On-device detection of abusive applications

The computing device detects abusive applications by monitoring changes in visual representations using an abuse detection module, effectively identifying and warning users about deceptive applications that change their appearance to evade detection.

WO2026095920A1PCT designated stage Publication Date: 2026-05-07GOOGLE LLC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
GOOGLE LLC
Filing Date
2024-10-29
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Abusive applications deceive users by changing their behavior to evade detection and harm users through nuisance promotions, data theft, and resource consumption, employing cloaking techniques to circumvent remedial measures.

Method used

A computing device monitors applications for changes in visual representations, such as icons and names, using an abuse detection module to detect abusive applications by comparing expected and actual visual representations, generating scores based on heuristics and machine learning models to identify deceptive changes.

Benefits of technology

Effectively detects abusive applications on-device by identifying changes in visual representations, providing proactive warnings to users, thereby preventing harm and resource misuse.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2024053421_07052026_PF_FP_ABST
    Figure US2024053421_07052026_PF_FP_ABST
Patent Text Reader

Abstract

In one example, a computing system comprises a memory that stores instructions, and one or more processors that executes the instructions to: determine, based on usage information of an application, a first visual representation of the application from a plurality of visual representations provided by the application, wherein user input corresponding to selection of the first visual representation causes a function associated with the application to be executed; determine, based on the usage information, a second visual representation of the application from the plurality of visual representations, wherein the second, visual representation replaces the first visual representation and is different in appearance than the first visual representation; determine whether the second visual representation is at least substantially blank; and. responsive to determining the second visual representation is at least substantially blank, present, to a user, an indication that the application is abusive.
Need to check novelty before this filing date? Find Prior Art

Description

ON-DEVICE DETECTION OF ABUSIVE APPLICATIONSBACKGROUND

[0001] Applications provide a variety of functions that users rely upon or enjoy.Unfortunately, bad actors deploy abusive applications which may deceive or otherwise harm users.SU2424ARY

[0002] In general, various aspects of the techniques described in this disclosure are directed to on-device detection of abusive applications. Abusive applications may cause harm to users by presenting nuisance promotions (e.g., advertisements), stealing user information (e.g., personal information, location information, health information, financial information, usernames and passwords, and other private information), presenting deceptive, nuisance, or other abusive notifications, consuming computing device resources (e.g., processing / memory resources), among other things. Abusive applications may utilize deceptive techniques to circumvent remedial measures intended to detect and disable abusive applications. For example, abusive applications may apply cloaking techniques to change their behavior once installed to users’ devices.

[0003] In accordance with the techniques disclosed herein, a computing device may detect abusive applications by, for example observing an application’s behavior over time. In this manner, the computing device may detect when an application changes, such as the application’s visual representation (e.g., application icon, application name). Based on the change, the computing device may determine the application is abusive and proactively warn the computing device’s user.

[0004] In one example, various aspects of the techniques are directed to a method comprising: determining, by a. computing device and based on usage information of an application installed on the computing device, a first visual representation of the application from a plurality of visual representations provided by the application, wherein user input corresponding to selection of the first visual representation causes a function associated with the application to be executed; determining, by the computing device and based on the usage information from the application, a second visual representation of the application from theplurality of visual representations, wherein the second visual representation replaces the first visual representation and is different in appearance than the first visual representation; determining, by the computing device, whether the second visual representation is at least substantially blank; and responsive to determining the second visual representation is at least substantially blank, presenting, by the computing device and to a user, an indication that the application is abusive.

[0005] In another example, various aspects of the techniques are directed to a computing system comprising: a memory that stores instructions, and one or more processors that execute the instructions to: determine, based on usage information of an application installed on the computing device, a first visual representation of the application from a plurality of visual representations provided by the application, wherein user input corresponding to selection of the first visual representation causes a function associated with the application to be executed; determine, based on the usage information from the application, a second visual representation of the application from the plurality of visual representations, wherein the second visual representation replaces the first visual representation and is different in appearance than the first visual representation; determine whether the second visual representation being at least substantially blank; and responsive to determining the second visual representation is at least substantially blank, present, to a user, an indication that the application is abusive.

[0006] In another example, various aspects of the techniques are directed to non-transitory computer-readable storage media including instructions that, when executed by one or more processors, cause the one or more processors to: determine, based on usage information of an application installed on the computing device, a first visual representa tion of the application from a plurality of visual representations provided by the application, wherein user input corresponding to selection of the first visual representation causes a function associated with the application to be executed; determine, based on the usage information from the application, a second visual representation of the application from the plurality of visual representations, wherein the second visual representation replaces the first visual representation and is different in appearance than the first visual representation; determine whether the second visual representation is at least substantially blank; and responsive todetermining the second visual representation is at least substantially blank, present, to a user, an indication that the application is abusive.

[0007] The details of one or more examples are set forth in the accompanying drawings and the description below. Other features, objects, and advantages will be apparent from the description and drawings, and from the claims.BRIEF DESCRIPTION OF DRAWINGS

[0008] FIG. 1 is a conceptual diagram illustrating an example environment for on-device detection of abusive applications, in accordance with one or more aspects of the present disclosure.

[0009] FIG. 2 is a block diagram illustrating an example environment for on-device detection of abusive applications, in accordance with one or more aspects of the present disclosure.

[0010] FIGS. 3A-3C are block diagrams illustrating behavior of first examples of abusive applications, in accordance with one or more aspects of the present disclosure.

[0011] FIG 4 is a flowchart illustrating a first example process for on -device detection of abusive applications, in accordance with one or more aspects of the present disclosure.

[0012] FIGS. 5A-5C are block diagrams illustrating behavior of second examples of abusive applications, in accordance with one or more aspects of the present disclosure.

[0013] FIG 6 is a flowchart illustrating a second example process for on-device detection of abusive applications, in accordance with one or more aspects of the present disclosure.DETAILED DESCRIPTION

[0014] FIG. 1 is a conceptual diagram illustrating an example environment for on-device detection of abusive applications, in accordance with one or more aspects of the present disclosure. As can be seen from the example of FIG. 1, environment 100 may include one or more computing devices 120A--120N (collectively, “computing devices 120”) that may communicate with computing system 110 over network 102. In some examples, computing devices 120 and computing system 110 may be peer devices that operate in a client / server fashion. For instance, computing devices 120 may be clients that are used to access services, such as application repository services (e.g., application search services, application store services, application upload and / or download services) provided by an application repositoryJwith application repository 112.

[0025] Computing device 120 may be an example of a smartphone, mobile phone, a tablet computer, a laptop computer, a desktop computer, a wearable device, a gaining system, a media player, an e-book reader, camera device, or a wearable computing device (e.g., a computerized watch, computerized eyewear, etc.), or other computing device. FIG. 1 illustrates a particular example of computing device 120, and many other examples of computing device 120 may be used in other instances and may include a subset of the components included in example computing device 120 or may include additional components not shown in FIG. 1.

[0016] Computing device 120 may include an operating system that provides an execution environment for one or more applications 125A-125N (collectively, “applications 125”). Examples of applications 125 include social networking applications, utility applications, productivity applications, entertainment applications, creativity applications, communication applications, shopping applications, games, and other software applications. In some examples, applications 125 may be downloaded from application repository' 112. For instance, application repository' 112 may host a plurality of application packages 114A-114N (collectively, “application packages 114”). Each application package 114 may include a respective one of applications 125. As such, to install application 125A, computing device 120 may download application package 114A that includes application 125 A and install application 125A using application package 114A, such as by extracting application 125 A from application package 114A.

[0017] Computing device 120 may provide a user interface 123, such as through the operating system of computing device 120. User interface 123 may present various applications 125 to a user, for example, to allow the user to execute application functionality (e.g., actions or other functions provided by applications 125). As can be seen in FIG. 1, user interface 123 may present one or more visual representations 127A-127N (collectively, “visual representations 127”) for each of applications 125. Visual representations 127 may include various graphical (e.g., visible) elements that identify or otherwise correspond to application 125 A. For example, visual representations 127 may include respective application icons 126A-126N (collectively, “application icons 126”), application names128A-128N (collectively, “application names 128”), or both for each of applications 125. User interface 123 may represent a mobile device application launcher in some examples.

[0018] As shown in the example of FIG. 1, user interface 123 may present visual representation 127A that includes application icon 126A and / or application name 128 A and corresponds to application 125 A, visual representation 127B that includes application icon 126B and / or application name 128B and corresponds to application 125B, visual representation 127C that includes application icon 126C and / or application name 128C and corresponds to application 125C, and so on and so forth. Visual representation 127 may represent a user interface element that a user may interact with, such as to execute (e.g., run) corresponding application 125. For example, user interface 123 may receive user input (e.g., touch input) corresponding to the selection of visual representation 127 A and, in response, computing device 120 may execute a function of application 125 A.

[0029] Computing device 120 may receive user input (e.g., touch input) for and present output of user interface 123, applications 125, or both through one or more user interface devices 124 of computing device 120. User interface device 124 of computing device 120 may be hardware that functions as an input and / or output device for computing device 1 0. For example, user interface device 1 4 may include a display component (e.g., liquid crystal display (LCD), organic light-emitting diode (OLED) display), which may be a screen at which information is displayed by user interface device 124 and a presence-sensitive input device that may detect an object at and / or near the display component. The presencesensitive input device may, for example, detect a user’s touch or other input. User interface device 124 may provide tactile, audio, and video output. User interface device 124, m some examples, includes one or more of a presence-sensitive display, speaker, liquid crystal display (LCD), organic light-emitting diode (OLED) display, haptic motors, linear actuating devices, or any other type of device for receiving input or generating output to a human or machine.

[0020] Each of applications 125 may include a plurality of visual representations 127, which may be provided with applications 125, such as by the respective developers of applications 125. For example, application 125A, in addition to visual representation 127A including application icon 126A and application name 128A, may include at least one other visual representation 12724 with application icon 12624, application name 12824, or both.

[0021] Each of applications 125 may include or be provided with usage information including parameters that computing device 120 may use (e.g., read) to determine when a particular visual representation of visual representations 127 should be used. For example, user interface 123 may read the usage information of application 125A and change visual representations 127 (e.g., replace visual representation 127A with visual representation 12724) based on the usage information. In this manner, application 125 A may be represented by different visual representations 127 on computing device 120 over time.

