W2101234009","https://openalex.org/W2122049982","https://openalex.org/W2122672392","https://openalex.org/W2125011234","https://openalex.org/W2127723417","https://openalex.org/W2152660559","https://openalex.org/W2167003418","https://openalex.org/W2168103835","https://openalex.org/W2168649891","https://openalex.org/W2204544304","https://openalex.org/W2227887088","https://openalex.org/W2289508129","https://openalex.org/W2296579688","https://openalex.org/W2308726246","https://openalex.org/W2324464293","https://openalex.org/W2407059953","https://openalex.org/W2407313496","https://openalex.org/W2473681893","https://openalex.org/W2487124337","https://openalex.org/W2506694253","https://openalex.org/W2575599800","https://openalex.org/W2603160474","https://openalex.org/W2618126787","https://openalex.org/W2619271281","https://openalex.org/W2621187857","https://openalex.org/W2767783754","https://openalex.org/W2767843091","https://openalex.org/W2767857768","https://openalex.org/W2768050722","https://openalex.org/W2783327762","https://openalex.org/W2789731619","https://openalex.org/W2794652108","https://openalex.org/W2808915780","https://openalex.org/W2811263310","https://openalex.org/W2883742592","https://openalex.org/W2884262171","https://openalex.org/W2900275727","https://openalex.org/W2906347220","https://openalex.org/W2909609357","https://openalex.org/W2950387995","https://openalex.org/W2953506610","https://openalex.org/W2964136807","https://openalex.org/W4239799938","https://openalex.org/W4244726870"],"related_works":["https://openalex.org/W2560361988","https://openalex.org/W2507113366","https://openalex.org/W2591124010","https://openalex.org/W3200508744","https://openalex.org/W3025122950","https://openalex.org/W2311926078","https://openalex.org/W2895504842","https://openalex.org/W4281384336","https://openalex.org/W2717179875","https://openalex.org/W4249118297"],"abstract_inverted_index":{"Machine":[0],"learning\u2013based":[1],"classification":[2,135],"dominates":[3],"current":[4],"malware":[5,35,57,67,124,230,241],"detection":[6,204],"approaches":[7],"for":[8,110,126,143,202,207,238],"Android.":[9,127],"However,":[10],"due":[11],"to":[12,79,88,91],"the":[13,17,63,69,107,156,161,170,193,217,224],"evolution":[14],"of":[15,66,158,219,226],"both":[16],"Android":[18,144],"platform":[19],"and":[20,43,55,105,118,179,205,243],"its":[21,93],"user":[22],"apps,":[23],"existing":[24],"such":[25],"techniques":[26],"are":[27],"widely":[28],"limited":[29],"by":[30,200],"their":[31],"reliance":[32],"on":[33,82,138,166,252],"new":[34,54,140],"samples,":[36],"which":[37,46,174,214],"may":[38],"not":[39,77],"be":[40,80,89,248],"timely":[41],"available,":[42],"constant":[44],"retraining,":[45],"is":[47,222,236],"often":[48],"very":[49],"costly.":[50],"As":[51],"a":[52,72,133,139],"result,":[53],"emerging":[56],"slips":[58],"through,":[59],"as":[60,164],"seen":[61],"from":[62,151,231,250],"continued":[64],"surging":[65],"in":[68,195],"wild.":[70],"Thus,":[71],"more":[73,86],"practical":[74],"detector":[75],"needs":[76],"only":[78],"accurate":[81],"particular":[83],"datasets":[84,168],"but,":[85],"critically,":[87],"able":[90],"sustain":[92],"capabilities":[94],"over":[95,234],"time":[96,235],"without":[97],"frequent":[98],"retraining.":[99],"In":[100],"this":[101],"article,":[102],"we":[103,186],"propose":[104],"study":[106],"sustainability":[108,116,157],"problem":[109],"learning-based":[111,240],"app":[112,253],"classifiers.":[113],"We":[114,128,154],"define":[115],"metrics":[117],"compare":[119],"them":[120],"among":[121],"five":[122,162],"state-of-the-art":[123],"detectors":[125,163],"further":[129],"developed":[130],"DroidSpan":[131,159,189,220],",":[132,213,221],"novel":[134],"system":[136],"based":[137],"behavioral":[141],"profile":[142],"apps":[145,178,233],"that":[146,188,223,244],"captures":[147],"sensitive":[148],"access":[149],"distribution":[150],"lightweight":[152],"profiling.":[153],"evaluated":[155],"versus":[160],"baselines":[165,194],"longitudinal":[167],"across":[169],"past":[171],"eight":[172],"years,":[173],"include":[175],"13,627":[176],"benign":[177,232],"12,755":[180],"malware.":[181],"Through":[182],"our":[183],"extensive":[184],"experiments,":[185],"showed":[187],"significantly":[190],"outperformed":[191],"all":[192],"substainability":[196],"at":[197],"reasonable":[198],"costs,":[199],"6%\u201332%":[201],"same-period":[203],"21%\u201337%":[206],"over-time":[208],"detection.":[209],"The":[210],"main":[211],"takeaway":[212],"also":[215],"explains":[216],"superiority":[218],"use":[225],"features":[227,246],"consistently":[228],"differentiating":[229],"essential":[237],"sustainable":[239],"detection,":[242],"these":[245],"can":[247],"learned":[249],"studies":[251],"evolution.":[254]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":18},{"year":2023,"cited_by_count":22},{"year":2022,"cited_by_count":34},{"year":2021,"cited_by_count":20},{"year":2020,"cited_by_count":5}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2020-04-24T00:00:00"}
