VLDB 2026 Research / reviewers in the wild / expert
Karim O. Elish
dblp:58/5556 · also Karim Elish
· DBLP profile ↗
15ranked-venue papers
5as first author
5since 2021 · last 2026
0000-0001-6060-4090ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 2 first-author · 4 since 2021Security and privacy · 4 · 1 first-authorArtificial intelligence and machine learning · 3Databases, data management, data science and information retrieval · 3 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Automated Reproduction of Android Application Bugs with LLMs: Are We There Yet?
Dennis Carey, Karim O. Elish, Paniz Abedin |
ICST | 2 |
| 2026 | SMELLDroid: A Dataset for Code Smells in Android AppsabstractCode smells are recurring design and implementation issues that degrade software quality and maintainability. While several studies have examined code smells in Android applications, there is a lack of publicly available datasets that systematically capture and quantify them. This paper introduces SMELLDroid, a large-scale dataset designed to support empirical studies on code smells within the Android ecosystem. The dataset comprises code smells extracted from 38,704 Android applications, including 29,201 malware apps and 9,503 benign apps. SMELLDroid encompasses seven code smell types—four object-oriented (BLOB, CC, LM, SAK) and three Android-specific (HAS, HBR, HSS)—with quantitative indicators representing their occurrence across applications. This dataset enables researchers to pursue multiple directions, such as quantifying smell prevalence, analyzing relationships among smell categories, and comparing code quality characteristics between benign and malware apps. Joyce Champie, Karim O. Elish, Mahmoud O. Elish |
MSR | 2 |
| 2026 | AndroMetric: Bridging Multi-Dimensional Software Metrics and Mobile Application Security
Sebastian Siedler, Karim O. Elish |
MSR | 2 |
| 2025 | Stealthy No More: An Effective Ensemble Learning Approach for Detecting Android RATsabstractAndroid Remote Access Trojans (RATs) pose a significant cybersecurity threat due to their stealthy behavior, sophisticated evasion techniques, and ability to grant attackers unauthorized access to compromised devices. Existing detection mechanisms, including signature-based and heuristic approaches, often struggle to effectively identify RATs due to their polymorphic nature and continuous evolution. To address these challenges, we propose an ensemble learning-based detection framework that leverages both static and dynamic analysis techniques to improve detection accuracy. Our evaluation results on a large publicly available Android malware benchmark dataset demonstrate that XGBoost model outperforms other models, achieving an F1-measure of 99.2%, with the lowest false positive rate. Additionally, we evaluate the capability of ensemble models in classifying RATs into specific families, with XGBoost again demonstrating superior classification performance. These findings highlight the effectiveness of ensemble learning in detecting Android RAT threats and offering a scalable and robust solution for enhancing mobile security. Nesreen Dalhy, Karim O. Elish |
SERA | 2 |
| 2022 | Lightweight, Effective Detection and Characterization of Mobile Malware FamiliesabstractAndroid malware is an ongoing threat to billions of smart devices’ security, ranging from mobile phones to car infotainment systems. Despite numerous approaches and previous studies to develop solutions for detecting and preventing Android malware, the rapid continuous development of new malware variants requires a careful reconsideration and the development of effective methods to identify malware families given a meager number of malware instances. In this paper, we present DroidMalVet, a novel Android malware family classification and detection approach that does not require to perform complex program analyses or utilize large feature sets. DroidMalVet is the first to use a promising, diverse, and small set of software metrics as features in a supervised learning platform to classify and detect various Android malware families. Our extensive empirical evaluations on two large public malware datasets show that DroidMalVet accurately detects both small and large malware families with F-Score accuracy of 94.4% and 96%, and AUC equal to 99.5% and 99.7% on the malware families in Drebin and AMD datasets, respectively. Moreover, our results demonstrate the superior performance of DroidMalVet in detecting small families (i.e., families with few samples). DroidMalVet complements existing approaches and presents an early warning tool for detecting known and emerging malware families. Karim O. Elish, Mahmoud O. Elish, Hussain M. J. Almohri |
IEEE Trans. Computers | 1 |
