{"id":"https://openalex.org/W2792027525","doi":"https://doi.org/10.23919/eusipco.2018.8553598","title":"Explaining Black-box Android Malware Detection","display_name":"Explaining Black-box Android Malware Detection","publication_year":2018,"publication_date":"2018-09-01","ids":{"openalex":"https://openalex.org/W2792027525","doi":"https://doi.org/10.23919/eusipco.2018.8553598","mag":"2792027525"},"language":"en","primary_location":{"id":"doi:10.23919/eusipco.2018.8553598","is_oa":false,"landing_page_url":"https://doi.org/10.23919/eusipco.2018.8553598","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 26th European Signal Processing Conference (EUSIPCO)","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["arxiv","crossref","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/1803.03544","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5023265601","display_name":"Marco Melis","orcid":"https://orcid.org/0000-0003-3641-2093"},"institutions":[{"id":"https://openalex.org/I172446870","display_name":"University of Cagliari","ror":"https://ror.org/003109y17","country_code":"IT","type":"education","lineage":["https://openalex.org/I172446870"]}],"countries":["IT"],"is_corresponding":true,"raw_author_name":"Marco Melis","raw_affiliation_strings":["DIEE, University of Cagliari, Piazza d'Armi, Cagliari","DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari"],"affiliations":[{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, Cagliari","institution_ids":["https://openalex.org/I172446870"]},{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari","institution_ids":["https://openalex.org/I172446870"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5051452548","display_name":"Davide Maiorca","orcid":"https://orcid.org/0000-0003-2640-4663"},"institutions":[{"id":"https://openalex.org/I172446870","display_name":"University of Cagliari","ror":"https://ror.org/003109y17","country_code":"IT","type":"education","lineage":["https://openalex.org/I172446870"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Davide Maiorca","raw_affiliation_strings":["DIEE, University of Cagliari, Piazza d'Armi, Cagliari","DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari"],"affiliations":[{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, Cagliari","institution_ids":["https://openalex.org/I172446870"]},{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari","institution_ids":["https://openalex.org/I172446870"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008367647","display_name":"Battista Biggio","orcid":"https://orcid.org/0000-0001-7752-509X"},"institutions":[{"id":"https://openalex.org/I172446870","display_name":"University of Cagliari","ror":"https://ror.org/003109y17","country_code":"IT","type":"education","lineage":["https://openalex.org/I172446870"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Battista Biggio","raw_affiliation_strings":["DIEE, University of Cagliari, Piazza d'Armi, Cagliari","DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari"],"affiliations":[{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, Cagliari","institution_ids":["https://openalex.org/I172446870"]},{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari","institution_ids":["https://openalex.org/I172446870"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075367917","display_name":"Giorgio Giacinto","orcid":"https://orcid.org/0000-0002-5759-3017"},"institutions":[{"id":"https://openalex.org/I172446870","display_name":"University of Cagliari","ror":"https://ror.org/003109y17","country_code":"IT","type":"education","lineage":["https://openalex.org/I172446870"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Giorgio Giacinto","raw_affiliation_strings":["DIEE, University of Cagliari, Piazza d'Armi, Cagliari","DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari"],"affiliations":[{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, Cagliari","institution_ids":["https://openalex.org/I172446870"]},{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari","institution_ids":["https://openalex.org/I172446870"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5065359946","display_name":"Fabio Roli","orcid":"https://orcid.org/0000-0003-4103-9190"},"institutions":[{"id":"https://openalex.org/I172446870","display_name":"University of Cagliari","ror":"https://ror.org/003109y17","country_code":"IT","type":"education","lineage":["https://openalex.org/I172446870"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Fabio Roli","raw_affiliation_strings":["DIEE, University of Cagliari, Piazza d'Armi, Cagliari","DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari"],"affiliations":[{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, Cagliari","institution_ids":["https://openalex.org/I172446870"]},{"raw_affiliation_string":"DIEE, University of Cagliari, Piazza d'Armi, 