REVIEW 2 major objections 1 minor 1 cited by
Detecting and Characterising Mobile App Metamorphosis in Google Play Store
T0 review · 2 major / 1 minor · reviewed 2026-05-23 · grok-4.3
Pith's one-line read A multi-modal search on two Google Play Store snapshots five years apart detects apps that undergo major identity or purpose changes.
desk verdict The paper names 'app metamorphosis' for major app re-branding or re-purposing and applies multi-modal matching across two Play Store snapshots, but the matching step has no reported validation so the counts and 11.3% figure rest on untested assumptions. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The multi-modal search methodology applied to two snapshots of the Google Play Store five years apart.
What would settle it
A manual review of a random sample of flagged apps that finds either many false detections or a large number of actual transformations the method missed.
Extended reading notes
Core claim
We define this previously unstudied phenomenon as 'app metamorphosis'. In this paper, we propose a novel and efficient multi-modal search methodology to identify apps undergoing metamorphosis and apply it to analyse two snapshots of the Google Play Store taken five years apart. Our methodology uncovers various metamorphosis scenarios, including re-births, re-branding, re-purposing, and others, enabling comprehensive characterisation. Although these transformations may register as successful for app developers based on our defined success score metric (e.g., re-branded apps performing approximately 11.3% better than an average top app), we shed light on the concealed security and privacy risk
Load-bearing premise
That a multi-modal search across two store snapshots five years apart can reliably locate genuine cases of app metamorphosis without substantial false positives or missed instances.
Editorial extensions
If this is right
- Re-branded apps register approximately 11.3 percent higher on the defined success score than an average top app.
- Metamorphosis scenarios such as re-births and re-purposing can be systematically catalogued.
- Transformed apps can carry concealed security and privacy risks that affect even tech-savvy users.
- Some transformations register as commercially successful for developers despite the underlying changes.
Reading between the lines
- Stores could add version-history flags that alert users when an app's core function has shifted.
- The same search technique might be applied to more frequent snapshots to track how often apps change direction.
- Reputation resets through re-branding could affect how rating systems should handle app identity over time.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper defines 'app metamorphosis' as significant transformations in mobile apps' use cases or market positioning on the Google Play Store. It proposes a multi-modal search methodology (name + description + icons + metadata) applied to two snapshots five years apart to detect and characterize scenarios including re-births, re-branding, and re-purposing. A success score metric is defined, with the claim that re-branded apps perform approximately 11.3% better than an average top app, while also highlighting concealed security and privacy risks.
Significance. If the detection methodology proves reliable through validation, the work offers a novel empirical lens on app evolution dynamics beyond incremental updates, with potential value for market analysis and security research. The use of real store snapshots and a quantitative success metric provides concrete characterization, though the absence of reported validation metrics limits the strength of the central claims.
major comments (2)
- [multi-modal search methodology] The multi-modal search methodology (as described in the abstract) lacks any reported precision, recall, or validation against a labeled ground-truth set. Without this, the identification of true metamorphosis instances between the five-year snapshots risks substantial false positives from name collisions, developer changes, or description drift, directly undermining the reported scenario counts and the 11.3% success-score advantage.
- [success score metric] The success score metric is presented as central to evaluating transformation outcomes (e.g., the 11.3% figure for re-branded apps), yet its exact definition, parameters, and computation are not specified. This free parameter makes it impossible to assess whether the performance claims are robust or sensitive to unstated choices in data handling or thresholding.
minor comments (1)
- [Abstract] The abstract would benefit from a brief statement on how the two snapshots were obtained and any filtering rules applied to the data.
Simulated Author's Rebuttal
We thank the referee for their constructive feedback, which highlights important areas for strengthening the presentation of our methodology and metrics. We respond to each major comment below and will revise the manuscript accordingly.
read point-by-point responses
-
Referee: The multi-modal search methodology (as described in the abstract) lacks any reported precision, recall, or validation against a labeled ground-truth set. Without this, the identification of true metamorphosis instances between the five-year snapshots risks substantial false positives from name collisions, developer changes, or description drift, directly undermining the reported scenario counts and the 11.3% success-score advantage.
