PADLOCK: A Context-Aware On-Device System for Android Permission-Risk Assessment – A Tanzanian Case Study
DOI:
https://doi.org/10.63158/journalisi.v8i3.1586Keywords:
Android security, permission-risk assessment, machine learning, on-device inference, mobile privacy, financial applicationsAbstract
Android applications often request sensitive permissions beyond their functional needs, creating privacy and security risks, especially in financial and digital lending apps. Existing Android permission mechanisms provide limited visibility into how permissions are used at runtime. This study proposes PADLOCK, a context-aware prototype for event-driven permission monitoring and contextual risk assessment. The methodology combined a survey-based user study (n = 600), analysis of 3,816 applications, machine learning development, and Android prototype implementation. A compact deep neural network, ShieldAI, was trained on permission-based features with heuristic risk labels to classify applications as benign or potentially higher-risk. The model was integrated into PADLOCK to support on-device monitoring and user-guided permission decisions. On a held-out test set, ShieldAI achieved 96.73% accuracy, 94.82% precision, and 92.42% recall. Controlled on-device testing showed an inference latency of approximately 2–3 ms per prediction and indicated reduced higher-risk permission-granting behaviour in PADLOCK-assisted evaluations. This study contributes an integrated Android prototype combining contextual permission analysis, machine-learning-based risk assessment, and event-driven monitoring. However, the findings remain limited to the evaluated dataset and controlled conditions, and broader real-world validation is required.
Downloads
References
[1] C. Liu, J. Lu, W. Feng, E. Du, L. Di, and Z. Song, “MOBIPCR: Efficient, accurate, and strict ML-based mobile malware detection,” Future Generation Computer Systems, vol. 144, pp. 140–150, Jul. 2023, doi: 10.1016/j.future.2023.02.014.
[2] S. Yilmaz and M. Davis, “Hidden Permissions on Android: A Permission-Based Android Mobile Privacy Risk Model,” European Conference on Cyber Warfare and Security, vol. 22, no. 1, pp. 717–724, Jun. 2023, doi: 10.34190/eccws.22.1.1453.
[3] G. S. Tuncay, “Android Permissions: Evolution, Attacks, and Best Practices,” IEEE Secur. Priv., vol. 22, no. 6, pp. 40–49, 2024, doi: 10.1109/MSEC.2024.3461629.
[4] D. Hayes, F. Cappa, and N. A. Le-Khac, “An effective approach to mobile device management: Security and privacy issues associated with mobile applications,” Digital Business, vol. 1, no. 1, p. 100001, Sep. 2020, doi: 10.1016/j.digbus.2020.100001.
[5] B. Mishra et al., “Privacy Protection Framework for Android,” IEEE Access, vol. 10, pp. 7973–7988, 2022, doi: 10.1109/ACCESS.2022.3142345.
[6] O. A. Akanji, M. Egele, and G. Stringhini, “The Cost of Convenience: Identifying, Analyzing, and Mitigating Predatory Loan Applications on Android,” in Proc. ACM Asia Conf. Comput. Commun. Secur. (ASIA CCS ’26), Bangalore, India, Jun. 2026, doi: 10.1145/3779208.3785263.
[7] C. W. Munyendo, Y. Acar, and A. J. Aviv, “‘Desperate Times Call for Desperate Measures’: User Concerns with Mobile Loan Apps in Kenya,” Proc. IEEE Symp. Secur. Priv., pp. 2304–2319, May 2022, doi: 10.1109/SP46214.2022.9833779.
[8] E. Caushaj and V. Sugumaran, “Classification and security assessment of Android apps,” Discover Internet of Things, vol. 3, p. 15, Oct. 2023, doi: 10.1007/S43926-023-00047-0.
[9] Tanzania Communications Regulatory Authority (TCRA), “Communications Statistics Report,” Sep. 2025, Accessed: Mar. 06, 2026. [Online]. Available: https://www.tcra.go.tz/services/statistics
[10] M. Khedkar, A. Kumar Mondal, and E. Bodden, “A study of privacy-related data collected by Android apps,” Automated Software Engineering, vol. 33, no. 2, p. 45, Jan. 2026, doi: 10.1007/s10515-025-00589-3.