[0022] For example, user interface 123 may present application 125A with a first visual representation 127A (e.g., application icon 126A and / or application name 128A) upon installation of application 125A to computing device 120. The usage information of application 125 A may indicate when another visual representation of application 125 A, such as visual representation 12724, should be used instead of a previous visual representation, such as visual representation 127 A. For example, the usage information may include parameters indicating that visual representation 12724 should supersede (e.g., replace) visual representation 127 A during at a predefined time (e.g., first week of the year, weekends, evenings). The predefined time may be a predefined or random amount of time after application 125 A is installed (e.g., 2 days, 5 days). Second visual representation 12724 may include application icon 12624 that is different from application icon 126A, application name 12824that is different from application name 128A, or both.

[0023] The usage information may include various parameters. For example, in addition to or instead of time-based parameters (e.g., the predefined time described above) the usage information may indicate visual representation 12724 should replace visual representation 127A based on the execution environment in which application 125 A executes. In this manner, application 125 A may, based on the usage information, use visual representation 12724 when application 125 A executes in an execution environment provided by computing device 120 (e.g., on a user device, such as computing device 120). As such, when application 125 A executes in a different execution environment, such as a testing or virtual execution environment which may be used for testing and review purposes, for example, by a service provider of application repository 112 (e.g., application store provider), application 125 A may use visual representation 127A.

[0024] . Applications 125 may include different visual representations 127 for various reasons. For example, application 125A may include different visual representations 127 to highlight a holiday or other time-sensitive promotion as compared to non-promotional period, trial periods as opposed to non-trial periods, or other time-sensitive events, or to indicate specifically enabled functionality (e.g., paid versus unpaid software features). In some examples, application 125 A may change visual representations 127 in response to user input, such as in response to user input selecting a particular visual representation 127 (e.g., the user’s preferred visual representation 127) to represent application 125 in user interface 123.

[0025] Abusive applications may utilize deceptive techniques to circumvent remedial measures intended to detect and disable abusive applications. For example, applications 125 may include usage information that changes visual representations 127 to evade remedial measures (e.g., detection, disablement) for addressing abusive applications. For instance, application 125 A may include usage information that changes visual representations 127 based on whether the application is executing in the testing or review execution environment, such as described above. In this manner, application 125 A may present an expected visual representation 127 to appear genuine to reviewers (e.g., application store service providers), but present a deceptive visual representation 127 to users, such as when application 125A executes in the execution environment of computing device 120. The deceptive visual representation 127 may be a visual representation that is difficult to observe (e.g., hidden). For example, the deceptive visual representation 127 may be blank as described below.

[0026] In some examples, abusive applications may perform a corresponding change to appearance, behavior (e.g., functionality), or both in connection with a change in visual representation 127. For instance, an abusive application may change in appearance and / or behavior from a utility application (e.g., calculator) to another type of application (e.g., banking application). The abusive application may change visual representations to a visual representation 127 that is blank to avoid remedial measures. In this manner, the abusive application attempts to masquerade as another type of application for the purpose of harming the user.

[0027] Computing device 120 may invoke abuse detection module 122 to perform on-device detection of abusive applications. Abuse detection module 122 may monitor the behavior ofapplications 125 on device to detect abusive applications. 24any techniques employed by abusive applications can be very effective in bypassing application analysis as well as human check. For example, an abusive application may employ cloaking techniques whereby the abusive application presents a different application experience (in a detection or testing environment) that what a real world user would experience when the user uses the application on computing device 120. For instance, an application may present itself as a poker game using game currency in a testing environment and, when installed to computing device 120, become a real poker game that accepts real money wagers. As yet another example, an abusive application may gain a different appearance and / or behaviors after installation, such as after a time delay or after an initial user interaction. As yet another example, an abusive application may obfuscate application code, such as to prevent detection by malware analysis.

[0028] Abuse detection module 122 may monitor applications 125 to detect changes to visual representations 127 that indicate one or more of applications 125 may be abusive applications. Though described herein as monitoring applications 125 to detect changes to visual representations 127, abuse detection module 122 may generally observe application / computing device 120 behavior over time to detect when application 125 changes in appearance (e.g., visual representation 127) or performs other behavioral change(s). For instance, abuse detection module 122 may monitor applications 125 to detect changes to visual representations 127 that result in visual representations 127 that are blank (e.g., invisible, hidden, empty, obfuscated, intentionally inconspicuous). Some examples of blank visual representations include visual representations 127 with transparent or empty application icons 126 and / or application names 128, application icons 126 of one color (e.g., entirely black, entirely white, entirely gray) or substantially one color (e.g., shade of gray commonly used as a wallpaper background a system theme) and application names 128 with invisible or substantially invisible characters (e.g., entirely spaces, Unicode or other characters having few, if any, visible pixels).

[0029] Computing device 120 may provide abuse detection module 122 with access to application information for applications 125 similar to that accessed by an application launcher of user interface 123 or the like. In this manner, abuse detection module 122 may access application information such as visual representations 127 and usage information ofapplications 125. Abuse detection module 122 may use such application information to monitor how applications 125 change visual representations 127. For example, abuse detection module 122 may read the usage information for application 125A to determine whether application 125A will change visual representations 127 and which of visual representations 127 application 125A will use subsequent to the change. For instance, abuse detection module 122 may read the usage information to determine application 125A will change from using visual representation 127A to using visual representation 12724.

[0030] Abuse detection module 122 may store previously used visual representations 127 for applications 125, such as to a storage device of computing device 120. Abuse detection module 122 may compare, for applications 125, respective previous visual representations to replacement visual representations to determine whether individual applications 125 have changed visual representations 127. For example, abuse detection module 122 may store the installed visual representation (e.g., visual representation 127A) corresponding to a visual representation used by application 125 A upon installation. When application 125A changes visual representations 127, such as to visual representation 12724, abuse detection module 122 may detect the change by comparing visual representation 12724 (e.g., the replacement visual representation) to visual representation 127A (e.g., the previous visual representation) to determine one or more differences, if any, between visual representation 12724 and visual representation 127 A. For example, abuse detection module 122 may determine that the visual representation 127 of application 125 A has changed, when visual representation 12724 and visual representation 127 A include different application icons 126 and / or different application names 128).

[0031] In some examples, abuse detection module 122 may obtain and store the previous visual representation (e.g., visual representation 127A) from application repository 112. As such, the previous visual representation may be the visual representation application 125A uses during testing or review', such as during a review process conducted by service provider of application repository 112. In this manner, if application 125 A includes usage information that causes application 125A to have a different visual application when installed to computing device 120 as compared to the visual application used during review' or testing, abuse detection module 122 may still detect a change to visual representations 127.

[0032] . Abuse detection module 122 may generate one or more scores based on visual representations 127 to determine whether one or more of applications 125 are abusive applications. In some examples, a score may correspond, such as in magnitude, to the likelihood or confidence level that visual representation 127 is blank. An application that changes visual representations 127 to use a blank visual representation 127 may correspond to an abusive application.

[0033] Abuse detection module 122 may combine one or more scores (e.g., sum, average, mean, or other combination of the one or more scores) to generate a combined score. Abuse detection module 122 may determine application 125A is an abusive application when a score (e.g., the combined score) for visual representation 127 of application 125A, satisfies a predefined threshold score. For example, abuse detection module 122 may determine application 125 A is an abusive application when a score for visual representation 12724 is above the threshold score. Accordingly, abuse detection module 122 may determine application 125 is not an abusive application when a score does not satisfy the threshold score (e.g., is not above the threshold score). In some examples, abuse detection module 122 may obtain (e.g., retrieve) and update, from time to time, the threshold score, instructions for generating one or more scores, or both from a remote source, such as application repository 112 of computing system 110.

[0034] When abuse detection module 122 determines application 125 A is an abusive application, abuse detection module 122 may output a warning to a user indicating application 125 A is at least potentially abusive (e.g., is an abusive application). For example, abuse detection module 122 may present notification 129 including a warning that application 125 A is at least potentially abusive. Abuse detection module 122 may generate such a warning for presentation to the user, such as through user interface device 124. User interface device 124 may accordingly display the warning.

[0035] . Abuse detection module 122 may generate one or more scores based on one or more characteristics of visual representation 12724. For example, abuse detection module 122 may generate one or more scores for application icon 12624 of visual representation 12724, one or more scores for application name 12824 of visual representation 12724, or both. For instance, abuse detection module 122 may generate a score indicating whether application icon 12624 has changed relative to application icon 126 A, a score indicating whetherapplication name 12824 has changed relative to application name 128 A, a score indicating whether application icon 12624 is blank, and a score indicating whether application name 12824 is blank, or various subsets thereof.

[0036] Abuse detection module 122 may generate scores in numerical form. As such, abuse detection module 122 may use higher scores to indicate a higher correspondence to a particular state (e.g., application icon 12624 and / or application name 12824 being changed or blank) and lower scores to indicate a lower correspondence to the particular state, or vice versa. Abuse detection module 122 may combine scores to generate the combined score using one or more heuristics. For example, abuse detection module 122 may generate the combined score by applying (e.g., executing) heuristics that cause abuse detection module 122 to sum, average, and find the mean or median of the one or more scores, or various subsets thereof. In some examples, the heuristics may cause abuse detection module 122 to generate the combined score by performing a Bayesian inference using the one or more scores as input.

[0037] With respect to application icons 126, abuse detection module 122 may generate one or more scores indicating a likelihood or confidence level (e.g., percentage chance) that application icon 12624 is blank. To generate one or more of such scores, abuse detection module 122 may generate an overflow-based hash of application icon 12624 and compare the hash to stored hashes (e.g,, previously generated hashes) for one or more blank application icons. For instance, abuse detection module 122 may include stored hashes for blank application icons, such as overflow-based hashes of application icons of one color (e.g., entirely black, entirely white, entirely gray) or substantially one color or application icons that are transparent. Abuse detection module 122 may generate the score based on how closely the hash of application icon 12624 matches a stored hash. For example, abuse detection module 122 may compare the hash of application icon 12624 to one or more stored hashes. If the hash of application icon 12624 is substantially similar to one of the stored hashes (e.g., within a predetermined range or distance to one of the stored hashes), abuse detection module 122 may generate a high score for application icon 12624 (e.g., 8 out of 10). If the hash of application icon 12624 matches (e.g., is identical) to one of the stored hashes, abuse detection module 122 may generate a maximum score (e.g., 10 out of 10) for application icon 12624. If the hash of application icon 12624 does not match or is notsubstantially similar to one of the stored hashes, abuse detection module 122 may generate a relatively lower score for application icon 12624 (e.g., 3 out of 10).

