Machine Learning Analysis of Potential Mobile Apps Threats on the Basis of Permissions
DOI:
https://doi.org/10.47839/ijc.25.2.4657Keywords:
mobile application, permission, threat, machine learning, cybersecurityAbstract
Nowadays, the use of mobile applications is extremely common. The number of new applications is constantly increasing, and accordingly, because of this, it is becoming increasingly difficult to determine the level of danger of a particular application. The issue of privacy and data security is especially acute, particularly because of the permissions that apps request. Such permissions can give applications access to sensitive user information and system resources, which, if misused, can lead to security risks. This research focuses on mobile application threat analysis using machine learning (ML) with a focus on the Android Permission dataset. By examining how different apps use and potentially abuse permissions, this research aims to identify high-risk apps that pose a serious threat to user privacy and cybersecurity. The importance of permissions as a vector for understanding mobile app security is undeniable, and a permission-based ML analysis approach can improve current app verification processes. This methodology can be further extended to include dynamic analysis where application behavior is monitored in real-time, providing an even more robust assessment of security risks in mobile environments.
References
I. Pekaric, C. Sauerwein, S. Laichner, and R. Breu, “How do mobile applications enhance security? An exploratory analysis of use cases and provided information,” Proceedings of the 2025 ACM Southeast Conference (ACMSE 2025). Association for Computing Machinery, New York, NY, USA, 2025, pp. 114–123. https://doi.org/10.1145/3696673.3723067.
H. I. Maseeh, C. Jebarajakirthy, A. Sivapalan, M. Ross, and M. Rehman, “Understanding smartphone users’ app usage with restricted permissions,” Information Technology & People, vol. 38, no. 2, pp. 1045–1088, 2025. https://doi.org/10.1108/ITP-03-2022-0200.
A. R. Nasab, M. Dashti, M. Shahin, M. Zahedi, H. Khalajzadeh, C. Arora, and P. Liang, “Fairness concerns in app reviews: A study on AI-based mobile apps,” ACM Trans. Softw. Eng. Methodol, vol. 34, issue 2, article 51, pp. 1-30, 2025. https://doi.org/10.1145/3690633.
M. Tahaei, R. Abu-Salma, and R. Awais, “Stuck in the permissions with you: Developer & end-user perspectives on app permissions & their privacy ramifications,” Proceedings of the ACM 2023 CHI Conference on Human Factors in Computing Systems (CHI'23), article 168, 2023, pp. 1–24. https://doi.org/10.1145/3544548.3581060.
C. I. Eke, A. A. Norman, & M. Mulenga, “Machine learning approach for detecting and combating bring your own device (BYOD) security threats and attacks: a systematic mapping review,” Artificial Intelligence Review, vol. 56, issue 8, pp. 8815-8858, 2023. https://doi.org/10.1007/s10462-022-10382-3.
A. Guerra-Manzanares, H. Bahsi, & M. Luckner, “Leveraging the first line of defense: A study on the evolution and usage of android security permissions for enhanced android malware detection,” Journal of Computer Virology and Hacking Techniques, vol. 19, issue 1, pp. 65-96, 2023. https://doi.org/10.1007/s11416-022-00432-3.
F. Wang, N. Yang, P. M. Shakeel, & V. Saravanan, “Machine learning for mobile network payment security evaluation system,” Transactions on Emerging Telecommunications Technologies, vol. 35, issue 4, e4226, 2024. https://doi.org/10.1002/ett.4226.
V. J. Raymond, R. J. R. Raj, & J. Retna, “Investigation of Android malware with machine learning classifiers using enhanced PCA algorithm,” Comput. Syst. Sci. Eng., vol. 44, issue 3, pp. 2147-2163, 2025. https://doi.org/10.32604/csse.2023.028227.
A. Gómez, & A. Muñoz, “Deep learning-based attack detection and classification in Android devices,” Electronics, vol. 12, issue 15, 3253, 2023. https://doi.org/10.3390/electronics12153253.
I. Naseer, “Machine learning applications in cyber threat intelligence: A comprehensive review,” The Asian Bulletin of Big Data Management, vol. 3, issue 2, pp. 190-200, 2023. https://doi.org/10.62019/abbdm.v3i2.85.