[11] Bank of Tanzania and Tanzania Communications Regulatory Authority, “Regulatory Notice on Unlicensed Digital Lending Applications,” Nov. 2024, Accessed: Mar. 06, 2026. [Online]. Available: https://www.bot.go.tz/PressRelease
[12] I. M. Almomani and A. Al Khayer, “A Comprehensive Analysis of the Android Permissions System,” IEEE Access, vol. 8, pp. 216671–216688, Nov. 2020, doi: 10.1109/ACCESS.2020.3041432.
[13] W. Wang, C. Ren, H. Song, S. Zhang, and P. Liu, “FGL_Droid: An Efficient Android Malware Detection Method Based on Hybrid Analysis,” Security and Communication Networks, vol. 2022, no. 1, p. 8398591, Jan. 2022, doi: 10.1155/2022/8398591.
[14] V. Ayres-Pereira, A. Pirrone, M. Korbmacher, I. Tjostheim, and G. Böhm, “The privacy and control paradoxes in the context of smartphone apps,” Front. Comput. Sci., vol. 4, p. 986138, Sep. 2022, doi: 10.3389/fcomp.2022.986138.
[15] S. S. Bakare, A. O. Adeniyi, C. U. Akpuokwe, and N. E. Eneh, “Data Privacy Laws And Compliance: A Comparative Review Of The Eu Gdpr And Usa Regulations,” Computer Science & IT Research Journal, vol. 5, no. 3, pp. 528–543, Mar. 2024, doi: 10.51594/csitrj.v5i3.859.
[16] A. Lekshmi, J. Atul, A. J. Pillai, M. Dhanya, and S. Kaladharan, “Risks in Instant Loan Apps: Analyzing User Perceptions Using Machine Learning Approach,” in ICT Analysis and Applications, S. Fong, N. Dey, and A. Joshi, Eds., Lecture Notes in Networks and Systems, vol. 1161. Singapore, Springer, Mar. 2025, pp. 461–471. doi: 10.1007/978-981-97-8602-2_41.
[17] O. Haggag, A. Pedace, S. Pan, and J. Grundy, “An analysis of privacy regulations and user concerns of finance mobile applications,” Inf. Softw. Technol., vol. 184, Aug. 2025, doi: 10.1016/j.infsof.2025.107756.
[18] S. D. Minc, P. P. Chandanabhumma, C. L. Sedney, T. S. Haggerty, D. M. Davidov, and R. A. Pollini, “Mixed methods research: A primer for the vascular surgeon,” Semin. Vasc. Surg., vol. 35, no. 4, pp. 447–455, Dec. 2022, doi: 10.1053/j.semvascsurg.2022.09.003.
[19] T. Yamane, Statistics: An Introductory Analysis, 2nd ed. New York: Harper and Row, 1967.
[20] F. Breitinger, R. Tully-Doyle, and C. Hassenfeldt, “A survey on smartphone user’s security choices, awareness and education,” Comput. Secur., vol. 88, p. 101647, Jan. 2020, doi: 10.1016/J.COSE.2019.101647.
[21] M. Sandesara et al., “Design and Experience of Mobile Applications: A Pilot Survey,” Mathematics, vol. 10, no. 14, p. 2380, Jul. 2022, doi: 10.3390/MATH10142380.
[22] S. Maganur, Y. Jiang, J. Huang, and F. Zhong, “Feature-Centric Approaches to Android Malware Analysis: A Survey,” Computers, vol. 14, no. 11, p. 482, Nov. 2025, doi: 10.3390/computers14110482.
[23] P. K. Mvula, P. Branco, G. V. Jourdan, and H. L. Viktor, “A Survey on the Applications of Semi-supervised Learning to Cyber-security,” ACM Comput. Surv., vol. 56, no. 10, Jun. 2024, doi: 10.1145/3657647.
[24] Google, “Android Apps on Google Play,” Google Play Store. Accessed: Jan. 20, 2025. [Online]. Available: https://play.google.com/store/apps
[25] L. Wang, M. Han, X. Li, N. Zhang, and H. Cheng, “Review of Classification Methods on Unbalanced Data Sets,” IEEE Access, vol. 9, pp. 64606–64628, Apr. 2021, doi: 10.1109/ACCESS.2021.3074243.
