Tri Wahyuni
Universitas Muhammadiyah Makassar

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Ensemble Learning for Android Privacy-Risk Flow Pre-Screening Using Permission and Metadata Features Tri Wahyuni; Muhammad Faisal; Titin Wahyuni; Nurnawaty; Rio Prasetyo Lukodono; Titik Khawa Abd Rahman
Journal of Embedded Systems, Security and Intelligent Systems Vol 7 No 3 (2026): September 2026
Publisher : Program Studi Teknik Komputer

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59562/jessi.v7i3.13180

Abstract

Purpose - This study develops a privacy-oriented pre-screening framework for identifying Android applications with potential Sensitive Data Exposure by combining lightweight permission and metadata features with ensemble learning. Design/methods/approach - Android applications obtained from the AndroZoo repository were analyzed using FlowDroid to construct reference labels based on sensitive source–sink flows. Privacy-oriented features were derived from permissions, application metadata, source and sink indicators, and interaction patterns. An Ensemble Stacking model integrating Random Forest, Support Vector Machine, and Extreme Gradient Boosting with Logistic Regression as the meta-classifier was evaluated under class imbalance. Additional circularity, ablation, repeated validation, and clean-feature experiments were conducted to assess robustness and deployment feasibility. Findings - The proposed framework demonstrated strong capability in distinguishing applications containing FlowDroid-defined potential privacy-risk flows. FlowDroid-derived source and sink indicators were highly discriminative, while permission-only features were less effective. Importantly, the clean-feature configuration retained strong discriminatory capability without requiring FlowDroid at inference time, supporting its use as a lightweight first-stage screening mechanism before more computationally intensive taint analysis. Research implications/limitations - The framework can support developers, security auditors, and platform administrators in prioritizing applications for deeper privacy inspection. However, the study relies on static analysis, a single application repository, and FlowDroid-derived reference labels. Originality/value - This study contributes a two-stage Android privacy-risk screening framework that combines lightweight deployable features with targeted static taint analysis while explicitly addressing label-feature circularity and inference-time feasibility.