09123, Cagliari","institution_ids":["https://openalex.org/I172446870"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5023265601"],"corresponding_institution_ids":["https://openalex.org/I172446870"],"apc_list":null,"apc_paid":null,"fwci":0.54182844,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.6139874,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"524","last_page":"528"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9975000023841858,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9908000230789185,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.8553290367126465},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8007864952087402},{"id":"https://openalex.org/keywords/interpretability","display_name":"Interpretability","score":0.777371883392334},{"id":"https://openalex.org/keywords/android","display_name":"Android (operating system)","score":0.750967264175415},{"id":"https://openalex.org/keywords/android-malware","display_name":"Android malware","score":0.7324383854866028},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.7016271948814392},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.6156995296478271},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5894834995269775},{"id":"https://openalex.org/keywords/mobile-malware","display_name":"Mobile malware","score":0.5174685120582581},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.49279168248176575},{"id":"https://openalex.org/keywords/empirical-research","display_name":"Empirical research","score":0.43281427025794983},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.41325676441192627},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3204039931297302},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.2776135504245758},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.12290015816688538}],"concepts":[{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.8553290367126465},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8007864952087402},{"id":"https://openalex.org/C2781067378","wikidata":"https://www.wikidata.org/wiki/Q17027399","display_name":"Interpretability","level":2,"score":0.777371883392334},{"id":"https://openalex.org/C557433098","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android (operating system)","level":2,"score":0.750967264175415},{"id":"https://openalex.org/C2989133298","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android malware","level":3,"score":0.7324383854866028},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.7016271948814392},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.6156995296478271},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5894834995269775},{"id":"https://openalex.org/C2780967490","wikidata":"https://www.wikidata.org/wiki/Q1291200","display_name":"Mobile malware","level":3,"score":0.5174685120582581},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.49279168248176575},{"id":"https://openalex.org/C120936955","wikidata":"https://www.wikidata.org/wiki/Q2155640","display_name":"Empirical research","level":2,"score":0.43281427025794983},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.41325676441192627},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3204039931297302},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.2776135504245758},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.12290015816688538},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0}],"mesh":[],"locations_count":6,"locations":[{"id":"doi:10.23919/eusipco.2018.8553598","is_oa":false,"landing_page_url":"https://doi.org/10.23919/eusipco.2018.8553598","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2018 26th European Signal Processing Conference (EUSIPCO)","raw_type":"proceedings-article"},{"id":"pmh:oai:arXiv.org:1803.03544","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1803.03544","pdf_url":"https://arxiv.org/pdf/1803.03544","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},{"id":"mag:2792027525","is_oa":true,"landing_page_url":"https://arxiv.org/abs/1803.03544","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"arXiv (Cornell University)","raw_type":null},{"id":"pmh:oai:iris.unica.it:11584/248107","is_oa":true,"landing_page_url":"https://ieeexplore.ieee.org/document/8553598","pdf_url":null,"source":{"id":"https://openalex.org/S4377196293","display_name":"UNICA IRIS Institutional Research Information System (University of Cagliari)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I172446870","host_organization_name":"University of Cagliari","host_organization_lineage":["https://openalex.org/I172446870"],"host_organization_lineage_names":[],"type":"repository"},"license":"other-oa","license_id":"https://openalex.org/licenses/other-oa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferencePaper"},{"id":"pmh:oai:iris.unige.it:11567/1083745","is_oa":false,"landing_page_url":"https://hdl.handle.net/11567/1083745","pdf_url":null,"source":{"id":"https://openalex.org/S4377196291","display_name":"CINECA IRIS Institutial Research Information System (University of