Authors: We agree that explicit validation metrics would improve the strength of the claims. The multi-modal design (requiring consistency across name, description, icons, and metadata) was intended to reduce false positives from single-modality issues such as name collisions, but the manuscript does not include quantitative precision/recall or a formal ground-truth evaluation. In the revision we will add a new subsection describing a manual validation performed on a random sample of detected cases (reporting inter-rater agreement and estimated precision), together with an explicit discussion of remaining limitations and false-positive risks. revision: yes
-
Referee: The success score metric is presented as central to evaluating transformation outcomes (e.g., the 11.3% figure for re-branded apps), yet its exact definition, parameters, and computation are not specified. This free parameter makes it impossible to assess whether the performance claims are robust or sensitive to unstated choices in data handling or thresholding.
Authors: We accept that the success score must be fully specified for reproducibility. The metric aggregates normalized changes in ranking, downloads, and ratings relative to category averages, but the manuscript omits the precise formula, weights, and thresholding steps. In the revised version we will insert the complete mathematical definition, all parameter values, and the exact computation that yields the reported 11.3% figure, enabling readers to perform sensitivity checks. revision: yes
Circularity Check
No circularity: empirical snapshot comparison with defined metrics
full rationale
The paper defines 'app metamorphosis' as a new phenomenon, proposes a multi-modal search method, applies it to two Google Play snapshots five years apart, and defines a success score metric to quantify outcomes such as the reported 11.3% advantage for re-branded apps. These are operational definitions and direct empirical measurements on observed data; no equations, parameters, or claims reduce by construction to their own inputs, no self-citation chains are load-bearing, and no ansatzes or uniqueness theorems are invoked. The central results rest on the external store data rather than internal redefinition or fitting.
Assumptions & free parameters
free parameters (1)
- success score metric
Cite this review
Pith. "Pith review of Detecting and Characterising Mobile App Metamorphosis in Google Play Store." pith.science (2026). https://pith.science/paper/2407.14565
@misc{pith2026240714565,
author = {Pith},
title = {Pith review of: Detecting and Characterising Mobile App Metamorphosis in Google Play Store},
year = {2026},
howpublished = {\url{https://pith.science/paper/2407.14565}},
note = {Machine review of arXiv:2407.14565}
}
read the original abstract
App markets have evolved into highly competitive and dynamic environments for developers. While the traditional app life cycle involves incremental updates for feature enhancements and issue resolution, some apps deviate from this norm by undergoing significant transformations in their use cases or market positioning. We define this previously unstudied phenomenon as 'app metamorphosis'. In this paper, we propose a novel and efficient multi-modal search methodology to identify apps undergoing metamorphosis and apply it to analyse two snapshots of the Google Play Store taken five years apart. Our methodology uncovers various metamorphosis scenarios, including re-births, re-branding, re-purposing, and others, enabling comprehensive characterisation. Although these transformations may register as successful for app developers based on our defined success score metric (e.g., re-branded apps performing approximately 11.3% better than an average top app), we shed light on the concealed security and privacy risks that lurk within, potentially impacting even tech-savvy end-users.
Figures
Figures from the paper (12 more)
Forward citations
Cited by 1 Pith paper
-
Detecting Content Rating Violations in Android Applications: A Vision-Language Approach
A vision-language model with style and content encoders plus cross-attention predicts Android game content ratings about 6% more accurately than fine-tuned CLIP and flags suspected rating violations, including Teacher...
