PADLOCK: A Context-Aware On-Device System for Android Permission-Risk Assessment – A Tanzanian Case Study

Loading...
Thumbnail Image

Date

2026-07-26

Journal Title

Journal ISSN

Volume Title

Publisher

Asosiasi Doktor Sistem Informasi Indonesia

Abstract

Android applications often request sensitive permissions beyond their functional needs, creating privacy and security risks, especially in financial and digital lending apps. Existing Android permission mechanisms provide limited visibility into how permissions are used at runtime. This study proposes PADLOCK, a context-aware prototype for event-driven permission monitoring and contextual risk assessment. The methodology combined a survey-based user study (n = 600), analysis of 3,816 applications, machine learning development, and Android prototype implementation. A compact deep neural network, ShieldAI, was trained on permission-based features with heuristic risk labels to classify applications as benign or potentially higher-risk. The model was integrated into PADLOCK to support on-device monitoring and user-guided permission decisions. On a held-out test set, ShieldAI achieved 96.73% accuracy, 94.82% precision, and 92.42% recall. Controlled on-device testing showed an inference latency of approximately 2–3 ms per prediction and indicated reduced higher-risk permission-granting behaviour in PADLOCK-assisted evaluations. This study contributes an integrated Android prototype combining contextual permission analysis, machine-learning-based risk assessment, and event-driven monitoring. However, the findings remain limited to the evaluated dataset and controlled conditions, and broader real-world validation is required.

Sustainable Development Goals

SDG 16: Peace, Justice and Strong Institutions

Keywords

Android security, permission-risk assessment, machine learning, on-device inference, mobile privacy, financial applications

Citation