An Empirical Study on the Robustness of Android Third-Party Library Detection Tools Against Advanced Obfuscation
Dahan Pan, Zhuohao Zhang, Yunjia Min, Runhan Feng, Yuanyuan Zhang
Abstract
Third-party libraries (TPLs) play a crucial role in Android app development by providing reusable functionalities, improving development efficiency, and reducing time-to-market. However, detecting and analyzing TPLs is essential, as their vulnerabilities, outdated versions, or malicious modifications can introduce security risks and compromise the integrity of Android apps. Existing TPL detection approaches struggle against code obfuscation, a prevalent practice in Android apps. While prior research has explored obfuscation-resistant detection methods, they largely overlook advanced obfuscation techniques such as package hierarchy obfuscation.
To bridge this gap, we first investigate the prevalence of advanced obfuscation in contemporary Android apps using ObfDetector, a novel static analysis tool capable of detecting identifier renaming, package hierarchy obfuscation, and code optimization. Our large-scale study on 77,504 closed-source Google Play apps and 619 widely used apps reveals extensive obfuscation adoption. We further evaluate the resilience of state-of-the-art TPL detection tools under realistic obfuscation conditions using a newly constructed benchmark dataset, exposing significant performance deficiencies, with F1-scores dropping below 50% for library-level detection and under 10% for version-level identification. Finally, we conduct a systematic failure analysis to uncover key architectural limitations in existing TPL detection frameworks and propose design guidelines for next-generation detection tools. We release our obfuscation detection tool and benchmark dataset to support further research in Android security.
• Software and its engineering → Software libraries and repositories.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 9500af09-b46b-4656-bdb3-d1e4fb0f0e93Builds on7
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu et al.ICSE 2021 · 85 citations
- Automated Third-Party Library Detection for Android Applications: Are We There Yet?Xian Zhan, Lingling Fan, Tianming Liu, Sen Chen et al.ASE 2020 · 55 citations
- Automated Detection of Password Leakage from Public GitHub RepositoriesRunhan Feng, Ziyang Yan, Shiyan Peng, Yuanyuan ZhangICSE 2022 · 36 citations
Related papers
- LibScan: Towards More Precise Third-Party Library Identification for Android ApplicationsYafei Wu, Cong Sun, Dongrui Zeng, Gang Tan et al.USENIX Security 2023
- How Does Code Optimization Impact Third-party Library Detection for Android Applications?Zifan Xie, Ming Wen, Tinghan Li, Yiding Zhu et al.ASE 2024 · 3 citations
- Towards Global Matches for Third-Party Library Detection in AndroidLige Zhan, Jiang Ming, Chenke Luo, Guojun Peng et al.ICSE 2026
- Precise and Efficient Patch Presence Test for Android Applications against Code ObfuscationZifan Xie, Ming Wen, Haoxiang Jia, Xiaochen Guo et al.ISSTA 2023 · 12 citations
- Beyond Fuzzy Matching: Constraint-Guided Patch Presence Testing for Obfuscated Java BinariesLige Zhan, Jiang Ming, Chenke Luo, Letian Sha et al.ICSE 2026