Reference graph
Works this paper leans on
-
[1]
Number of available applications in the google play store from december 2009 to march 2023,
Statista Inc., “Number of available applications in the google play store from december 2009 to march 2023,” 2023. Accessed on May, 2023
work page 2009
-
[2]
Number of apps available in leading app stores as of 3rd quarter 2022,
Statista Inc., “Number of apps available in leading app stores as of 3rd quarter 2022,” 2022. Accessed on May, 2023
work page 2022
-
[3]
Short video service musical.ly is merging into sister app tiktok,
TechCrunch, “Short video service musical.ly is merging into sister app tiktok,” 2018. Accessed on May, 2023
work page 2018
-
[4]
A measurement study of google play,
N. Viennot, E. Garcia, and J. Nieh, “A measurement study of google play,” in The 2014 ACM international conference on Measurement and modeling of computer systems , pp. 221–233, 2014
work page 2014
-
[5]
Beyond google play: A large-scale comparative study of chinese android app markets,
H. Wang, Z. Liu, J. Liang, N. Vallina-Rodriguez, Y . Guo, L. Li, J. Tapiador, J. Cao, and G. Xu, “Beyond google play: A large-scale comparative study of chinese android app markets,” in Proceedings of the Internet Measurement Conference 2018 , pp. 293–307, 2018
work page 2018
-
[6]
K. Chen, X. Wang, Y . Chen, P. Wang, Y . Lee, X. Wang, B. Ma, A. Wang, Y . Zhang, and W. Zou, “Following devil’s footprints: Cross-platform analysis of potentially harmful libraries on android and ios,” in 2016 IEEE Symposium on Security and Privacy (SP) , pp. 357–376, IEEE, 2016
work page 2016
-
[7]
Proactive libraries: enforcing correct behaviors in android apps,
O. Riganelli, I. D. Fagadau, D. Micucci, and L. Mariani, “Proactive libraries: enforcing correct behaviors in android apps,” in Proceedings of the ACM/IEEE 44th International Conference on Software Engineering: Companion Proceedings, pp. 159–163, 2022
work page 2022
-
[8]
Why an android app is classified as malware: Toward malware classifi- cation interpretation,
B. Wu, S. Chen, C. Gao, L. Fan, Y . Liu, W. Wen, and M. R. Lyu, “Why an android app is classified as malware: Toward malware classifi- cation interpretation,” ACM Transactions on Software Engineering and Methodology (TOSEM), vol. 30, no. 2, pp. 1–29, 2021
work page 2021
Show all 48 references
-
[9]
Crowdroid: behavior- based malware detection system for android,
I. Burguera, U. Zurutuza, and S. Nadjm-Tehrani, “Crowdroid: behavior- based malware detection system for android,” in Proceedings of the 1st ACM workshop on Security and privacy in smartphones and mobile devices, pp. 15–26, 2011. 14
2011
-
[10]
Riskranker: scal- able and accurate zero-day android malware detection,
M. Grace, Y . Zhou, Q. Zhang, S. Zou, and X. Jiang, “Riskranker: scal- able and accurate zero-day android malware detection,” in Proceedings of the 10th international conference on Mobile systems, applications, and services, pp. 281–294, 2012
2012
-
[11]
“andro- maly
A. Shabtai, U. Kanonov, Y . Elovici, C. Glezer, and Y . Weiss, ““andro- maly”: a behavioral malware detection framework for android devices,” Journal of Intelligent Information Systems , vol. 38, no. 1, pp. 161–190, 2012
2012
-
[12]
Droidmat: Android malware detection through manifest and api calls tracing,
D.-J. Wu, C.-H. Mao, T.-E. Wei, H.-M. Lee, and K.-P. Wu, “Droidmat: Android malware detection through manifest and api calls tracing,” in 2012 Seventh Asia joint conference on information security , pp. 62–69, IEEE, 2012
2012
-
[13]
Droid-sec: deep learning in android malware detection,