| 2020 | A Client Bootstrapping Protocol for DoS Attack Mitigation on Entry Point Services in the CloudabstractThis paper presents a client bootstrapping protocol for proxy-based moving target defense system for the cloud. The protocol establishes the identity of prospective clients who intend to connect to web services behind obscure proxy servers in a cloud-based network. In client bootstrapping, a set of initial line of defense services receive new client requests, execute an algorithm to assign them to a proxy server, and reply back with the address of the chosen proxy server. The bootstrapping protocol only reveals one proxy address to each client, maintaining the obscurity of the addresses for other proxy servers. Hiding the addresses of proxy servers aims to lower the likelihood that a proxy server becomes the victim of a denial-of-service (DoS) attack. Existing works address this problem by requiring the solution of computationally intensive puzzles from prospective clients. This solution slows the progression of attacks as well as new clients. This paper presents an alternative idea by observing that limited capacity of handling initial network requests is the primary cause of denial-of-service attacks. Thus, the suggested alternative is to utilize cost-effective high-capacity networks to handle client bootstrapping, thus thwarting attacks on the initial line of defense. The prototype implementation of the protocol using Google’s firebase demonstrates the proof of concept for web services that receive network requests from clients on mobile devices. Hussain M. J. Almohri, Mohammad Al-Mutawa, Mahmoud Alawadh, Karim O. Elish |
Secur. Commun. Networks | 4 |
| 2020 | Identifying Mobile Inter-App Communication RisksabstractMalware collusion is a technique utilized by attackers to evade standard detection. It is a new threat where two or more applications, appearing benign, communicate to perform a malicious task. Most proposed approaches aim at detecting stand-alone malicious applications. We point out the need for analyzing data flows across multiple Android apps, a problem referred to as end-to-end flow analysis. In this work, we present a flow analysis for app pairs that computes the risk level associated with their potential communications. Our approach statically analyzes the sensitivity and context of each inter-app flow based on inter-component communication (ICC) between communicating apps, and defines fine-grained security policies for inter-app ICC risk classification. We perform an empirical study on 7,251 apps from the Google Play store to identify the apps that communicate with each other via ICC channels. Our results report four times fewer warnings on our dataset of 197 real app pairs communicating via explicit external ICCs than the state-of-the-art permission-based collusion detection. Karim O. Elish, Haipeng Cai, Daniel Barton, Danfeng Yao, Barbara G. Ryder |
IEEE Trans. Mob. Comput. | 1 |
| 2019 | Identifying Android Malware Families Using Android-Oriented MetricsabstractAndroid malware (malicious apps) families share common attributes and behavior through sharing core malicious code. However, as the number of new malware increases, the task of identifying the correct family becomes more challenging. Two prominent approaches tackle this problem, either using dynamic analysis that captures the runtime behavior of the malware or using static analysis methods that can reveal malicious behavior by analyzing the underlying logic and code patterns. A third emerging way is to use the various sources of identification features to analyze the architectural and external attributes of a malicious app. For example, two malicious apps can have different behavioral patterns but share common attributes. We hypothesize that this malware can belong to the same family but attempt to mislead dynamic and code-level static analysis tools by randomizing their behavior. In this work, we utilize a promising set of Android-oriented code metrics that guide a supervised classification learning process for identifying malware families in Android. Our empirical results on 2,869 malware apps, across 35 different malware families, show that these metrics are very effective to identify malware families. In particular, we achieve low false positive rate (1.2%) and AUC score of 0.984 for family identification by using Random Forest (RF) classifier. William Blanc, Lina G. Hashem, Karim O. Elish, Hussain M. J. Almohri |
IEEE BigData | 3 |
| 2018 | Machine Learning-Based Prediction of Prolonged Length of Stay in NewbornsabstractThe ability to predict prolonged length of hospital stay for newborn children has clinical value as an indicator of newborn health status but also can assist in such health system resource considerations as improved utilization of hospital wards and beds. In this paper, we describe the application of machine learning-based prediction to a Healthcare Cost and Utilization Project dataset and report on the performance of various developed predictive models. Via only utilizing administrative data and minimal clinical data available near to the time of admission/birth, we are able to demonstrate high performing models. The use of HCUP data for building newborn prolonged length of stay models potentially applicable across health care providers is an important contribution, and additionally the models represent high-performing models in the field of published predictive models of newborn length of stay in general. Brandon Thompson, Karim O. Elish, Robert Steele |
