Aleksandr Pilgun

dblp:232/3240 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
2since 2021 · last 2025
0000-0002-6789-6046ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
4 papers
Software testing · 76% Program analysis · 24%
Network and information security
2 papers
Web and mobile security · 100%

Topics — the 10 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Software testing › test coverage
code coverage
1.632025
Demo: Reverse Engineering Android Apps with Code Coverage · CCS 2025
Fine-grained Code Coverage Measurement in Automated Black-box Android Testing · ACM Trans. Softw. Eng. Methodol. 2020
An Effective Android Code Coverage Tool · CCS 2018
Web and mobile security › mobile security
android security
1.222025
Demo: Reverse Engineering Android Apps with Code Coverage · CCS 2025
An Effective Android Code Coverage Tool · CCS 2018
Web and mobile security
mobile security
1.222025
Demo: Reverse Engineering Android Apps with Code Coverage · CCS 2025
An Effective Android Code Coverage Tool · CCS 2018
Program analysis
dynamic analysis
1.222025
Demo: Reverse Engineering Android Apps with Code Coverage · CCS 2025
An Effective Android Code Coverage Tool · CCS 2018
Software testing › test coverage
coverage-based testing
0.732025
The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018
Demo: Reverse Engineering Android Apps with Code Coverage · CCS 2025
An Effective Android Code Coverage Tool · CCS 2018
Software testing › mobile application testing
android app testing
0.522020
Fine-grained Code Coverage Measurement in Automated Black-box Android Testing · ACM Trans. Softw. Eng. Methodol. 2020
The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018
Software testing › test generation
automated test generation
0.312018
The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018
Software testing › test coverage
coverage metrics
0.312018
The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018
Software testing › test generation › search-based test generation
evolutionary testing
0.112020
Fine-grained Code Coverage Measurement in Automated Black-box Android Testing · ACM Trans. Softw. Eng. Methodol. 2020
Software testing
mobile application testing
0.112018
The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android · CCS 2018