[26] A. Kaur, S. Lal, S. Goel, M. Pandey, and A. Agarwal, “Android Malware Detection System using Machine Learning,” ACM International Conference Proceeding Series, vol. 1, pp. 186–191, Oct. 2024, doi: 10.1145/3675888.3676049.
[27] S. Lee and S. Han, “SMAD: Semi-Supervised Android Malware Detection via Consistency on Fine-Grained Spatial Representations,” Electronics (Basel)., vol. 14, no. 21, p. 4246, Oct. 2025, doi: 10.3390/electronics14214246.
[28] A. Muzaffar, H. R. Hassen, H. Zantout, and M. A. Lones, “ActDroid: An active learning framework for android malware detection,” Comput. Secur., vol. 160, Jan. 2026, doi: 10.1016/j.cose.2025.104724.
[29] D. Elreedy et al., “A theoretical distribution analysis of synthetic minority oversampling technique (SMOTE) for imbalanced learning,” Mach. Learn., vol. 113, no. 7, pp. 4903–4923, Jan. 2023, doi: 10.1007/S10994-022-06296-4.
[30] J. Sadaiyandi, P. Arumugam, A. K. Sangaiah, and C. Zhang, “Stratified Sampling-Based Deep Learning Approach to Increase Prediction Accuracy of Unbalanced Dataset,” Electronics (Basel)., vol. 12, no. 21, p. 4423, Oct. 2023, doi: 10.3390/electronics12214423.
[31] I. Salehin and D. K. Kang, “A Review on Dropout Regularization Approaches for Deep Neural Networks within the Scholarly Domain,” Electronics (Basel)., vol. 12, no. 14, p. 3106, Jul. 2023, doi: 10.3390/electronics12143106.
[32] S. Song and S. Yang, “TS-SMOTE: An Improved SMOTE Method Based on Symmetric Triangle Scoring Mechanism for Solving Class-Imbalanced Problems,” Symmetry (Basel)., vol. 17, no. 8, p. 1326, Aug. 2025, doi: 10.3390/SYM17081326.
[33] J. C. Obi, “A comparative study of several classification metrics and their performances on data,” World Journal of Advanced Engineering Technology and Sciences, vol. 8, no. 1, pp. 308–314, Feb. 2023, doi: 10.30574/wjaets.2023.8.1.0054.
[34] Flutter Developers, “Platform Channels: Writing Custom Platform-Specific Code,” Flutter Documentation. Accessed: Apr. 25, 2026. [Online]. Available: https://docs.flutter.dev/platform-integration/platform-channels
[35] A. Mahindru et al., “PermDroid a framework developed using proposed feature selection approach and machine learning techniques for Android malware detection,” Sci. Rep., vol. 14, no. 1, p. 10724, May 2024, doi: 10.1038/s41598-024-60982-y.
[36] A. Nandan Prasad, “Ethical Implications and Bias Mitigation,” in Introduction to Data Governance for Machine Learning Systems: Fundamental Principles, Critical Practices, and Future Trends, A. Nandan Prasad, Ed., Berkeley, CA: Apress, 2024, pp. 307–382. doi: 10.1007/979-8-8688-1023-7_5.
[37] J. Senanayake, H. Kalutarage, and M. O. Al-Kadri, “Android mobile malware detection using machine learning: A systematic review,” Electronics (Basel)., vol. 10, no. 13, p. 1606, Jul. 2021, doi: 10.3390/electronics10131606.
[38] A. R. Nasser, A. M. Hasan, and A. J. Humaidi, “DL-AMDet: Deep learning-based malware detector for android,” Intelligent Systems with Applications, vol. 21, p. 200318, Mar. 2024, doi: 10.1016/J.ISWA.2023.200318.
[39] O. N. Elayan and A. M. Mustafa, “Android Malware Detection Using Deep Learning,” Procedia Comput. Sci., vol. 184, pp. 847–852, Jan. 2021, doi: 10.1016/J.PROCS.2021.03.106.
[40] M. Ibrahim, B. Issa, and M. B. Jasser, “A Method for Automatic Android Malware Detection Based on Static Analysis and Deep Learning,” IEEE Access, vol. 10, pp. 117334–117352, 2022, doi: 10.1109/ACCESS.2022.3219047.