[0038] Abuse detection module 122 may account for alpha channel information (e.g., transparency) when generating the hash of application icon 12624. For example, abuse detection module 122 may generate the same hash for application icons 126 with alpha channel information indicating application icons 126 are transparent, regardless of their color. To illustrate, abuse detection module 122 may generate the same hash for application icons 126 with RGBA (e.g., red, green, blue, and alpha channel information) values of (0, 0, 0, 0) and (255, 255, 255, 0), respectively, because the alpha channel information of 0 indicates the application icons 126 are entirely transparent. Though described in the foregoing as entirely transparent (e.g., 100% transparent), abuse detection module 122 may, in some examples, generate the same hash for application icons when the alpha channel information satisfies a transparency threshold (e.g., 80% transparent, 90% transparent).

[0039] With respect to application names 128, abuse detection module 122 may generate one or more scores indicating a likelihood or confidence level (e.g., percentage chance) application name 12824 is blank. Abuse detection module 122 may apply a trimming technique to remove invisible characters (e.g., Unicode or other whitespace characters) from application names 128. Abuse detection module 122 may generate a hash, such as an overflow-based hash, with application names 128 after application names 128 have been trimmed (e.g., application names 128 without invisible characters).

[0040] Abuse detection module 122 may generate a score based on how closely the hash matches one or more stored hashes for application names 128. For example, abuse detection module 122 may compare the hash of application name 12824 to one or more stored hashes. Abuse detection module 122 may include stored hashes for blank application names, such as overflow-based hashes of application names that are blank (e.g., include no non- whitespace characters, invisible or substantially invisible characters, or both). If the hash of application name 12824 is substantially similar to one of the stored hashes (e.g., within a predetermined range or distance to one of the stored hashes ), abuse detection module 122 may generate a high score for application name 12824 (e.g., 8 out of 10). If the hash of application name 12824 matches (e.g., is identical) to one of the stored hashes, abuse detection module 122 may generate a maximum score (e.g., 10 out of 10) for application name 12824. If the hashof application name 12824 does not match or is not substantially similar to one of the stored hashes, abuse detection module 122 may generate a relatively lower score for application name 12824 (e.g., 3 out of 10).

[0041] Abuse detection module 122 may monitor applications 125 for changes to visual representations 127. For example, abuse detection module 122 may periodically (e.g., once per day, once per hour) determine whether applications 125 have changed visual representations 127 at user interface 123. As another example, abuse detection module 122 may read usage information for application 125 A to determine if application 125 A changed visual representations 127. For instance, abuse detection module 122 may determine application 125A will replace visual representation 127A with visual representation 12724 based on the usage information. Abuse detection module 122 may compare visual representation 12724 to the previously used visual representation, in this case visual representation 127A, to determine whether visual representation for application 125 A has changed.

[0042] Abuse detection module 122 may determine visual representation 127 for application 125 has changed based on a comparison between prior visual representation and replacement visual representation of application 125. For example, abuse detection module 122 may perform a comparison of the binary data that constitutes visual representation 12724 and visual representation 127 A. Abuse detection module 122 may determine visual representation 12724 and visual representation 127 A are different if the respective binary data of visual representation 12724 and visual representation 127 A do not match (e.g., are not identical). As another example, abuse detection module 122 may generate a hash, such as an overflow-based hash, for each of visual representation 12724 and visual representation 127A. Abuse detection module 122 may compare the hashes for each of visual representation 12724 and visual representation 127A and determine visual representation 12724 and visual representation 127 A are different when the respective hashes do not match.

[0043] In some examples, rather than periodically monitoring (e.g., periodically determining whether visual representations 127 for each of applications 125 have changed) each of applications 125 installed on computing device 120, which may cause high system resource consumption at computing device 120, abuse detection module 122 may randomly select one or more subsets of applications 125 to monitor. For example, abuse detection module 122may monitor a first subset of applications 125 at time tO, a second subset of applications 125 at time tl, a third subset of application 125 at time t2, and so on and so forth. Abuse detection module 122 may avoid selecting overlapping random subsets of applications 125, such as by storing a record of previously monitored applications 125 within a particular period of time (e.g., one day, one week) to avoid over monitoring (e.g., avoid excess resource consumption) or failing to monitor one or more of applications 125.

[0044] In some examples, abuse detection module 122 may determine whether visual representations 127 currently used by applications 125 are likely to be blank without first determining applications 125 have changed visual representations. In this manner, abuse detection module 122 may determine whether one or more of applications 125 are abusive independent of changes, if any, to visual representations of these applications. For example, application 125 A may use an expected visual representation during review / testing, such as by detecting the execution environment, and use a blank visual representation when installed to computing device 120. By monitoring currently used visual representations 127, abuse detection module 122 may detect abuse applications that attempt to evade review processes by presenting a different visual representation during review / testing,

[0045] Computing system 110 may be any suitable computing system, such as one or more desktop computers, laptop computers, mainframes, servers, cloud computing systems, virtual machines, etc. capable of sending and receiving information via network 102, In some examples, computing system 110 may represent a cloud computing system that provides one or more services via network 102. That is, in some examples, computing system 110 may be a distributed computing system. One or more computing devices, such as computing devices 120, may access the services provided by the cloud by communicating with computing system 110. FIG. 1 illustrates only one particular example of computing system 110, and many other examples of computing system 110 may be used in other instances and may include a subset of the components included in example computing system 110 or may include additional components not shown in FIG. 1.

[0046] Computing system 110 may include application repository 112 that computing system 110 may invoke to provide application repository services. For example, application repository 112 may publish applications packages 114 including corresponding applications 125 developed by application developers. In this manner, computing devices 120 maydownload applications packages 114 from application repository 112 and install applications 125 corresponding to the downloaded application packages to computing devices 120. In some examples, application repository 112 may process payment information and / or authorizations from computing devices 120, such as to allow purchase prior to download and installation of paid applications 125 or paid features of applications 125. Application repository 112 may represent an application store, web server, or other repository where applications 125, application packages 114, or both may be downloaded by computing devices 120, such as for installation purposes at computing device 120.

[0047] Application repository’ 112 may receive application packages 114 from various sources. For example, application repository’ 112 may receive application packages 114 uploaded by application developers. For instance, application repository 112 may receive application package 114A including application 125 A from a first application developer and may receive application package 114N including application 125N from an nth application developer. Application repository 112 may receive a variety’ of developer provided application information 142 including application information, such as usage information, and visual representations 127, In some examples, the application information may be encoded or embedded within applications 125, application packages 114, or both. For example, visual representations 127 and / or usage information for application 125A may be encoded or embedded within application 125A and / or application package 114A, where application package 114A is the application package that includes application 125A.

[0048] As described above, abusive applications may employ cloaking techniques, change behaviors, or obfuscation techniques. For example, an abusive application may employ cloaking techniques whereby the abusive application presents a different application experience (in a detection or testing environment) that what a real world user would experience when the user uses the application on computing device 120., As another example, an abusive application may gam a different appearance and / or behaviors after installation, such as after a time delay or after an initial user interaction. As yet another example, an abusive application may obfuscate application code, such as to prevent detection by malware analysis.

[0049] Some abusive applications may obfuscate their code to circumvent malware detection techniques. Without foreknowledge of the techniques being employed, the intendedfunctionality of an application may be difficult or impossible to unveil. These issues may be exacerbated, in large scale environments (e.g., popular application stores), which host applications at scale (e.g., hundreds of thousands or millions of applications), by the sheer volume of applications.

[0050] By monitoring changes in visual representations 127, abuse detection module 122 may detect a variety of abusive applications regardless of the detection avoidance techniques being employ ed. By performing such monitoring on-device, abuse detection module 122 may detect abusive applications that change their behavior to an abusive behavior at unpredictable times. Because abuse detection module 122 executes on device, abuse detection module 122 may detect changes to visual representations 127 as they occur on computing device 120 and proactively warn the user when abuse detection module 122 determines the changes indicate a correspondence with an abusive application.

[0051] FIG. 2 is a block diagram illustrating an example environment for on-device detection of abusive applications, in accordance with one or more aspects of the present disclosure. As can be seen from the example of FIG, 2, environment 200 may include a computing device 220 that may communicate with a computing system 210 over network 202. Computing device 220, computing system 210, and network 202 of FIG, 2 are respectively described below as an example of computing devices 120, computing system 110, and network 102 as illustrated in FIG. 1.

[0052] Computing device 220 may be an example of a mobile phone, a tablet computer, a laptop computer, a wearable device, a gaming system, a media player, an e-book reader, or any other type of computing device that may execute applications 225A-225N (collectively, “applications 225”). FIG. 2 illustrates a particular example of computing device 220, and many other examples of computing devices 220 may be used in other instances and may include a subset of the components included in example computing device 220 or may include additional components not shown in FIG. 2.[00531 Computing device 220 includes one or more processors 232, one or more input devices 234, one or more output devices 236, one or more user interface devices 224, one or more communication units 238, and one or more storage devices 240. One or more storage devices 240 of computing device 220 may include abuse detection module 222, winch may be an example of abuse detection module 122 of FIG. 1, and data store 248.

[0054] In some examples, abuse detection module 222 may be stored in and / or execute within an isolated confidential execution environment 242 for security purposes, privacy purposes, or both, such as ANDROID® Private Compute Core. Confidential execution environment 242 may provide limited interprocess communications (IPC) and execute abuse detection module 222 using processes isolated from other elements of the operating system. In some examples, confidential execution environment 242 may be implemented or executed with a secure core comprising isolated processing circuitry of processor 232.

[0055] Data store 248 may store various data, such as in a structured or unstructured format. For example, data store 248 may be a database or a file folder for storing various data. For instance, data store 248 may store one or more applications 225, one or more visual representations 227A-22724 (collectively, “visual representations 227”), one or more units of usage information 243 or various subsets thereof. As can be seen from the example of FIG.2, visual representations 227 and usage information 243 for application 225 may be included in respective applications 225 in some examples. Applications 225, visual representations 227, and usage information of FIG. 2 may respectively be examples of applications 125, visual representations 227, and the usage information described with respect to FIG. 1.

