How Does Code Optimization Impact Third-party Library Detection for Android Applications?
Zifan Xie, Ming Wen, Tinghan Li, Yiding Zhu, Qinsheng Hou, Hai Jin
Abstract
Android applications (apps) widely use third-party libraries (TPLs) to reuse functionalities and simplify the development process. Unfortunately, these TPLs often suffer from vulnerabilities that attackers can exploit, leading to catastrophic consequences for app users. To mitigate this threat, researchers have developed tools to detect TPL versions in the app. If an app is found using a TPL vulnerable version, these tools will issue warnings. Although these tools claim to resist the effects of code obfuscation, our preliminary study indicates that code optimization is common during the app release process. A lack of consideration for the impact of code optimizations significantly reduces the effectiveness of existing tools. To fill this gap, this work systematically investigates how and to what extent different optimization strategies affect existing tools. Our findings have led to a new tool named LibHunter, designed to against major code optimization strategies (e.g., Inlining and CallSite Optimization) while also resisting code obfuscation and shrinking. Extensive evaluations on a dataset of apps with optimization, obfuscation, and shrinking enabled show LibHunter significantly outperforms existing tools. It achieves F1 value that surpass the best tools by 29.3% and 36.1% at the library and version levels, respectively. We also applied LibHunter to detect vulnerable TPLs in the top Google Play apps, which shows the scalability of our approach, as well as the potential of our approach to facilitate malware detection.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d61c8786-5a44-4bd3-bacf-e2f683955561Cited by top-tier papers2
- An Empirical Study on the Robustness of Android Third-Party Library Detection Tools Against Advanced ObfuscationDahan Pan, Zhuohao Zhang, Yunjia Min, Runhan Feng et al.ICSE 2026
- Insecure Ingredients? Exploring Dependency Update Patterns of Bundled JavaScript Packages on the WebBen Swierzy, Marc Ohm, Michael MeierICSE 2026
Builds on14
- Reliable Third-Party Library Detection in Android and its Security ApplicationsMichael Backes, Sven Bugiel, Erik DerrCCS 2016 · 345 citations
- Keep me Updated: An Empirical Study of Third-Party Library Updatability on AndroidErik Derr, Sven Bugiel, Sascha Fahl, Yasemin Acar et al.CCS 2017 · 196 citations
- Statistical Deobfuscation of Android ApplicationsBenjamin Bichsel, Veselin Raychev, Petar Tsankov, Martin T. VechevCCS 2016 · 128 citations
- ATVHUNTER: Reliable Version Detection of Third-Party Libraries for Vulnerability Identification in Android ApplicationsXian Zhan, Lingling Fan, Sen Chen, Feng Wu et al.ICSE 2021 · 85 citations
- PDiff: Semantic-based Patch Presence Testing for Downstream KernelsZheyue Jiang, Yuan Zhang, Jun Xu, Qi Wen et al.CCS 2020 · 54 citations
Related papers
- LibScan: Towards More Precise Third-Party Library Identification for Android ApplicationsYafei Wu, Cong Sun, Dongrui Zeng, Gang Tan et al.USENIX Security 2023
- Precise and Efficient Patch Presence Test for Android Applications against Code ObfuscationZifan Xie, Ming Wen, Haoxiang Jia, Xiaochen Guo et al.ISSTA 2023 · 12 citations
- Automated Third-Party Library Detection for Android Applications: Are We There Yet?Xian Zhan, Lingling Fan, Tianming Liu, Sen Chen et al.ASE 2020 · 55 citations
- Beyond Fuzzy Matching: Constraint-Guided Patch Presence Testing for Obfuscated Java BinariesLige Zhan, Jiang Ming, Chenke Luo, Letian Sha et al.ICSE 2026
- Towards Global Matches for Third-Party Library Detection in AndroidLige Zhan, Jiang Ming, Chenke Luo, Guojun Peng et al.ICSE 2026
