Advanced Malware Detection TechniquesDigital and Cyber ForensicsSoftware Testing and Debugging Techniques

Yiming Wu, Zhuo Liu, Yanjie Lin, Binbin Zhao, Chunyi Zhou, Tiejun Wu, Z. Hong

2026.1.1Cyber Security and Applications

DOI: 10.1016/j.csa.2026.100124

Abstract

The Android operating system, dominating over 85% of the mobile market through open-source flexibility, suffers from intrinsic vulnerabilities. The APK(Android Package Kit) parsability and Smali code modifiability enable attackers to decompile applications via tools. This facilitates widespread repackaging-malicious actors inject payloads or tamper with functionality, redistributing counterfeit applications(apps) through third-party markets. These practices cause dual damage. Developers face code theft and revenue diversion, while users endure privacy leaks, financial fraud, and device compromise. Consequently, accurate repackaging detection has become critical. This paper reviews recent progress in repackaging detection techniques for Android applications. We first outline the fundamental characteristics of Android apps and then examine detection methods based on code analysis and resource similarity. Frequently used Android app datasets and evaluation metrics for measuring the effectiveness of repackaging detection methods are also summarized. Finally, we discuss the development trends of repackaging detection techniques and identify future research directions, with the aim of providing meaningful insights and guidance for researchers in this domain.

Citation format

WU, Yiming, et al. Android app repackaging detection: A comprehensive survey. Cyber Security and Applications, 2026, 4: 100124.