ICMLA | 2 |
| 2017 | Prioritized Analysis of Inter-App Communication RisksabstractInter-Component Communication (ICC) enables useful interactions between mobile apps. However, misuse of ICC exposes users to serious threats such as intent hijacking/spoofing and app collusions, allowing malicious apps to access privileged user data via another app. Unfortunately, existing ICC analyses are largely incompetent in both accuracy and scale. This poster points out the need and technical challenges of prioritized analysis of inter-app ICC risks. In this poster, we propose MR-Droid, a MapReduce-based computing framework for accurate and scalable inter-app ICC analysis in Android. MR-Droid extracts data-flow features between multiple communicating apps and the target apps to build a large-scale ICC graph. Our approach is to leverage the ICC graph to provide contexts for inter-app communications to produce precise alerts and prioritize risk assessments. This process requires large app-pair data, which is enabled by our MapReduce-based program analysis. Our initial extensive experiments on 11,996 apps from 24 app categories (13 million pairs) demonstrate the scalability of our approach. Haipeng Cai, Gang Wang 0011, Danfeng Yao, Karim O. Elish, Barbara G. Ryder |
CODASPY | 5 |
| 2015 | Profiling user-trigger dependence for Android malware detectionabstractAs mobile computing becomes an integral part of the modern user experience, malicious applications have infiltrated open marketplaces for mobile platforms. Malware apps stealthily launch operations to retrieve sensitive user or device data or abuse system resources. We describe a highly accurate classification approach for detecting malicious Android apps. Our method statically extracts a data-flow feature on how user inputs trigger sensitive API invocations, a property referred to as the user-trigger dependence. Our evaluation with 1433 malware apps and 2684 free popular apps gives a classification accuracy (2.1% false negative rate and 2.0% false positive rate) that is better than, or at least competitive against, the state-of-the-art. Our method also discovers new malicious apps in the Google Play market that cannot be detected by virus scanning tools. Our thesis in this mobile app classification work is to advocate the approach of benign property enforcement, i.e., extracting unique behavioral properties from benign programs and designing corresponding classification policies. Karim O. Elish, Xiaokui Shu, Danfeng Yao, Barbara G. Ryder, Xuxian Jiang |
Comput. Secur. | 1 |
| 2014 | High Precision Screening for Android Malware with Dimensionality ReductionabstractWe present a new method of classifying previously unseen Android applications as malware or benign. The algorithm starts with a large set of features: the frequencies of all possible n-byte sequences in the application's byte code. Principal components analysis is applied to that frequency matrix in order to reduce it to a low-dimensional representation, which is then fed into any of several classification algorithms. We utilize the implicitly restarted Lanczos bidiagonalization algorithm and exploit the sparsity of the n-gram frequency matrix in order to efficiently compute the low-dimensional representation. When trained upon that low-dimensional representation, several classification algorithms achieve higher accuracy than previous work. Britton Wolfe, Karim O. Elish, Danfeng Yao |
ICMLA | 2 |
| 2014 | Comprehensive Behavior Profiling for Proactive Android Malware Detection
Britton Wolfe, Karim O. Elish, Danfeng Yao |
ISC | 2 |
| 2009 | Investigating the Effect of Refactoring on Software Testing EffortabstractRefactoring, the process of improving the design of existing code by changing its internal structure without affecting its external behavior, tends to improve software quality by improving design, improving readability, and reducing bugs. There are many different refactoring methods, each having a particular purpose and effect. Consequently, the effect of refactorings on software quality attribute may vary. Software testing is an external software quality attributes that takes lots of time and effort to make sure that the software performs as intended. In this paper, we propose a classification of refactoring methods based on their measurable effect on software testing effort. This, in turn, helps the software developers decide which refactoring methods to apply in order to optimize a software system with regard to the testing effort. Karim O. Elish, Mohammad R. Alshayeb |
APSEC | 1 |
| 2008 | Predicting defect-prone software modules using support vector machines
Karim O. Elish, Mahmoud O. Elish |
J. Syst. Softw. | 1 |