[0056] Communication channels 233 may interconnect each of the components 232, 234, 236, 238, 224, and 240 for inter-component communications (physically, communicatively, and / or operatively). In some examples, communication channels 233 may include a system bus, a network connection, an inter- process communication data structure, or any other method for communicating data.

[0057] One or more input devices 234 of computing device 220 may receive input.Examples of input are tactile, audio, and video input. Input devices 234 of computing device 220, in one example, includes a presence-sensitive display, touch-sensitive screen, mouse, keyboard, voice responsive system, video camera, microphone or any other type of device for detecting input from a human or machine.

[0058] One or more output devices 236 of computing device 220 may generate output.Examples of output are tactile, audio, and video output. Output devices 236 of computing device 220, in one example, includes a presence-sensitive display, sound card, video graphics adapter card, speaker, liquid crystal display (LCD), organic light-emitting diode (OLED)display, a light field display, haptic motors, linear actuating devices, or any other type of device for generating output to a human or machine.

[0059] One or more communication units 238 of computing device 220 may communicate with external devices by transmitting and / or receiving communication signals, such as via one or more wired or wireless connections. Examples of one or more communication units 238 include a network interface card (e.g., Ethernet, WI-FI®), an optical transceiver, a radio frequency transceiver, a global positioning system (GPS) receiver, or any other type of device that can wirelessly send and / or receive information. Other examples of one or more communication units 238 may include short wave radios, cellular data radios, wireless network radios, as well as universal serial bus (USB) controllers. Though described above with respect to particular communication units, computing device 220 may include any other type of communication device that can send and / or receive information over a wired or wireless connection.

[0060] User interface device 224 of computing device 220 may be hardware that functions as an input and / or output device for computing device 220. For example, user interface device 224 may include a display component, which may be a screen at which information is displayed by user interface device 224 and a presence-sensitive input device that may detect an object at and / or near the display component. User interface device 224 of FIG. 2 may be an example of user interface device 124 as illustrated in FIG. 1. For example, user interface device 224 may present applications 225, user interface 123 of FIG. 1, or both and receive user input, (e.g., touch gestures) for applications 225, user interface 123, or both.

[0061] One or more processors 232 may implement functionality and / or execute instructions within computing device 220. For example, one or more processors 232 on computing device 220 may receive and execute instructions stored by one or more storage devices 240 that, execute the functionality of abuse detection module 222. The instructions executed by one or more processors 232 may cause computing device 220 to store information within one or more storage devices 240 during program execution. Examples of one or more processors 232 include application processors, display controllers, sensor hubs, and any other hardware configured to function as a processing unit. One or more processors 232 may execute instructions of abuse detection module 222 and applications 225 to perform actions or functions corresponding to abuse detection module 222 and applications 225, respectively.

[0062] One or more storage devices 240 within computing device 220 may store information for processing during operation of computing device 220. For example, storage device 240 may store data accessed by abuse detection module 222 during execution at computing device 220, including heuristics 244, one or more machine learning (24L) models 246, applications 225, visual representations 227, usage information 243, and other data, or various subsets thereof. In some examples, storage device 240 is a temporary memory, meaning that a primary purpose of storage device 240 is not long-term storage. One or more storage devices 240 on computing device 220 may be configured for short-term storage of information as volatile memory and therefore not retain stored contents if powered off.Examples of volatile memories include random access memories (RA24), dynamic random access memories (DRA24), static random access memories (SRA24), and other forms of volatile memories known in the art.

[0063] One or more storage devices 240, in some examples, also include one or more computer-readable storage media. One or more storage devices 240 may be configured to store larger amounts of information than volatile memory. One or more storage devices 240 may further be configured for long-term storage of information as non-volatile memory space and retain information after power on / off cycles. Examples of non-volatile memories include magnetic hard discs, optical discs, flash memories, or forms of electrically programmable memories (EPRO24) or electrically erasable and programmable (EEPRO24) memories. One or more storage devices 240 may store program instructions and / or information (e.g,, data) associated with abuse detection module 222,

[0064] In some examples, one or more storage devices 240 may store an operating system. Computing device 220 and / or the operating system may provide an execution environment for abuse detection module 222 and applications 225. In some examples, abuse detection module 222 may communicate with data store 248 to request and receive applications 225 and / or application information corresponding respectively to each application of applications 225. For example, abuse detection module 222 may communicate with data store 248 to request and receive application information such as visual representations 227 and usage information for one or more of applications 225.

[0065] As described above, abuse detection module 222 may perform on-device detection of abusive applications. In some examples, abuse detection module 222 may include heuristics244, 24L models 246, or both, which abuse detection module 222 may apply to perform on-device detection of abusive applications. For example, abuse detection module 222 may apply heuristics 244, 24L models 246, or both to monitor applications 225 by detecting changes to visual representations 227 of one or more of applications 225. Abuse detection module 222 may apply heuristics 244, AIL models 246, or both to determine whether changes to visual representations 227 indicate one or more of applications 225 are abusive applications.

[0066] In some examples, abuse detection module 222 may include heuristics 244 in the form of instructions or rules that abuse detection module 222 may execute to detect changes to visual representations 227 and determine whether such changes indicate application 225 is an abusive application. For instance, visual representation 227A may represent a previous visual representation of application 225, such as the initial visual representation used by application upon installation to computing device 220. Visual representation 22724 may represent a subsequent (e.g., replacement) visual representation. Heuristics 244, when applied by abuse detection module 222 may cause abuse detection module 222 to compare the previous visual representation, visual representation 227A, to the subsequent visual representation, visual representation 22724 and determine whether a change in visual representations 227 of application 225 has occurred (e.g., visual representation 22724 is different than visual representation 227A).

[0067] Responsive to determining a change in visual representations 227 has occurred, heuristics 244 may cause abuse detection module 222 to determine whether the change in visual representations 227 indicates application 225 is an abusive application. For example, abuse detection module 222 may determine the change in visual representations 227 indicates application 225 is an abusive application when visual representation 22724 corresponds to a blank visual representation (e.g., is blank). As described above, abuse detection module 222 may consider visual representation 227N4 to be blank when an application icon or application name, such as application icon 12624 or application name 12824 of FIG. 1, respectively, is blank. Abuse detection module 222 may apply heuristics 244 to generate one or more scores indicating the likelihood or confidence level visual representation 22724 is blank.[00681 For example, abuse detection module 222 may apply heuristics 244 to generate an overflow-based hash of application icon 22624 and compare the hash to stored hashes for one zoor more blank application icons, such as described above. Abuse detection module 222 may apply heuristics 244 to generate the score based on how closely the hash of application icon 22624 matches a stored hash. For example, abuse detection module 222 may compare the hash of application icon 22624 to one or more stored hashes. If the hash of application icon 22624 is substantially similar to one of the stored hashes (e.g., within a predetermined range or distance to one of the stored hashes), abuse detection module 222 may generate a high score for application icon 22624 (e.g., 8 out of 10). If the hash of application icon 22624 matches (e.g., is identical) to one of the stored hashes, abuse detection module 222 may generate a maximum score (e.g., 10 out of 10) for application icon 22624. If the hash of application icon 22624 does not match or is not substantially similar to one of the stored hashes, abuse detection module 222 may generate a relatively lower score for application icon 12624 (e.g., 3 out of 10).

[0069] With respect to application names 228, abuse detection module 222 may generate one or more scores based on how closely the hash matches one or more stored hashes for application names 228. For example, abuse detection module 222 may compare the hash of application name 22824 to one or more stored hashes for one or more application names that are known to be blank (e.g., include no non-whitespace characters, invisible or substantially invisible characters, or both). If the hash of application name 22824 is substantially similar to one of the stored hashes (e.g., within a predetermined range or distance to one of the stored hashes), abuse detection module 222 may generate a high score for application name 22824 (e.g., 8 out. of 10). If the hash of application name 22824 matches (e.g., is identical) to one of the stored hashes, abuse detection module 222 may generate a maximum score (e.g., 10 out of 10) for application name 22824. If the hash of application name 22824 does not match or is not substantially similar to one of the stored hashes, abuse detection module 222 may generate a relatively lower score for application name 12824 (e.g., 3 out of 10).

[0070] In some examples, abuse detection module 222 may include and apply various 24L models 246 to determine whether visual representation 22724 is blank. Examples of different types of machine-learning models are provided below for illustration. Additional models beyond the example models provided below may be used as well. 24L model 246 may be or include one or more classifier models such as, for example, linear classification models; quadratic classification models; etc. 24L model 246 may be or include one or moreregression models such as, for example, simple linear regression models; multiple linear regression models; logistic regression models; stepwise regression models; multivariate adaptive regression splines; locally estimated scatterplot smoothing models; etc.

[0071] As such, to determine whether visual representation 22724 is blank, 24L model 246 may perform a classification of visual representation 22724 where visual representation 22724 may be classified as blank or not blank. 24L model 246 may output an indication of the classification 24L model 246 determines for visual representation 22724. Abuse detection module 222 may output an indication that application 225 A is at least potentially abusive in response to 24L model 246 classifying visual representation 22724 as blank.

[0072] 24L model 246 may be or include one or more artificial neural networks (also referred to simply as neural networks). A neural network may include a group of connected nodes, which also may be referred to as neurons or perceptrons. A neural network may be organized into one or more layers. Neural networks that include multiple layers may be referred to as “deep” networks. A deep network may include an input layer, an output layer, and one or more hidden layers positioned between the input layer and the output layer. The nodes of the neural network may be connected or non-fully connected.

[0073] One or more neural networks may be used to provide an embedding within a multidimensional embedding space for visual representations 227 of applications 225. For example, the embedding may be a representation of characteristics of visual representations 227 abstracted into one or more learned dimensions. In some instances, embeddings may be a useful source for identifying related entities, such as visual representations 227 that are blank or correspond to blank visual representations. In some instances, embeddings may be extracted from the output of the network, while in other instances embeddings may be extracted from any hidden node or layer of the network (e.g., a close to final but not final layer of the network).

[0074] 24L model 246 may utilize an embedding space, such as a multi-dimensional embedding space to determine whether visual representations 227 are blank. For example, 24L module 246 may generate an embedding for visual representation 22724 that specifies a location for visual representation 22724 within the embedding space based on graphical information (e.g., pixels) contained within visual representation 22724. 24L model 246 maygenerate the embeddings such that distances in the embedding space correspond to the likelihood that visual representations 227 are blank.

