Machine Learning Analysis of Potential Mobile Apps Threats on the Basis of Permissions

Authors

  • Tetiana Hovorushchenko
  • Olga Pavlova
  • Vitalii Alekseiko

DOI:

https://doi.org/10.47839/ijc.25.2.4657

Keywords:

mobile application, permission, threat, machine learning, cybersecurity

Abstract

Nowadays, the use of mobile applications is extremely common. The number of new applications is constantly increasing, and accordingly, because of this, it is becoming increasingly difficult to determine the level of danger of a particular application. The issue of privacy and data security is especially acute, particularly because of the permissions that apps request. Such permissions can give applications access to sensitive user information and system resources, which, if misused, can lead to security risks. This research focuses on mobile application threat analysis using machine learning (ML) with a focus on the Android Permission dataset. By examining how different apps use and potentially abuse permissions, this research aims to identify high-risk apps that pose a serious threat to user privacy and cybersecurity. The importance of permissions as a vector for understanding mobile app security is undeniable, and a permission-based ML analysis approach can improve current app verification processes. This methodology can be further extended to include dynamic analysis where application behavior is monitored in real-time, providing an even more robust assessment of security risks in mobile environments.

References

I. Pekaric, C. Sauerwein, S. Laichner, and R. Breu, “How do mobile applications enhance security? An exploratory analysis of use cases and provided information,” Proceedings of the 2025 ACM Southeast Conference (ACMSE 2025). Association for Computing Machinery, New York, NY, USA, 2025, pp. 114–123. https://doi.org/10.1145/3696673.3723067.

H. I. Maseeh, C. Jebarajakirthy, A. Sivapalan, M. Ross, and M. Rehman, “Understanding smartphone users’ app usage with restricted permissions,” Information Technology & People, vol. 38, no. 2, pp. 1045–1088, 2025. https://doi.org/10.1108/ITP-03-2022-0200.

A. R. Nasab, M. Dashti, M. Shahin, M. Zahedi, H. Khalajzadeh, C. Arora, and P. Liang, “Fairness concerns in app reviews: A study on AI-based mobile apps,” ACM Trans. Softw. Eng. Methodol, vol. 34, issue 2, article 51, pp. 1-30, 2025. https://doi.org/10.1145/3690633.

M. Tahaei, R. Abu-Salma, and R. Awais, “Stuck in the permissions with you: Developer & end-user perspectives on app permissions & their privacy ramifications,” Proceedings of the ACM 2023 CHI Conference on Human Factors in Computing Systems (CHI'23), article 168, 2023, pp. 1–24. https://doi.org/10.1145/3544548.3581060.

C. I. Eke, A. A. Norman, & M. Mulenga, “Machine learning approach for detecting and combating bring your own device (BYOD) security threats and attacks: a systematic mapping review,” Artificial Intelligence Review, vol. 56, issue 8, pp. 8815-8858, 2023. https://doi.org/10.1007/s10462-022-10382-3.

A. Guerra-Manzanares, H. Bahsi, & M. Luckner, “Leveraging the first line of defense: A study on the evolution and usage of android security permissions for enhanced android malware detection,” Journal of Computer Virology and Hacking Techniques, vol. 19, issue 1, pp. 65-96, 2023. https://doi.org/10.1007/s11416-022-00432-3.

F. Wang, N. Yang, P. M. Shakeel, & V. Saravanan, “Machine learning for mobile network payment security evaluation system,” Transactions on Emerging Telecommunications Technologies, vol. 35, issue 4, e4226, 2024. https://doi.org/10.1002/ett.4226.

V. J. Raymond, R. J. R. Raj, & J. Retna, “Investigation of Android malware with machine learning classifiers using enhanced PCA algorithm,” Comput. Syst. Sci. Eng., vol. 44, issue 3, pp. 2147-2163, 2025. https://doi.org/10.32604/csse.2023.028227.

A. Gómez, & A. Muñoz, “Deep learning-based attack detection and classification in Android devices,” Electronics, vol. 12, issue 15, 3253, 2023. https://doi.org/10.3390/electronics12153253.

I. Naseer, “Machine learning applications in cyber threat intelligence: A comprehensive review,” The Asian Bulletin of Big Data Management, vol. 3, issue 2, pp. 190-200, 2023. https://doi.org/10.62019/abbdm.v3i2.85.

