arrow
Return

Using Machine Learning to Detect Vault (Anti-Forensic) Apps

delete2025-04-22
delete0
delete
OA
AI
M
Michael N. Johnstone *
W
Wencheng Yang
M
Mohiuddin Ahmed
DOI:10.3390/fi17050186delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Content hiding, or vault applications (apps), are designed with a secondary, often concealed purpose, such as encrypting and storing files. While these apps may serve legitimate functions, they unequivocally present significant challenges for law enforcement. Conventional methods for tackling this issue, whether static or dynamic, prove inadequate when devices-typically smartphones-cannot be modified. Additionally, these methods frequently require prior knowledge of which apps are classified as vault apps. This research decisively demonstrates that a non-invasive method of app analysis, combined with machine learning, can effectively identify vault apps. Our findings reveal that it is entirely possible to detect an Android vault app with 98% accuracy using a random forest classifier. This clearly indicates that our approach can be instrumental for law enforcement in their efforts to address this critical issue.
Keywords:
software development
vault apps
content hiding
malware detection
machine learning
Android

Journal

Future Internet cover
Future Internet
IF:
3.6
Papers:
1.2K
Citations:
6.5K

Organization

U
Univ Southern Queensland
Scholars:
277
Papers: 202
Citations: 103