[0075] As such, visual representations 227 that are blank may be separated by smaller distances relative to embeddings for known blank visual representations (e.g., entirely white, entirely black, entirely gray) as compared to visual representations 227 that are not blank which may be separated by relatively larger distances to known blank visual representations. 24L model 246 may output the score corresponding to a likelihood or confidence level (e.g., percentage chance) that visual representation 22724 is blank based on the distance between the embedding for visual representation 22724 to the embedding for a visual representation 227 that is known to be blank where closer distances indicate a higher likelihood that visual representation 22724 is blank.

[0076] In some examples, 24L models 246 may perform or be subjected to one or more reinforcement learning techniques such as 24arkov decision processes; dynamic programming; Q functions or Q-leaming; value function approaches; deep Q-networks; differentiable neural computers; asynchronous advantage actor-critics; deterministic policy gradient; etc. Computing system 210 may generate 24L models 246 using various training techniques, including supervised, unsupervised, semi-supervised, and reinforcement learning techniques, utilizing one or more training data sets including previous examples of filtered application information. For example, supervised or unsupervised reinforcement learning techniques may be used to generate 24L models 246 that, when applied by abuse detection module 222, outputs an indication (e.g., score) indicating whether visual representation 22724: is blank.

[0077] For instance, if the distance is within a first range, 24L model 246 may generate a high score for visual representation 22724 (e.g., 9 out of 10). If the distance is outside of the first range but within a second larger range, 24L model 246 may generate a relatively lower score (e.g., 5 out of 10) for visual representation 22724. If the distance is outside the second larger range but within a third range, larger than the first and second range, 24L model 246 may generate an even lower score (e.g., 1 out of 10) for visual representation 22724, and so on and so forth. 24L model 246 may generate scores for portions of visual representations 227 individually (e.g., individual scores for respective application icons 226 and / or application names 228 of visual representations 227).23

[0078] During training, computing system 210 may validate the output generated by 24L models 246 using a validation data set where the output generated by 24L module 246 may be compared to previously validated data, such as visual representations classified as blank or not blank by human validators. By validating the output generated by 24L module 246, computing system 210 may ensure 24L model 246 is of a high quality or at least a satisfactory quality prior to deploying 24L model 246 for use with abuse detection module 222. Computing system 210 may also validate 24L model 246 as part of a feedback loop that continuously improves the quality of the output (e.g., scores or other indications of whether visual representation 227 is blank) of 24L model 246.

[0079] Abuse detection module 122 may combine scores from various sources (e.g., heuristics 244, 24L models 246) to generate a combined score using one or more heuristics. In some examples, abuse detection module 122 may generate the combined score by summing, averaging, or finding the mean or median of the one or more scores, such as described above. Abuse detection module 122 may apply heuristics 244 to generate a combined score. For example, heuristics 244, when applied by abuse detection module 122 may cause abuse detection module 122 to sum, average, find the mean or median, or otherwise combine one or more scores to generate the combined score. If a combined score satisfies a threshold score, abuse detection module 122 may determine application 225 is an abusive application and output an indication of the same.

[0080] Though described above with respect to heuristics 244 and 24L models 246, abuse detection module 222 may apply any suitable image recognition technique to determine whether visual representation 22724 is blank or to generate one or more scores indicating a likelihood or confidence level that visual representation 22724 is blank. Responsive to determining visual representation 22724 is blank, abuse detection module 222 may warn the user of computing device 220 that application 225A may be an abusive application, warning, such as through user interface device 224.

[0081] Abuse detection module 222 may perform operations described herein using software, hardware, firmware, or a mixture of hardware, software, and firmware residing in and / or executing at computing device 220 to interact with the application store of computing system 210 as well as other functions associated with applications 225, including installing applications 225, such as from respective application packages 214A-214N (collectively,24“application packages 214”) and / or updating or deleting applications 225 on computing device 220. Application packages 214 of FIG. 2 may be examples of application packages 114 as illustrated in FIG. 1.

[0082] Computing device 220 may execute abuse detection module 222, applications 225, or both with multiple processors or multiple devices, as virtual machines executing on underlying hardware, as one or more services of an operating system or computing platform, and / or as one or more executable programs at an application layer of a computing platform of computing device 220. In some examples, computing system 210 may perform detection of abusive applications and send, to computing device 220, an indication (e.g., warning) when computing system 210 detects an abusive application of applications 225. For example, computing system 210 may include and execute, such as through one or more processors of computing system 210, abuse detection module 222 remote from computing device 220. In these examples, computing device 220 may send, at one or more times (e.g., periodically or in response to detecting a change in visual representations 227), visual representations 227 of applications 225 installed to computing device 220 to computing system 210 for use as input to abuse detection module 222 at computing system 210, subject to first obtaining user approval and / or consistent with user preferences / settings.

[0083] FIGS. 3A-3C are block diagrams illustrating behavior of first examples of abusive application, in accordance with one or more aspects of the present disclosure. FIGS. 3A-3C are described below in the context of FIG. 1. As can be seen from FIGS. 3A-3C, a user interface 323 may present one or more visual representations 327A-32724 (collectively, “visual representations 327”) of an application, such as application 125 A of FIG. 1. Visual representations 327 may include various graphical representations of application 125A, such as application icons 326A-32624 (collectively, “application icons 326”), application names 328A-32824 (collectively, “application names 328”), or both. As described above, in response to user input selecting one of visual representations 327, a computing device 120, may execute a function of the application corresponding to the selected visual representation (e.g., the application represented by the selected visual representation). Visual representations 327, including application icons 326 and application names 328 thereof may respectively be examples of visual representations 127, application icons 126, and application names 128 as illustrated in FIG. 1.25

[0084] FIG. 3A illustrates an example of a first visual representation 327A which may be an initial visual representation for application 125A. For example, first visual representation 327A may be the visual representation used by application 125 A upon installation of application 125 A to computing device 120. As can be seen, first visual representation 327A includes application icon 326A, shown as a smiling face for example purposes, and application name 328A, shown as “UTILITY” also for example purposes.

[0085] As such, first visual representation 327A is not blank in that first visual representation 327A includes non-blank application icon 326A as well as non-blank application name 328A. An abuse application may change visual representations 327 such that the resulting visual representation 327 is intended to be inconspicuous (e.g., invisible, hidden, or not easily seen). In this manner, the abusive application may hide itself from remedial measures (e.g., detection, deletion) and continue to execute on computing device 120.

[0086] FIGS. 3B-3C illustrate different examples of second visual representations 32724. Second visual representation 32724 may be subsequent to first visual representation 327 A and thus may supersede (e.g., replace) first visual representation 327A at some point in time while application 125A remains installed on computing device 120. For example, application 125 A may include usage information, such as usage information 243 of FIG. 2 that causes user interface 323 to replace first visual representation 327A with second visual representation 32724. As described above, the usage information may cause user interface 323 to replace first visual representation 327 A based on various criteria. For example, the usage information may cause user interface 323 to replace first visual representation 327 A with second visual representation 32724 in response to the elapse of a predefined or random time period or in response to the application being executed in a testing, virtual, or other execution environment that does not correspond to the execution environment of computing device 120.

[0087] An abusive application may include usage information that renders the application inconspicuous, such as at a particular time or in response to various criteria. For example, an abusive application may include usage information that changes first visual representation 327A to second visual representation 32724, where second visual representation is at least substantially blank (e.g., includes a blank application icon 326, blank application name 328, or both). As can be seen from the example of FIG. 3B for instance, abuse detection module122 may consider second visual representation 32724 to be substantially blank in that second visual representation 32724 includes application icon 32624 that is blank as indicated by the dotted line depiction of application icon 32624 regardless of whether application name 32824 is blank or not blank. In the example of FIG. 3B, application name 32824 is not blank and remains the same as application name 328A. As can be seen from the example of FIG. 3C, second visual representation 32724 may be entirely blank. As compared to second visual representation 32724 of FIGS. 3A and 3B, second visual representation 32724 of FIG. 3C includes application icon 32624 and application name 32824 that are both blank as indicated by the dotted line depictions thereof. The dotted line depiction of application icon 32624 and application name 32824 is for illustrative purposes and, in operation, application icon 32624 and application name 32824 may not include the same.

[0088] Abuse detection module 122 may generate one or more scores that indicate the likelihood or confidence level that second visual representation 32724 is blank. Referring to FIG. 3B for example, abuse detection module 122 may generate a first score of 10 out of 10 (e.g,, 100% likely to be blank) based on application icon 32624 being blank and a second score of 0 out of 10 (e.g., 0% likely to be blank) based on application name 32824 not being blank. Abuse detection module 122 may generate a combined score using the first score and the second score. For example, abuse detection module 122 may average these two scores to generate a combined score of 5 (e.g., 50% likely to be blank). If the combined score satisfies a threshold score (e.g., is greater than the threshold score), abuse detection module 122 may present a warning to the user indicating that application 125 / X may be an abusive application, such as through user interface device 124. For instance, in this example, if the threshold score is 5, abuse detection module 122 may refrain from presenting the warning since the combined score does not satisfy the threshold score.

[0089] Though described in the above example with particular scores, abuse detection module 122 may generate additional or fewer scores. Continuing the above example for instance, abuse detection module 122 may generate a third score of 10 out of 10 (e.g., 100% likely to be changed) based on application icon 32624 of second visual representation 32724 being different than application icon 326A of first visual representation 32724. Abuse detection module 122 may combine the first, second, and third scores, or various subsets, such as by averaging these scores to generate a combined score. As described above, abusedetection module 122 may combine scores in various ways, including by summing, finding the mean or median, or by apply ing a weighting function or Bayesian techniques to the scores to generate a combined score. Abuse detection module 122 may compare the combined score to a threshold score to determine whether application 125A is an abusive application.