I. H. Sarker, “Machine learning for intelligent data analysis and automation in cybersecurity: current and future prospects,” Annals of Data Science, vol. 10, issue 6, pp. 1473-1498, 2023. https://doi.org/10.1007/s40745-022-00444-2.
N. B. Alom, “A comprehensive analysis of customer behavior analytics, privacy concerns, and data protection regulations in the era of big data and machine learning,” International Journal of Applied Machine Learning and Computational Intelligence, vol. 14, issue 5, pp. 21-40, 2024.
P. Bhat, S. Behal, & K. Dutta, “A system call-based android malware detection approach with homogeneous & heterogeneous ensemble machine learning,” Computers & Security, vol. 130, 103277, 2023. https://doi.org/10.1016/j.cose.2023.103277.
H. N. Fakhouri, S. Alawadi, F. M. Awaysheh, I. B. Hani, M. Alkhalaileh, & F. Hamad, “A comprehensive study on the role of machine learning in 5G security: challenges, technologies, and solutions,” Electronics, vol. 12, issue 22, 4604, 2023. https://doi.org/10.3390/electronics12224604.
T. Hovorushchenko, A. Herts, A. Boyarchuk, & O. Pavlova, “System for determination of legal responsibility/penalty for a cybersecurity breach,” Proceedings of the ITTAP’2022, 2022, pp. 233-240.
T. Hovorushchenko, O. Pavlova, & M. Kostiuk, “Method of increasing the security of smart parking system,” Journal of Cyber Security and Mobility, vol. 12, issue 3, pp. 297–314, 2023. https://doi.org/10.13052/jcsm2245-1439.123.3.
E. Zaitseva, T. Hovorushchenko, O. Pavlova, Y. Voichur, “Identifying the mutual correlations and evaluating the weights of factors and consequences of mobile application insecurity,” Systems, vol. 11, 242, 2023. https://doi.org/10.3390/systems11050242.
R. Mayya, and S. Viswanathan, “Delaying informed consent: An empirical investigation of mobile apps’ upgrade decisions,” Management Science, vol. 71, issue 8, pp. 7113-7135, 2024. https://doi.org/10.1287/mnsc.2022.00334.
R. Mohammadi, M. M. Hosseini, R. Bahrami, “Uncovering security vulnerabilities through multiplatform malware analysis,” Security and Privacy, vol. 8, issue 1, e455, 2025. https://doi.org/10.1002/spy2.455.
L. Wei, H. Huang, S.C. Cheung, K. Li, “How far are app secrets from being stolen? A case study on Android,” Empir Software Eng, vol. 30, article 90, 2025. https://doi.org/10.1007/s10664-024-10607-9.
J. Apoorva, “AI-driven malware behaviour classification and detection systems,” International Journal of Advanced Research in Computer Science and Engineering (IJARCSE), vol. 1, issue 3, pp. 16–24, 2025. https://ijarcse.org/index.php/ijarcse/article/view/69.
Matplotlib – Visualization with Python, 2024. [Online]. Available at: https://matplotlib.org/.
Android Permission Dataset, 2021, May 29, Kaggle. [Online]. Available at: https://www.kaggle.com/datasets/saurabhshahane/android-permission-dataset.
N. H. Saeed, A. A. Hamza, M. A. Sobh, and A. M. Bahaa-Eldin, “Efficient feature ranked hybrid framework for android IoT malware detection,” Sci Rep, vol. 16, 3726, 2026. https://doi.org/10.1038/s41598-026-35238-6.
A. Kadir, S.K. Peddoju, “PacDroid: lightweight android malware detection using permissions and intent features,” Multimed Tools Appl, vol. 84, pp. 32351–32379, 2025. https://doi.org/10.1007/s11042-024-20455-w.
A. M. H. Othman, M. F. A. Razak, S. M. Asmara, and S. N. Ramli, “Artificial intelligence-driven detection of Android malware using machine learning techniques,” International Journal on Advanced Science Engineering and Information Technology, vol. 15, issue 5, pp. 1656–1662, 2025. https://doi.org/10.18517/ijaseit.15.5.13405.
Downloads
Published
How to Cite
Issue
Section
License
International Journal of Computing is an open access journal. Authors who publish with this journal agree to the following terms:• Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
• Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
• Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.