Genoa)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I83816512","host_organization_name":"University of Genoa","host_organization_lineage":["https://openalex.org/I83816512"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"info:eu-repo/semantics/conferenceObject"},{"id":"doi:10.48550/arxiv.1803.03544","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.1803.03544","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:1803.03544","is_oa":true,"landing_page_url":"http://arxiv.org/abs/1803.03544","pdf_url":"https://arxiv.org/pdf/1803.03544","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"text"},"sustainable_development_goals":[{"score":0.5799999833106995,"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10"},{"score":0.41999998688697815,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W9657784","https://openalex.org/W1985987493","https://openalex.org/W2122672392","https://openalex.org/W2282821441","https://openalex.org/W2407059953","https://openalex.org/W2439568532","https://openalex.org/W2493343568","https://openalex.org/W2536353943","https://openalex.org/W2733922298","https://openalex.org/W2772683029","https://openalex.org/W2773446523","https://openalex.org/W2963207607","https://openalex.org/W2963777745","https://openalex.org/W2964153729","https://openalex.org/W4247200422","https://openalex.org/W6600428322","https://openalex.org/W6637162671","https://openalex.org/W6640425456","https://openalex.org/W6681608319","https://openalex.org/W6718991148","https://openalex.org/W6735632633","https://openalex.org/W6737181878","https://openalex.org/W6741159423","https://openalex.org/W7024935943"],"related_works":["https://openalex.org/W2964088652","https://openalex.org/W3164409774","https://openalex.org/W31472457","https://openalex.org/W258019806","https://openalex.org/W2949187909","https://openalex.org/W3194109284","https://openalex.org/W2753303661","https://openalex.org/W3159337037","https://openalex.org/W3140052287","https://openalex.org/W2186069231","https://openalex.org/W2311926078","https://openalex.org/W3161854416","https://openalex.org/W2946009685","https://openalex.org/W3181226914","https://openalex.org/W3084749795","https://openalex.org/W3130682519","https://openalex.org/W3081416576","https://openalex.org/W2784727992","https://openalex.org/W3038275207","https://openalex.org/W2774347535"],"abstract_inverted_index":{"Machine-learning":[0],"models":[1,103,144,196],"have":[2,37],"been":[3],"recently":[4],"used":[5],"for":[6],"detecting":[7],"malicious":[8],"Android":[9,57,96,182],"applications,":[10],"reporting":[11],"impressive":[12],"performances":[13],"on":[14,21,75,179],"benchmark":[15,46,76],"datasets,":[16,47],"even":[17],"when":[18,83],"trained":[19],"only":[20],"features":[22,110],"statically":[23],"extracted":[24],"from":[25],"the":[26,39,54,93,107,135,158,163],"application,":[27],"such":[28,42],"as":[29,173],"system":[30],"calls":[31],"and":[32,169,194],"permissions.":[33],"However,":[34],"recent":[35],"findings":[36],"highlighted":[38],"fragility":[40],"of":[41,56,152,192],"in-vitro":[43],"evaluations":[44],"with":[45],"showing":[48],"that":[49,69],"very":[50],"few":[51],"changes":[52],"to":[53,61,80,104,112,122,133,145,165],"content":[55],"malware":[58,71,97,170,183],"may":[59],"suffice":[60],"evade":[62],"detection.":[63],"How":[64],"can":[65],"we":[66,118],"thus":[67],"trust":[68],"a":[70,130,180],"detector":[72],"performing":[73],"well":[74],"data":[77],"will":[78],"continue":[79],"do":[81],"so":[82],"deployed":[84],"in":[85],"an":[86],"operating":[87],"environment?":[88],"To":[89],"mitigate":[90],"this":[91,116,120],"issue,":[92],"most":[94,108,136],"popular":[95,181],"detectors":[98],"use":[99],"linear,":[100],"explainable":[101],"machine-learning":[102],"easily":[105],"identify":[106,134],"influential":[109,137],"contributing":[111],"each":[113],"decision.":[114],"In":[115],"work,":[117],"generalize":[119],"approach":[121,132,155],"any":[123],"black-box":[124],"machine-":[125],"learning":[126],"model,":[127],"by":[128,162,175],"leveraging":[129],"gradient-based":[131],"local":[138],"features.":[139],"This":[140],"enables":[141],"using":[142],"nonlinear":[143,195],"potentially":[146],"increase":[147],"accuracy":[148],"without":[149],"sacrificing":[150],"interpretability":[151],"decisions.":[153],"Our":[154],"also":[156,187],"highlights":[157],"global":[159],"characteristics":[160],"learned":[161],"model":[164],"discriminate":[166],"between":[167],"benign":[168],"applications.":[171],"Finally,":[172],"shown":[174],"our":[176],"empirical":[177],"analysis":[178],"detection":[184],"task,":[185],"it":[186],"helps":[188],"identifying":[189],"potential":[190],"vulnerabilities":[191],"linear":[193],"against":[197],"adversarial":[198],"manipulations.":[199]},"counts_by_year":[{"year":2022,"cited_by_count":1},{"year":2020,"cited_by_count":2},{"year":2019,"cited_by_count":1}],"updated_date":"2026-02-09T09:26:11.010843","created_date":"2025-10-10T00:00:00"}
