Sep 2026· International Journal of Interactive Mobile Technologies (ijim)· 0 citations· 11 references
TL;DR
GeminiShield is proposed, a layered security architecture that integrates Gemini AI across the Android software stack, and its efficacy is validated through comparative analysis against state-of-the-art approaches, demonstrating detection accuracy of 97.3%, outperforming prior approaches while maintaining acceptable computational overhead on resource-constrained devices.
Abstract
Android remains the world’s dominant mobile operating system with over 3.5 billion active devices, making it a prime target for increasingly sophisticated security threats and privacy violations. Traditional signature-based and rule-driven defenses are proving insufficient against polymorphic malware, zero-day exploits, and context-aware privacy attacks. This paper presents a comprehensive investigation into security vulnerabilities and privacy challenges in the Android ecosystem, with a particular focus on how Google’s latest Gemini AI family, including Gemini Nano for on-device inference, Gemini Pro for cloud-assisted analysis, and Gemini 1.5 for long-context threat intelligence, fundamentally transforms threat detection and privacy enforcement. We survey the contemporary Android threat landscape spanning ransomware, banking trojans, spyware, and supply chain attacks, then systematically evaluate Gemini AI’s contributions to behavioral malware detection, real-time permission auditing, contextual privacy advisory, and natural language-driven threat intelligence. We further propose GeminiShield, a layered security architecture that integrates Gemini AI across the Android software stack, and validate its efficacy through comparative analysis against state-of-the-art approaches. Our results demonstrate detection accuracy of 97.3%, outperforming prior approaches while maintaining acceptable computational overhead on resource-constrained devices. Open challenges including adversarial attacks on AI models, on-device inference constraints, and regulatory compliance are critically discussed.
A static analysis framework for Android malware detection that couples a LightGBM classifier with SHapley Additive exPlanations and a mapping layer built on the MITRE ATT&CK knowledge base is described.
Pavitra Murapala, L. Dr.· International Journal of Inn...· 0 citations
Android apps handle sensitive data, often displayed on screens (i.e., Activities), and protecting these activities is vital for ensuring user privacy. Several studies have demonstrated the risk of private data leakage via screen capture and identified malware exploiting this vulnerability. To mitigate such threats, Goo...
Youngseok Kim, Sung-Ho Lee, Sungjae Hwang· Proceedings of the ACM on So...· 0 citations
Mobile phones have become the primary computing platform for personal and financial data, yet they operate under strict constraints of battery life, memory, and processing power that limit the practicality of conventional cryptographic standards such as AES and RSA. This paper presents a review of the literature on lig...
Nandini Sharma, Dr. Naveen Kumar Singh· International Journal of Res...· 0 citations
Mobile apps frequently embed sensitive secrets, such as API keys, access tokens, client secrets, and private keys that support internal functionality or enable integration with external systems and third-party services. Developers frequently embed these secrets into Android apps, which allows attackers to extract them...
Marco Alecci, Jordan Samhi, Tegawendé F. Bissyandé et al.· Proceedings of the ACM on So...· 0 citations
The rapid evolution of malware variants has increasingly undermined traditional signature‐based detection techniques, which are easily evaded through obfuscation and polymorphism that preserve malicious functionality. This challenge is particularly acute in Internet of Things (IoT) environments, where device heteroge...
Khizar Hayat, S. Hina, Fabiha Hashmat et al.· Security and Privacy· 0 citations
This work provides the first study of such a whole-system defense, especially with respect to a deployed and operational capability, and shows an increase in product abuse coverage, a 30% reduction in monthly alerts, and adaptability to changes in malicious actors'behavior.
Shaefer Drew, Michael Brautbar, Paul Knight et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.