[0090] As another example, referring to second visual representation 32724 of FIG. 3C, abuse detection module 122 may generate a first score of 8 out of 10 (e.g., 80% likely to be blank) based on application icon 32624 being blank since application icon 32624 includes a relatively small number (e.g., less than 5%) of visible pixels. Abuse detection module 122 may generate a second score of 10 out of 10 (e.g., 100% likely to be blank) based on application name 32824 being blank. Abuse detection module 122 may generate a combined score using the first score and the second score. For example, abuse detection module 122 may average these two scores to generate a combined score of 9 (e.g., 90% likely to be blank). Similar to above, if the combined score satisfies the threshold score (e.g., is greater than the threshold score), abuse detection module 122 may present a warning to the user indicating that application 125 A may be an abusive application, such as through user interface device 124, For instance, in this example, if the threshold score is 5 or above, abuse detection module 122 may present the warning since the combined score does satisfy the threshold score.

[0091] FIG. 4 is a flowchart illustrating a first example process for on-device detection of abusive applications, in accordance with one or more aspects of the present disclosure. FIG.4 is described below in the context of FIG. 1.

[0092] Computing device 120 may determine, based on usage information of an application 125 A installed on computing device 120, a first visual representation 127 A of application 125A from a plurality of visual representations 127 provided by application 125 A (402). Computing device 120 may install application 125 A to computing device 120 and determine first visual representation 127A of application 125A in response to installing application 125 A. In this manner, first visual representation 127A may be the initial visual representation for application 125 A. Responsive to user input corresponding to selection of first visual representation 127 A, computing device 120 may execute a function of application 125 A.28

[0093] Computing device 120 may determine, based on the usage information from the application, a second visual representation 12724 of application 125A from visual representations 127 (404). Second visual representation 12724 may replace first visual representation 127A and may be different in appearance than first visual representation 127A. For example, second visual representation 12724 may include a different application icon 12624 and / or application name 12824.

[0094] Computing device 120 may determine whether second visual representation 12724 is at least substantially blank (406). To determine whether second visual representation 12724 is at least substantially blank, computing device 120 may generate a score based on whether application name 12824 of second visual representation 12724 is at least substantially blank, based on whether application icon 12624 of second visual representation 12724 is at least substantially blank, or both. In such cases, computing device 120 may determine second visual representation 12724 is at least substantially blank when the score satisfies a threshold score (e.g., is greater than the threshold score).

[0095] In some examples, computing device 120 may determine one or more differences between first visual representation 127A and second visual representation 12724. In such a case, computing device 120 may determine whether second visual representation 12724 is at least substantially blank in response to determining the one or more differences. In this manner, computing device 120 may determine whether second visual representation 12724 is at least substantially blank in response to determining second visual representation 12724 is different from first visual representation 127A.

[0096] Responsive to determining second visual representation 12724 is at least substantially blank, computing device 120 may present, to a user, an indication that application 125 / X is abusive (e.g., is an abusive application) (408). Computing device 120 may present, to the user, the indication that the application is abusive by presenting, to the user, a warning identifying the application as at least potentially abusive. Computing device 120 may present the indication through user interface device 124.

[0097] In some examples, one or more processors 232 of FIG. 2 execute abuse detection module 122 to provide the functionality described above with respect to the flowchart of FIG. 4.29[ 00981 FIGS. 5A-5C are block diagrams illustrating behavior of second examples of abusive applications, in accordance with one or more aspects of the present disclosure. FIGS. 5A–5C are described below in the context of FIG. 1. As described below, visual representation 527A and visual representation 52724 may be visual representations of application 125A of FIG. 1 and visual representation 527N may be a visual representation of application 125N of FIG. 1.

[0099] As can be seen from FIGS. 5A–5C, a user interface 523 may present one or more visual representations 527A-527N (collectively, “visual representations 527”) of an application, such as application 125 A of FIG. 1. Visual representations 527 may include various visible (e.g., graphical) representations of application 125 A, such as application icons 526A-526N (collectively, “application icons 526”), application names 528A-528N (collectively, “application names 528”), or both. As described above, in response to user input selecting one of visual representations 527, a computing device 120, may execute a function of the application corresponding to the selected visual representation (e.g., the application represented by the selected visual representation). User interface 523, visual representations 527, including application icons 526 and application names 528 thereof may respectively be examples of user interface 123, visual representations 127, application icons 126, and application names 128 as illustrated in FIG. 1.

[0100] As compared to the behavior of the example abusive applications described in connection with FIGS. 3A-3C, which change visual representations 327 to use intentionally inconspicuous (e.g., blank) visual representations, the abusive applications illustrated in FIGS. 5A-5C may deceive users into believing the abusive applications are other applications (e.g., legitimate applications). For example, rather than changing visual representations 527 to be blank, the abusive applications of FIGS. 5A–5C may change visual representations 527 to result in a visual representation that is at least substantially similar to the visual representation of another application.

[0101] Referring to FIG. 5A for example, application 125A may initially use visual representation 527A including application icon 526A, shown as a frowning face for example purposes, and application name 528A, shown as “UTILITY” also for example purposes. First visual representation 527A may correspond to the expected visual representation for application 125 A. For example, first visual representation 527A may include applicationicon 526 A and application name 528 A that correspond to the purported (e.g., expected, advertised) functionality of application 125 A. In the example of FIG. 5 A for instance, application 125A purports to be a utility application and included application icon 526A and application name 528A may correspond to such functionality.

[0102] Application 125 A may include usage information that causes application 125 A to use second visual representation 52724, as shown in FIG. 5B. For example, based on the usage information, application 125 A may replace visual representation 527 A with visual representation 52724. For purposes of this example, rather than a blank visual representation, application 125 A utilizes visual representation 52724 which is deceptively similar to that of another application, such as application 125N. For purposes of this example, application 125N may be a banking application.

[0103] Continuing this example, application icon 52624, shown as a smiling face, may be deceptively similar to application icon 526N of application 125N, application name 52824, shown as “BANK,” may be deceptively similar to application name 528N of application 125N, or both to mislead users into believing application 125A is application 125N. In this manner, application 125A may avoid remedial measures by “hiding” (e.g., masquerading, appearing to be) as a legitimate application (e.g., application 125N). For example, by utilizing a visual representation that is similar to another application, application 125 may be difficult to find, such as to disable or delete application 125A, Even if found, the user may not delete or disable application 125 A, based on the user’s belief from visual representation 52724 that application 125A is application 125N.

[0104] Abuse detection module 122 may monitor applications 125 to detect when one or more of applications 125 change visual representations 527 to appear as other applications (e.g., to be deceptively similar to other applications). Similar to above, abuse detection module 122 may apply heuristics, 24L models, or other techniques, to determine when applications 125 change visual representations 527 to correspond to (e.g., be similar in appearance to) visual representations 527 of other applications 125.

[0105] As described above, abuse detection module 122 may perform on-device detection of abusive applications. For example, the heuristics, when applied by abuse detection module 122 may cause abuse detection module 122 to compare the previous visual representation, such as visual representation 527A, to the subsequent visual representation, such as visualrepresentation 52724 and determine whether a change in visual representations 527 of application 225 has occurred (e.g., visual representation 52724 is different than visual representation 527A).

[0106] Responsive to determining a change in visual representations 527 has occurred, the heuristics may cause abuse detection module 122 to determine whether the change in visual representations 527 indicates application 125 is an abusive application. For example, abuse detection module 122 may determine the change in visual representations 527 indicates application 125 A is an abusive application when visual representation 52724 corresponds to (e.g., is similar in appearance to) a visual representation 527N of another application 125N. Abuse detection module 122 may apply the heuristics to generate one or more scores indicating the likelihood or confidence level (e.g., percentage chance) that visual representation 22724 of application 125 A corresponds to visual representation 527N of application 125N.

[0107] For example, abuse detection module 122 may apply the heuristics to generate an overflow-based hash of application icon 52624 of visual representation 52724 and compare the hash to stored hashes for one or more applications icons 526 of other applications 125, such as application icon 526N of visual representation 527N. Abuse detection module 122 may generate these stored hashes, such as by generating an overflow-based hash of application icons 526 of visual representations 527 of other applications 125 installed on computing device 120.

[0108] Abuse detection module 122 may apply the heuristics to generate one or more scores based on how closely the hash of application icon 52624 matches a stored hash for application icon 526N. If the hash of application icon 52624 is substantially similar to one of the stored hashes for other application icons 526 (e.g., within a predetermined range or distance to one of the stored hashes), abuse detection module 222 may generate a high score for application icon 52624 (e.g., 8 out of 10). If the hash of application icon 22624 matches (e.g., is identical) to one of the stored hashes, abuse detection module 222 may generate a maximum score (e.g., 10 out of 10) for application icon 22624. If the hash of application icon 22624 does not match or is not substantially similar to one of the stored hashes, abuse detection module 222 may generate a relatively lower score for application icon 12624 (e.g., 3 out of 10).

[0109] With respect to application names 528 of visual representations 527, abuse detection module 222 may generate one or more scores based on how closely a hash (e.g., overflowbased hash) of one of application names 528 matches one or more stored hashes for application names 228. For example, abuse detection module 222 may compare the hash of application name 52824 to one or more stored hashes for one or more application names 528 of other applications 125, such as application name 528N of application 125N. If the hash of application name 52824 is substantially similar to one of the stored hashes (e.g., within a predetermined range or distance to one of the stored hashes), abuse detection module 122 may generate a high score for application name 52824 (e.g., 8 out of 10). If the hash of application name 52824 matches (e.g., is identical) to one of the stored hashes, abuse detection module 122 may generate a maximum score (e.g., 10 out of 10) for application name 52824. If the hash of application name 52824 does not match or is not substantially similar to one of the stored hashes, abuse detection module 122 may generate a relatively lower score for application name 12824 (e.g., 3 out of 10).

[0110] Abuse detection module 122 may apply the heuristics to generate a combined score from the one or more scores, such as described above. If the combined score satisfies a threshold score, abuse detection module 122 may determine application 225 is an abusive application and output an indication of the same. If the combined score does not satisfy the threshold score, abuse detection module 122 may refrain from outputting the indication.

[0111] In some examples, abuse detection module 222 may include and apply various 24L models, such as 24L models 246 of FIG. 2, to determine whether visual representation 22724 corresponds to visual representations 527 of one or more of applications 125. For example, to determine whether visual representation 52724 corresponds to visual representation 527N, an 24L model may perform a classification of visual representation 52724 where visual representation 52724 may be classified as similar or dissimilar to visual representation 527N. The 24L model may output an indication of the classification the 24L model determines for visual representation 52724. Abuse detection module 122 may output an indication that application 125 A is at least potentially abusive in response to the AIL model classifying visual representation 52724 as similar to visual representation 527N.