Methods — techniques the papers use, named apart from their topics

reverse engineering · 1.7instrumentation · 1.1smali bytecode analysis · 0.7dynamic analysis · 0.4coverage metric combination · 0.3automated test design · 0.3
YearPublicationVenuePosition
2025 Demo: Reverse Engineering Android Apps with Code Coverage
abstract
peer reviewed
Aleksandr Pilgun
CCS1
2025 MalLoc: Toward Fine-Grained Android Malicious Payload Localization via LLMs
abstract
The rapid evolution of Android malware poses significant challenges to the maintenance and security of mobile applications (apps). Traditional detection techniques often struggle to keep pace with emerging malware variants that employ advanced tactics such as code obfuscation and dynamic behavior triggering. One major limitation of these approaches is their inability to localize malicious payloads at a fine-grained level, hindering precise understanding of malicious behavior. This gap in understanding makes the design of effective and targeted mitigation strategies difficult, leaving mobile apps vulnerable to continuously evolving threats. To address this gap, we propose MalLoc, a novel approach that leverages the code understanding capabilities of large language models (LLMs) to localize malicious payloads at a fine-grained level within Android malware. Our experimental results demonstrate the feasibility and effectiveness of using LLMs for this task, highlighting the potential of MalLoc to enhance precision and interpretability in malware analysis. This work advances beyond traditional detection and classification by enabling deeper insights into behavior-level malicious logic and opens new directions for research, including dynamic modeling of localized threats and targeted countermeasure development.
Tiezhu Sun, Marco Alecci, Aleksandr Pilgun, Yewei Song, Xunzhu Tang, Jordan Samhi, Tegawendé F. Bissyandé, Jacques Klein
ICSME3
2020 Don't Trust Me, Test Me: 100% Code Coverage for a 3rd-party Android App
abstract
The incompleteness of 3rd-party app testing is an accepted fact in Software Engineering. This issue makes it impossible to verify the app functionality and to confirm its safety to the end-user. To solve this problem, enterprises developed strict policies. A company, willing to use modern apps, may perform an expensive security analysis, rely on trust or forbid the app. These strategies may lead companies to high direct and indirect spending with no guarantee of safety. In this work, we present a novel approach, called Dynamic Binary Shrinking, that allows a user to review app functionality and leave only tested code. The shrunk app produces 100 % instruction coverage on observed behaviors and in this way guarantees the absence of unexplored, and therefore, potentially malicious code. On our running examples, we demonstrate that apps use less than 20 % of the codebase. We developed an approach and the ACVCut tool to shrink Android apps towards the executed code. Repository - http//github.com/pilgun/acvcut [1].
Aleksandr Pilgun
APSEC1
2020 Dissecting Android Cryptocurrency Miners
abstract
Cryptojacking applications pose a serious threat to mobile devices. Due to the extensive computations, they deplete the battery fast and can even damage the device. In this work we make a step towards combating this threat. We collected and manually verified a large dataset of Android mining apps. In this paper, we analyze the gathered miners and identify how they work, what are the most popular libraries and APIs used to facilitate their development, and what static features are typical for this class of applications. Further, we analyzed our dataset using VirusTotal. The majority of our samples is considered malicious by at least one VirusTotal scanner, but 16 apps are not detected by any engine; and at least 5 apks were not seen previously by the service. Mining code could be obfuscated or fetched at runtime, and there are many confusing miner-related apps that actually do not mine. Thus, static features alone are not sufficient for miner detection. We have collected a feature set of dynamic metrics both for miners and unrelated benign apps, and built a machine learning-based tool for dynamic detection. Our BrenntDroid tool is able to detect miners with 95% of accuracy on our dataset.
Stanislav Dashevskyi, Yury Zhauniarovich, Olga Gadyatskaya, Aleksandr Pilgun, Hamza Ouhssain
CODASPY4
2020 Fine-grained Code Coverage Measurement in Automated Black-box Android Testing
abstract
Today, there are millions of third-party Android applications. Some of them are buggy or even malicious. To identify such applications, novel frameworks for automated black-box testing and dynamic analysis are being developed by the Android community. Code coverage is one of the most common metrics for evaluating effectiveness of these frameworks. Furthermore, code coverage is used as a fitness function for guiding evolutionary and fuzzy testing techniques. However, there are no reliable tools for measuring fine-grained code coverage in black-box Android app testing. We present the Android Code coVerage Tool, ACVTool for short, that instruments Android apps and measures code coverage in the black-box setting at class, method and instruction granularity. ACVTool has successfully instrumented 96.9% of apps in our experiments. It introduces a negligible instrumentation time overhead, and its runtime overhead is acceptable for automated testing tools. We demonstrate practical value of ACVTool in a large-scale experiment with Sapienz, a state-of-the-art automated testing tool. Using ACVTool on the same cohort of apps, we have compared different coverage granularities applied by Sapienz in terms of the found amount of crashes. Our results show that none of the applied coverage granularities clearly outperforms others in this aspect.
Aleksandr Pilgun, Olga Gadyatskaya, Yury Zhauniarovich, Stanislav Dashevskyi, Artsiom Kushniarou, Sjouke Mauw
ACM Trans. Softw. Eng. Methodol.1
2018 The Influence of Code Coverage Metrics on Automated Testing Efficiency in Android
abstract
Code coverage is an important metric that is used by automated Android testing and security analysis tools to guide the exploration of applications and to assess efficacy. Yet, there are many different variants of this metric and there is no agreement within the Android community on which are the best to work with. In this paper, we report on our preliminary study using the state-of-the-art automated test design tool Sapienz. Our results suggest a viable hypothesis that combining different granularities of code coverage metrics can be beneficial for achieving better results in automated testing of Android applications.
Stanislav Dashevskyi, Olga Gadyatskaya, Aleksandr Pilgun, Yury Zhauniarovich
CCS3
2018 An Effective Android Code Coverage Tool
abstract
The deluge of Android apps from third-party developers calls for sophisticated security testing and analysis techniques to inspect suspicious apps without accessing their source code. Code coverage is an important metric used in these techniques to evaluate their effectiveness, and even as a fitness function to help achieving better results in evolutionary and fuzzy approaches. Yet, so far there are no reliable tools for measuring fine-grained bytecode coverage of Android apps. In this work we present ACVTool that instruments Android apps and measures the smali code coverage at the level of classes, methods, and instructions. Tool repository: https://github.com/pilgun/acvtool
Aleksandr Pilgun, Olga Gadyatskaya, Stanislav Dashevskyi, Yury Zhauniarovich, Artsiom Kushniarou
CCS1