I. H. Sarker, “Machine learning for intelligent data analysis and automation in cybersecurity: current and future prospects,” Annals of Data Science, vol. 10, issue 6, pp. 1473-1498, 2023. https://doi.org/10.1007/s40745-022-00444-2.

N. B. Alom, “A comprehensive analysis of customer behavior analytics, privacy concerns, and data protection regulations in the era of big data and machine learning,” International Journal of Applied Machine Learning and Computational Intelligence, vol. 14, issue 5, pp. 21-40, 2024.

P. Bhat, S. Behal, & K. Dutta, “A system call-based android malware detection approach with homogeneous & heterogeneous ensemble machine learning,” Computers & Security, vol. 130, 103277, 2023. https://doi.org/10.1016/j.cose.2023.103277.

H. N. Fakhouri, S. Alawadi, F. M. Awaysheh, I. B. Hani, M. Alkhalaileh, & F. Hamad, “A comprehensive study on the role of machine learning in 5G security: challenges, technologies, and solutions,” Electronics, vol. 12, issue 22, 4604, 2023. https://doi.org/10.3390/electronics12224604.

T. Hovorushchenko, A. Herts, A. Boyarchuk, & O. Pavlova, “System for determination of legal responsibility/penalty for a cybersecurity breach,” Proceedings of the ITTAP’2022, 2022, pp. 233-240.

T. Hovorushchenko, O. Pavlova, & M. Kostiuk, “Method of increasing the security of smart parking system,” Journal of Cyber Security and Mobility, vol. 12, issue 3, pp. 297–314, 2023. https://doi.org/10.13052/jcsm2245-1439.123.3.

E. Zaitseva, T. Hovorushchenko, O. Pavlova, Y. Voichur, “Identifying the mutual correlations and evaluating the weights of factors and consequences of mobile application insecurity,” Systems, vol. 11, 242, 2023. https://doi.org/10.3390/systems11050242.

R. Mayya, and S. Viswanathan, “Delaying informed consent: An empirical investigation of mobile apps’ upgrade decisions,” Management Science, vol. 71, issue 8, pp. 7113-7135, 2024. https://doi.org/10.1287/mnsc.2022.00334.

R. Mohammadi, M. M. Hosseini, R. Bahrami, “Uncovering security vulnerabilities through multiplatform malware analysis,” Security and Privacy, vol. 8, issue 1, e455, 2025. https://doi.org/10.1002/spy2.455.

L. Wei, H. Huang, S.C. Cheung, K. Li, “How far are app secrets from being stolen? A case study on Android,” Empir Software Eng, vol. 30, article 90, 2025. https://doi.org/10.1007/s10664-024-10607-9.

J. Apoorva, “AI-driven malware behaviour classification and detection systems,” International Journal of Advanced Research in Computer Science and Engineering (IJARCSE), vol. 1, issue 3, pp. 16–24, 2025. https://ijarcse.org/index.php/ijarcse/article/view/69.

Matplotlib – Visualization with Python, 2024. [Online]. Available at: https://matplotlib.org/.

Android Permission Dataset, 2021, May 29, Kaggle. [Online]. Available at: https://www.kaggle.com/datasets/saurabhshahane/android-permission-dataset.

N. H. Saeed, A. A. Hamza, M. A. Sobh, and A. M. Bahaa-Eldin, “Efficient feature ranked hybrid framework for android IoT malware detection,” Sci Rep, vol. 16, 3726, 2026. https://doi.org/10.1038/s41598-026-35238-6.

A. Kadir, S.K. Peddoju, “PacDroid: lightweight android malware detection using permissions and intent features,” Multimed Tools Appl, vol. 84, pp. 32351–32379, 2025. https://doi.org/10.1007/s11042-024-20455-w.

A. M. H. Othman, M. F. A. Razak, S. M. Asmara, and S. N. Ramli, “Artificial intelligence-driven detection of Android malware using machine learning techniques,” International Journal on Advanced Science Engineering and Information Technology, vol. 15, issue 5, pp. 1656–1662, 2025. https://doi.org/10.18517/ijaseit.15.5.13405.

Downloads

Published

2026-06-30

How to Cite

Hovorushchenko, T., Pavlova, O., & Alekseiko, V. (2026). Machine Learning Analysis of Potential Mobile Apps Threats on the Basis of Permissions. International Journal of Computing, 25(2), 315-323. https://doi.org/10.47839/ijc.25.2.4657

Issue

Section

Articles