[0112] An AIL model may utilize an embedding space, such as a multi-dimensional embedding space to determine whether visual representations 527 correspond to one another.For example, the 24L module may generate an embedding for visual representation 52724 and visual representation 527N that specifies respective locations for visual representation 52724 and visual representation 527N within the embedding space based on graphical information (e.g., pixels) respectively contained within visual representation 52724 and visual representation 527N. The 24L model may generate the embeddings such that distances in the embedding space correspond to the likelihood that visual representations 527 are similar, where closer distances indicate a higher likelihood that visual representations 527 are similar.

[0113] As such, visual representations 527 that are similar may be separated by smaller distances as compared to visual representations 527 that are dissimilar, which may be separated by relatively larger distances. The AIL model may output the score corresponding to a likelihood or confidence level (e.g., percentage chance) that visual representation 52724 corresponds to visual representation 527N based on the distance between the embedding for visual representation 52724 to the embedding for a visual representation 527N where closer distances indicate a higher likelihood that visual representation 52724 and visual representation 527N are similar,

[0114] Though described above with respect to heuristics and 24L models, abuse detection module 122 may apply any suitable image recognition technique to determine whether visual representation 52724 corresponds to visual representation 527N or to generate one or more scores indicating a likelihood or confidence level that visual representation 52724 corresponds to visual representation 527N. Responsive to determining visual representation 52724 corresponds to visual representation 527N, abuse detection module 122 may warn the user of computing device 120 that application 125 A may be an abusive application. Abuse detection module 122 may generate data to output a user interface element that presents the warning, such as through user interface device 224.

[0125] As described above, abusive applications may have malicious or otherwise abusive functionality. Referring to the example of FIG. 5C for instance, abusive applications may present nuisance promotions 552 or the like that disrupt the user experience by occupying substantially all of user interface 523 and potentially offering deceptive products or services. To illustrate, application 125 A may change visual representations 527 to visual representation 52724 and thereafter display one or more deceptive or nuisance promotions552 (e.g., advertisements), such as to obtain impressions. As can be seen, nuisance promotions 552 may be a full screen promotion that occupies substantially all or entirely all of user interface 523 and thereby at least partially obscure (e.g., cover) other user interface elements, such as visual representations of other applications 125, such as visual representation 527N. Since application 125A has changed to visual representation 52724, which is deceptively similar to that of the banking application, application 125A may be difficult or impossible to find, delete, or disable. Though described in connection with the behavior of abusive applications that change visual representations 527 to appear as other applications, in some examples, the behavior of abusive applications that change visual representations to be blank may also include presenting nuisance promotions 552.

[0116] Abusive applications may deceive the user of computing device 120 into initiating presentation of nuisance promotions 552. For example, application 125A may present a notification, such as notification 129 of FIG. 1, that, when selected, causes user interface 523 to display nuisance promotion 552. Because application 125A may use visual representation 52724, which is deceptively similar to visual representation 527 of another application, in this example visual representation 527N of application 125N, notification 129 presented by application 125 A may appear to be from application 125N. For example, the operating system of computing device 120 may include visual representation 52724 of application 125 A in notification 129 presented by application 1 5 A. As such, the user may select notification 129 on the belief that notification 129 is from application 125N as opposed to application 125 / X. Rather than providing expected functionality (e.g., opening application 125N), application 125A may display nuisance promotion 552 in response to user input selecting notification 129. Application 125 A may include, in notification 129, claims to unlikely functionality (e.g., making operation of computing device 102 faster), various incentives (e.g., free crypto currency), or other deceptive content, such as to cause the user to select notification 129.

[0117] Abuse detection module 122 may monitor applications 125 to detect abusive applications that present notifications 129 that are abusive (e.g., include deceptively similar visual representations 527). For example, abuse detection module 122 may detect when application 125 A presents nuisance promotion 552 in response to selection of one or more notifications 129. Abuse detection module 122 may determine whether visual representation52724 used by application 125 A corresponds to visual representation 527N of another application 125N. In response to determining visual representation 52724 corresponds to visual representation 527N and detecting application 125A has presented nuisance promotion 552 in response to selection of notification 129, abuse detection module 122 may determine application 125 A is abusive. Accordingly, abuse detection module 122 may output an indication that application 125A is at least potentially abusive.

[0118] Abuse detection module 122 may apply image recognition techniques to detect nuisance promotions 522, including heuristics and / or 24L models. For example, abuse detection module 122 may apply heuristics that generate hashes, such as overflow-based hashes, for user interface elements that may correspond to nuisance promotions 552, and compare such hashes to stored hashes (e.g., previously generated hashes) for user interface elements known to be nuisance promotions 552. Similar to above, abuse detection module 122 may generate a score corresponding to a likelihood or confidence level (e.g., percentage chance) based on the similarity’ between a hash and a stored hash. Abuse detection module 122 may assign a higher score when the hash matches or is very similar to the stored hash and a relatively lower score when the hash is not similar to the stored hash. When the score satisfies a threshold score, abuse detection module 122 may determine the user interface element is a nuisance promotion 552.

[0129] In some examples, abuse detection module 122 may apply one or more 24L models that output a classification for the user interface element indicating whether the user interface element is classified as a nuisance promotion 552 or not. An 24L model may utilize an embedding space, such as described above, and generate an embedding for the user interface element, where the distance between the embedding and one or more stored embeddings (e.g., previously generated embeddings) of nuisance promotions 552 indicates a likelihood or confidence level that the user interface element is a nuisance promotion 552, Abuse detection module 122 may generate a score corresponding to a likelihood or confidence level (e.g., percentage chance) that the user interface element is a nuisance promotion 552 based on the distance where closer distances indicate a higher likelihood that the user interface element is a nuisance promotion 552.

[0120] Computing device 120, such as through the operating system of computing device 120, may provide permissions to abuse detection module 122 to allow abuse detectionmodule 122 to access graphical information displayed in user interface 523 for the purpose of generating scores or otherwise analyzing the graphical information to detect nuisance promotions 522.

[0121] FIG. 6 is a flowchart illustrating a second example process for on-device detection of abusive applications, in accordance with one or more aspects of the present disclosure. FIG.6 is described below in the context of FIG. 1.

[0122] Computing device 120 may determine, based on usage information of an application 125 A installed on computing device 120, a first visual representation 127A of a first application 125 A from a plurality of visual representations 127 provided by application 125 A (602). Responsive to user input corresponding to selection of first visual representation 127 A, computing device 120 may execute a function of application 125 A.

[0123] Computing device 120 may determine, based on the usage information from first application 125A, a second visual representation 12724 of first application 125 A from visual representations 127 (604). Second visual representation 12724 may replace first visual representation 127 A and may be different in appearance than first visual representation 127A.

[0124] Computing device 120 may generate, based on second visual representation 12724, a score corresponding to second visual representation 12724 being at least substantially similar to a third visual representation 127N of a second application 125N (606). Each of visual representations 127 may include one or more of an application icon 126 or an application name 128. Computing device 120 may generate the score based on the similarity between application name 12824 of second visual representation 12724 and application name 128N of visual representation 127N, based on the similarity between application icon 12624 of second visual representation 12724 and application icon 126N of visual representation 127N, or both. Computing device 120 may apply heuristics, 24L models, or both to generate the score.

[0125] Computing device 120 may determine first application 125A causes a notification 129 including second visual representation 12724 to be presented (608). When notification 129 is presented by an abusive application, computing device 120 may present a nuisance promotion, such as nuisance promotion 552 of FIG. 5, in response to selection of notification 129.

[0126] Responsive to determining first application 125 A causes the notification to be presented, computing device 120 may present, to a user, an indication that application 125 A is abusive (e.g., is an abusive application) (610). Computing device 120 may present, to the user, the indication that the application is abusive by presenting, to the user, a warning identifying the application as at least potentially abusive. Computing device 120 may present the indication through user interface device 124.

[0127] In some examples, one or more processors 232 of FIG. 2 execute abuse detection module 122 to provide the functionality described above with respect to the flowchart of FIG. 6.

[0128] Aspects of this disclosure include the following examples.

[0129] Example 1: A method includes determining, by a computing device and based on usage information of an application installed on the computing device, a first visual representation of the application from a plurality of visual representations provided by the application, wherein user input corresponding to selection of the first visual representation causes a function associated with the application to be executed; determining, by the computing device and based on the usage information from the application, a second visual representati on of the application from the plurality of visual representations, wherein the second visual representation replaces the first visual representation and is different in appearance than the first visual representation; determining, by the computing device, whether the second visual representation is at least substantially blank; and responsive to determining the second visual representation is at least substantially blank, presenting, by the computing device and to a user, an indication that the application is abusive.

[0130] Example 2: The method of example 1, wherein each of the plurality of visual representations comprises one or more of an application icon or an application name.

[0131] Example 3: The method of examples 2, wherein determining whether the second visual representation is at least substantially blank comprises generating, by the computing device, a score based on whether the application name of the second visual representation is at least substantially blank, wherein the second visual representation is at least substantially blank when the score satisfies a threshold score.

[0132] Example 4: The method of any of examples 2 and 3, wherein generating the score comprises generating, by the computing device, the score based on whether the application icon of the second visual representation is at least substantially blank.

[0133] Example 5: The method of any of examples 1-4. further comprising determining, by the computing device, one or more differences between the first visual representation and the second visual representation.

[0134] Example 6: The method of example 5, wherein determining whether the second visual representation is at least substantially blank is responsive to determining the one or more differences between the first visual representation and the second visual representation.

[0135] Example 7: The method of any of examples 1-6, further comprising installing, by the computing device, the application on the computing device, wherein determining the first visual representation of the application is responsive to installing the application on the computing device.

[0136] Example 8: The method of any of examples 1-7, wherein presenting, to the user, the indication that the application is abusive comprises presenting, by the computing device and to the user, a warning identifying the application as at least potentially abusive.

[0137] Example 9: The method of any of examples 1-8, wherein determining whether the second visual representation is at least substantially blank comprises applying, by the computing device, one or more machine learning models to the second visual representation.

