Towards Understanding Android APIs: Official Lists, Vendor Customizations, and Real-World Usage
Android apps are built on APIs that abstract core Android system functionalities. These APIs are officially documented in multiple files distributed with the Android source code or SDK, which we collectively refer to as Android API Lists (AALs). Prior Android research has relied on specific AALs, often treating them as interchangeable ground truth. However, recent studies suggest that different AALs can lead to substantially different research outcomes, raising concerns about the validity and reproducibility of Android API-based analyses. To address this issue, we present the first in-depth empirical study of four official AALs that are widely used in prior work. We systematically characterize their contents and analyze their evolution across Android releases. We then perform a fine-grained comparison of the APIs recorded in each AAL to uncover their underlying API inclusion policies and inconsistencies. To assess the practical impact of these differences, we further examine API availability on nine Android devices, including both stock Android and vendor-customized systems. Finally, we analyze API usage in 17,759 real-world Android apps (including open-source apps, commercial apps, and malware) to quantify how the choice of AAL affects empirical Android research. Our results reveal that official AALs are neither stable nor mutually consistent, and that discrepancies among them can substantially influence research conclusions. We also observe that vendor-customized APIs are actively used by normal apps, yet remain largely overlooked by existing studies. Based on these findings, we discuss their implications for Android API-based research and provide actionable suggestions to help researchers select and interpret AALs more reliably.
Thu 11 JunDisplayed time zone: London change
09:00 - 10:30 | APIs and EcosystemsResearch Papers / Short Papers and Emerging Results / AI Models / Data / Industry Papers at JMS 743 Chair(s): Iulian Neamtiu New Jersey Institute of Technology | ||
09:00 15mTalk | MavCrawl: A Comprehensive Dataset of Maven Libraries with Metadata and Their Dependencies AI Models / Data Abhinav Jamwal Dept. of Computer Science & Engineering, Indian Institute of Technology, Roorkee, India, Parvathi Nair Indian Institute of Technology Roorkee, Siya Arora Indian Institute of Technology Roorkee, Manish Agrawal Indian Institute of Technology Roorkee, Sandeep Kumar Dept. of Computer Science & Engineering, Indian Institute of Technology, Roorkee, India | ||
09:15 15mTalk | Towards Understanding Android APIs: Official Lists, Vendor Customizations, and Real-World Usage Research Papers Sinan Wang Southern University of Science and Technology, Qi Zhang Hong Kong University of Science and Technology, Jiacheng Li University of Maryland, Lili Wei McGill University, Yida Tao Southern University of Science and Technology, Yepang Liu Southern University of Science and Technology Pre-print | ||
09:30 10mTalk | Making OpenAPI Documentation Agent-Ready: Detecting Documentation and REST Smells with a Multi-Agent LLM System Industry Papers Rayfran Lima SIDIA R&D Institute, Davi G. Assunção Pinheiro Sidia Institute of Technology, Thiago Medeiros Menezes Sidia Institute of Technology Pre-print | ||
09:40 10mTalk | Hallucination Inspector: A Fact-Checking Judge for API Migration Short Papers and Emerging Results Marcos Tileria , Santanu Dash University of Surrey, Profir-Petru Pârțachi Institute of Science Tokyo, Earl T. Barr University College London Pre-print | ||