[41] N. Topalli and A. Badii, “A User-Centric Context-Aware Framework for Real-Time Optimisation of Multimedia Data Privacy Protection, and Information Retention Within Multimodal AI Systems,” Sensors, vol. 25, no. 19, p. 6105, Oct. 2025, doi: 10.3390/s25196105.
[42] J. L. Herrera, H. Y. Chen, J. Berrocal, J. M. Murillo, and C. Julien, “Context-aware privacy-preserving access control for mobile computing,” Pervasive Mob. Comput., vol. 87, p. 101725, Dec. 2022, doi: 10.1016/j.pmcj.2022.101725.
[43] M. Chaudhary and A. Masood, “RealMalSol: real-time optimized model for Android malware detection using efficient neural networks and model quantization,” Neural Comput. Appl., vol. 35, no. 15, pp. 11373–11388, Feb. 2023, doi: 10.1007/s00521-023-08303-8.
[44] A. Pathak, U. Barman, and T. S. Kumar, “Machine learning approach to detect android malware using feature-selection based on feature importance score,” Journal of Engineering Research, vol. 13, no. 2, pp. 712–720, Jun. 2025, doi: 10.1016/j.jer.2024.04.008.
[45] M. K. Alzaylaee, S. Y. Yerima, and S. Sezer, “DL-Droid: Deep learning based android malware detection using real devices,” Comput. Secur., vol. 89, p. 101663, Feb. 2020, doi: 10.1016/j.cose.2019.101663.
[46] J. Kim, Y. Ban, E. Ko, H. Cho, and J. H. Yi, “MAPAS: a practical deep learning-based android malware detection system,” International Journal of Information Security 2022 21:4, vol. 21, no. 4, pp. 725–738, Feb. 2022, doi: 10.1007/s10207-022-00579-6.
[47] A. Alhussen, “Advanced Android Malware Detection through Deep Learning Optimization,” Engineering, Technology & Applied Science Research, vol. 14, no. 3, pp. 14552–14557, Jun. 2024, doi: 10.48084/etasr.7443.
[48] R. Ma, S. Yin, X. Feng, H. Zhu, and V. S. Sheng, “A lightweight deep learning-based android malware detection framework,” Expert Syst. Appl., vol. 255, p. 124633, Dec. 2024, doi: 10.1016/j.eswa.2024.124633.
[49] V. Sekara, L. Alessandretti, E. Mones, and H. Jonsson, “Temporal and cultural limits of privacy in smartphone app usage,” Sci. Rep., vol. 11, no. 1, p. 3861, Feb. 2021, doi: 10.1038/s41598-021-82294-1.
[50] A. Ehsan, C. Catal, and A. Mishra, “Detecting Malware by Analyzing App Permissions on Android Platform: A Systematic Literature Review,” vol. 22, no. 20, p. 7928, Oct. 2022, doi: 10.3390/S22207928.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Journal of Information Systems and Informatics

This work is licensed under a Creative Commons Attribution 4.0 International License.
Authors Declaration
- The Authors certify that they have read, understood, and agreed to the Journal of Information Systems and Informatics (JournalISI) submission guidelines, policies, and submission declaration. The submission has been prepared using the provided template.
- The Authors certify that all authors have approved the publication of this manuscript and that there is no conflict of interest.
- The Authors confirm that the manuscript is their original work, has not received prior publication, is not under consideration for publication elsewhere, and has not been previously published.
- The Authors confirm that all authors listed on the title page have contributed significantly to the work, have read the manuscript, attest to the validity and legitimacy of the data and its interpretation, and agree to its submission.
- The Authors confirm that the manuscript is not copied from or plagiarized from any other published work.
- The Authors declare that the manuscript will not be submitted for publication in any other journal or magazine until a decision is made by the journal editors.
- If the manuscript is finally accepted for publication, the Authors confirm that they will either proceed with publication immediately or withdraw the manuscript in accordance with the journal’s withdrawal policies.
- The Authors agree that, upon publication of the manuscript in this journal, they transfer copyright or assign exclusive rights to the publisher, including commercial rights