[0138] Example 10: A computing device includes a memory that stores instructions; and one or more processors that execute the instructions to: determine, based on usage information of an application installed on the computing device, a first visual representation of the application from a plurality of visual representations provided by the application, wherein user input corresponding to selection of the first visual representation causes a function associated with the application to be executed; determine, based on the usage information from the application, a second visual representation of the application from the plurality of visual representations, wherein the second visual representation replaces the first visual representation and is different in appearance than the first visual representation; determine whether the second visual representation is at least substantially blank; and responsive to determining the second visual representation is at least substantially blank, present, to a user, an indication that the application is abusive.

[0139] Example 11: The computing device of example 10, wherein each of the plurality of visual representations comprises one or more of an application icon or an application name.

[0140] Example 12: The computing device of example 11, wherein to determine whether the second visual representation is at least substantially blank the one or more processors execute the instructions to generate a score based on whether the application name of the second visual representation is at least substantially blank, wherein the second visual representation is at least substantially blank when the score satisfies a threshold score.

[0141] Example 13: The computing device of any of examples 11 and 12, wherein to generate the score the one or more processors execute the instructions to generate the score based on whether the application icon of the second visual representation is at least substantially blank.

[0142] Example 14: The computing device of any of examples 10-13, wherein the one or more processors execute the instructions to determine one or more differences between the first visual representation and the second visual representation.

[0143] Example 25: The computing device of example 14, wherein the one or more processors execute the instructions to determine whether the second visual representation is at least substantially blank responsive to determining the one or more differences between the first visual representation and the second visual representation.

[0144] Example 16: The computing device of any of examples 10-25, wherein the one or more processors execute the instructions to install the application on the computing device, wherein the one or more processors execute the instructions to determine the first visual representation of the application responsive to installing the application on the computing device.

[0145] Example 17: The computing device of any of examples 10-16, wherein to present the indication that the application is abusive the one or more processors execute the instructions to present, to the user, a warning identifying the application as at least potentially abusive.

[0146] Example 18: The computing device of any of examples 10-17, wherein to determine whether the second visual representation is at least substantially blank the one or more processors execute the instructions to apply one or more machine learning models to the second visual representation.

[0147] Example 29: Non-transitory computer-readable storage media storing instructions that, when executed, cause one or more processors of a computing device to: determine, based on usage information of an application installed on the computing device, a first visual representation of the application from a plurality of visual representations provided by the application, wherein user input corresponding to selection of the first visual representation causes a function associated with the application to be executed; determine, based on the usage information from the application, a second visual representation of the application from the plurality of visual representations, wherein the second visual representation replaces the first visual representation and is different in appearance than the first visual representation; determine whether the second visual representation is at least substantially blank; and responsive to determining the second visual representation is at least substantially blank, present, to a user, an indication that the application is abusive.

[0148] Example 20: The non-transitory computer-readable storage media of example 29, wherein each of the plurality of visual representations comprises one or more of an application icon or an application name.

[0149] Example 21: The non-transitory computer-readable storage media of example 20, wherein to determine whether the second visual representation is at least substantially blank the instructions, when executed, cause the one or more processors to generate a score based on whether the application name of the second visual representation is at least substantially blank, wherein the second visual representation is at least substantially blank when the score satisfies a threshold score.

[0250] Example 22: The non-transitory computer-readable storage media of any of examples 20 and 21, wherein to generate the score the instructions, when executed, cause the one or more processors to generate the score based on whether the application icon of the second visual representation is at least substantially blank.

[0251] Example 23: The non-transitory computer-readable storage media of any of examples 29-22, wherein the instructions, when executed, cause the one or more processors to determine one or more differences between the first visual representation and the second visual representation.

[0252] Example 24: The non-transitory computer- readable storage media of example 23, wherein the instructions, when executed, cause the one or more processors to determinewhether the second visual representation is at least substantially blank responsive to determining the one or more differences between the first visual representation and the second visual representation.

[0253] Example 25: The non-transitory computer-readable storage media of any of examples 29-24, wherein the instructions, when executed, cause the one or more processors to install the application on the computing device, wherein the instructions, when executed, cause the one or more processors to determine the first visual representation of the application responsive to installing the application on the computing device.

[0254] Example 26: The non-transitory computer-readable storage media of any of examples 29-25, wherein to present the indication that the application is abusive the instructions, when executed, cause the one or more processors to present, to the user, a warning identifying the application as at least potentially abusive.

[0255] Example 27: The non-transitory computer- readable storage media of any of examples 29-26, wherein to determine whether the second visual representation is at least substantially blank the instructions, when executed, cause the one or more processors to apply one or more machine learning models to the second visual representation.

[0256] Example 28: A computer-program product that includes instructions that cause one or more processors to perform any combination of the methods of examples 1 -9.

[0257] In one or more examples, the functions described may be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions may be stored on or transmitted over, as one or more instructions or code, a computer-readable medium and executed by a hardware-based processing unit. Computer-readable media may include computer-readable storage media, which corresponds to a tangible medium such as data, storage media, or communication media including any medium that facilitates transfer of a computer program from one place to another, e.g., according to a communication protocol. In this manner, computer-readable media generally may correspond to (1) tangible computer-readable storage media, which is non-transitory or (2) a communication medium such as a signal or carrier wave. Data storage media may be any available media that may be accessed by one or more computers or one or more processors to retrieve instructions, code and / or data structures for implementation of the techniquesdescribed in this disclosure. A computer program product may include a computer-readable medium.

[0258] By way of example, and not limitation, such computer-readable storage media may comprise RA24, RO24, EEPRO24, CD-RO24 or other optical disk storage, magnetic disk storage, or other magnetic storage devices, flash memory, or any other storage medium that may be used to store desired program code in the form of instructions or data structures and that may be accessed by a computer. Also, any connection is properly termed a computer-readable medium. For example, if instructions are transmitted from a website, server, or other remote source using a coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. It should be understood, however, that computer-readable storage media and data storage media do not include connections, carrier waves, signals, or other transient media, but are instead directed to non-transient, tangible storage media. Disk and disc, as used herein, includes compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), floppy disk and Blu-ray disc, where disks usually reproduce data magnetically, while disks reproduce data optically with lasers.Combinations of the above should also be included within the scope of computer-readable media.

[0259] Instructions may be executed by one or more processors, such as one or more digital signal processors (DSPs), general purpose microprocessors, application specific integrated circuits (ASICs), field programmable logic arrays (FPGAs), or other equivalent integrated or discrete logic circuitry'. Accordingly, the term "processor," as used herein may refer to any of the foregoing structures or any other structure suitable for implementation of the techniques described herein. In addition, in some aspects, the functionality described herein may be provided within dedicated hardware and / or software modules. Also, the techniques could be fully implemented in one or more circuits or logic elements.

[0160] The techniques of this disclosure may be implemented in a wide variety of devices or apparatuses, including a wireless handset, an integrated circuit (IC) or a set of ICs (e.g., a chip set). Various components, modules, or units are described in this disclosure to emphasize functional aspects of devices configured to perform the disclosed techniques, butdo not necessarily require realization by different hardware units. Rather, as described above, various units may be combined in a hardware unit or provided by a collection of intraoperative hardware units, including one or more processors as described above, in conjunction with suitable software and / or firmware.

[0161] It is to be recognized that, depending on the example, certain acts or events of any of the methods described herein may be performed in a different sequence, may be added, merged, or left out altogether (e.g., not all described acts or events are necessary for the practice of the method). 24oreover, in certain embodiments, acts or events may be performed concurrently, e.g., through multi-threaded processing, interrupt processing, or multiple processors, rather than sequentially.

[0162] In some examples, a computer-readable storage medium comprises a non-transitory medium. The term "non-transitory" indicates that the storage medium is not embodied in a carrier wave or a propagated signal. In certain examples, a non-transitory storage medium may store data that can, over time, change (e.g., in RA24 or cache).

[0163] Various examples have been described. These and other examples are within the scope of the following claims.

Claims

CLAI24S:

1. A method comprising:determining, by a computing device and based on usage information of an application installed on the computing device, a first visual representation of the application from a plurality of visual representations provided by the application, wherein user input corresponding to selection of the first visual representation causes a function associated with the application to be executed;determining, by the computing device and based on the usage information from the application, a second visual representation of the application from the plurality of visual representations, wherein the second visual representation replaces the first visual representation and is different in appearance than the first visual representation;determining, by the computing device, whether the second visual representation is at least substantially blank; andresponsive to determining the second visual representation is at least substantially blank, presenting, by the computing device and to a user, an indication that the application is abusive.

2. The method of claim 1, wherein each of the plurality of visual representations comprises one or more of an application icon or an application name.

3. The method of claim 2, wherein determining whether the second visual representation is at least substantially blank comprises generating, by the computing device, a score based on whether the application name of the second visual representation is at least substantially blank, wherein the second visual representation is at least substantially blank when the score satisfies a threshold score.

4. The method of any of claims 2 and 3, wherein generating the score comprises generating, by the computing device, the score based on whether the application icon of the second visual representation is at least substantially blank.

5. The method of any of claims 1-4, further comprising determining, by the computing device, one or more differences between the first visual representation and the second visual representation.

6. The method of claim 5, wherein determining whether the second visual representation is at least substantially blank is responsive to determining the one or more differences between the first visual representation and the second visual representation.

7. The method of any of claims 1-6, further comprising installing, by the computing device, the application on the computing device, wherein determining the first visual representation of the application is responsive to installing the application on the computing device.

8. The method of any of claims 1-7, wherein presenting, to the user, the indication that the application is abusive comprises presenting, by the computing device and to the user, a warning identifying the application as at least potentially abusive.

9. The method of any of claims 1-8, wherein determining whether the second visual representation is at least substantially blank comprises applying, by the computing device, one or more machine learning models to the second visual representation.

10. A computing device comprising:a memory' that stores instructions; andone or more processors that execute the instructions to perform the method of any of claims 1-9.

11. Non-transitory computer-readable storage media comprising instructions that, when executed by one or more processors, cause the one or more processors to perform the method of any of claims 1 -9.

12. A computer-program product that includes instructions that cause one or more processors to perform any combination of the methods of claims 1-9.

Citation Information

Patent Citations

  • System, method, and computer program product for detecting unwanted data based on an analysis of an icon

    US20130276105A1

  • Apparatus and method for detecting malicious application based on visualization similarity

    US20160110543A1

  • Systems and methods for threat detection and warning

    US20200137110A1

  • Detecting unknown malicious content in computer systems

    US20210141897A1