SANER 2026
Tue 17 - Fri 20 March 2026 Limassol, Cyprus

Repackaging is a widely used technique for modifying existing Android applications by introducing targeted changes to their code and resources. Malicious actors exploit it to distribute malware, commit plagiarism, and exfiltrate sensitive data. Although often described as a straightforward process, requiring only that an app be downloaded, decompiled, modified, and redistributed, its practical use in research contexts reveals a more complex reality. Existing work frequently overlooks why certain repackaging attempts fail, as well as the potential impact of repackage-proofing mechanisms embedded within apps. To address this gap, we present InstruMate, a novel approach for systematically assessing the repackaging resilience of Android applications. InstruMate progressively escalates from simple modifications—such as altering the app’s signature—to more complex interventions targeting code instrumentation. Each modified version is rigorously assessed against the original using novel health-check procedures that reveal discrepancies in the user interface and execution behavior. We demonstrate this approach, by evaluating the resilience to repackaging of 156 highly popular apps obtained from the Google Play Store (including WhatsApp Messenger, LinkedIn, Roblox, TikTok, among others), each exceeding one billion installations worldwide. The results reveal that 86% of the analyzed apps are non-resilient to the most basic form of repackaging involving only a signature change; 81% can be modified to enable execution in debug mode; and 83% exhibit no resistance to superficial appearance modifications. Beyond these surface-level changes, more sophisticated transformations using black-box static and dynamic instrumentation show that 65% of the apps remain susceptible to code tampering. In contrast, 11% of the apps in our dataset actively resist repackaging through explicit user warnings or runtime exceptions that abruptly terminate execution. We further trace several of these defenses to specific anti-repackaging mechanisms integrated within the analyzed applications.

Wed 18 Mar

Displayed time zone: Athens change

16:00 - 17:30
Session 3B - Evolution and Security of Mobile SystemsResearch Track / Short Papers and Posters Track at Megaron Beta
Chair(s): Vadim Zaytsev University of Twente
16:00
15m
Talk
Relocate and Emulate: Re-Hosting Android’s Application Layer
Research Track
Thomas Sutter University of Bern, Timo Kehrer University of Bern, Marc Rennhard Zurich University of Applied Sciences, Bernhard Tellenbach Armasuisse Cyber-Defence Campus
16:15
15m
Talk
Scratching the Iceberg: Unveiling the Outdated Third-Party Native Libraries in Android Apps
Research Track
Shiyang Zhang Tianjin University, Chengwei Liu Nankai University, Sen Chen Nankai University, Lyuye Zhang Nanyang Technological University, Yang Liu Nanyang Technological University
16:30
15m
Talk
Dialing Danger: Large-Scale Mining and Risk Assessment of Android Secret Codes in OEM Firmware
Research Track
Ruoyan Lin Shandong University, Shishuai Yang Zhengzhou University of Aeronautics, Fenghao Xu Southeast University, Wenrui Diao Shandong University
16:45
15m
Talk
InstruMate: A Systematic Framework for Assessing Android App Repackaging Resilience
Research Track
Leandro de Souza Oliveira , Rodrigo Bonifácio Informatics Center - CIn/UFPE and Computer Science Department / University of Brasília, Joanna C. S. Santos University of Notre Dame, Rui Rua New York University Abu Dhabi
17:00
15m
Talk
An Empirical Study of Privacy Leakage Vulnerability in Third-Party Android Logs Libraries
Research Track
Yixi Zhao University of Waterloo, Kundi Yao Ontario Tech University, Yiming Tang Rochester Institute of Technology, Weiyi Shang University of Waterloo
17:15
7m
Talk
AMF-GR: Adaptive Matrix Factorization and Graph Fusion for Android Library Recommendation
Short Papers and Posters Track
Abhinav Jamwal Dept. of Computer Science & Engineering, Indian Institute of Technology, Roorkee, India, Sandeep Kumar Dept. of Computer Science & Engineering, Indian Institute of Technology, Roorkee, India
17:22
7m
Talk
BUPLinker: Bridging Users and Developers in Mobile Application Evolution
Short Papers and Posters Track
Ayana Uematsu Waseda University, Hironori Washizaki Waseda University, Naoyasu Ubayashi Waseda University, Masanari Kondo Kyushu University, Juichi Takahashi AGEST, Inc, Yohei Takagi AGEST Inc.