Z. Yuan, Y . Lu, Z. Wang, and Y . Xue, “Droid-sec: deep learning in android malware detection,” inProceedings of the 2014 ACM conference on SIGCOMM, pp. 371–372, 2014
2014
-
[14]
An analysis of the privacy and security risks of android vpn permission-enabled apps,
M. Ikram, N. Vallina-Rodriguez, S. Seneviratne, M. A. Kaafar, and V . Paxson, “An analysis of the privacy and security risks of android vpn permission-enabled apps,” in Proceedings of the 2016 internet measurement conference, pp. 349–364, 2016
2016
-
[15]
Share first, ask later (or never?)-studying violations of gdpr’s explicit consent in android apps,
T. T. Nguyen, M. Backes, N. Marnau, and B. Stock, “Share first, ask later (or never?)-studying violations of gdpr’s explicit consent in android apps,” in USENIX Security Symposium , 2021
2021
-
[16]
Mixed signals: Analyzing soft- ware attribution challenges in the android ecosystem,
K. Hageman, Á. Feal, J. Gamba, A. Girish, J. Bleier, M. Lindorfer, J. Tapiador, and N. Vallina-Rodriguez, “Mixed signals: Analyzing soft- ware attribution challenges in the android ecosystem,” IEEE Transac- tions on Software Engineering , 2023
2023
-
[17]
Early detection of spam mobile apps,
S. Seneviratne, A. Seneviratne, M. A. Kaafar, A. Mahanti, and P. Mo- hapatra, “Early detection of spam mobile apps,” in Proceedings of the 24th International Conference on World Wide Web , pp. 949–959, 2015
2015
-
[18]
A longitudinal study of google play,
R. Potharaju, M. Rahman, and B. Carbunar, “A longitudinal study of google play,”IEEE Transactions on computational social systems, vol. 4, no. 3, pp. 135–149, 2017
2017
-
[19]
Update behavior in app markets and security implications: A case study in google play,
A. Möller, F. Michahelles, S. Diewald, L. Roalter, and M. Kranz, “Update behavior in app markets and security implications: A case study in google play,” in Research in the Large, LARGE 3.0: 21/09/2012- 21/09/2012, pp. 3–6, 2012
2012
-
[20]
To update or not to update: Insights from a two-year study of android app evolution,
V . F. Taylor and I. Martinovic, “To update or not to update: Insights from a two-year study of android app evolution,” in Proceedings of the 2017 ACM on Asia Conference on Computer and Communications Security , pp. 45–57, 2017
2017
-
[21]
A longitudinal study of popular ad libraries in the google play store,
M. Ahasanuzzaman, S. Hassan, C.-P. Bezemer, and A. E. Hassan, “A longitudinal study of popular ad libraries in the google play store,” Empirical Software Engineering , vol. 25, pp. 824–858, 2020
2020
-
[22]
Understanding the evolution of mobile app ecosystems: A longitudinal measurement study of google play,
H. Wang, H. Li, and Y . Guo, “Understanding the evolution of mobile app ecosystems: A longitudinal measurement study of google play,” in The World Wide Web Conference, pp. 1988–1999, 2019
1988
-
[23]
Understanding the long- term evolution of mobile app usage,
T. Li, Y . Fan, Y . Li, S. Tarkoma, and P. Hui, “Understanding the long- term evolution of mobile app usage,” IEEE Transactions on Mobile Computing, 2021
2021
-
[24]
Decline in mobile appli- cation life cycle,
A. Vagrani, N. Kumar, and P. V . Ilavarasan, “Decline in mobile appli- cation life cycle,” Procedia Computer Science , vol. 122, pp. 957–964, 2017
2017
-
[25]
Adrob: Examining the landscape and impact of android application plagiarism,
C. Gibler, R. Stevens, J. Crussell, H. Chen, H. Zang, and H. Choi, “Adrob: Examining the landscape and impact of android application plagiarism,” in Proceeding of the 11th annual international conference on Mobile systems, applications, and services , pp. 431–444, 2013
2013
-
[26]
Viewdroid: To- wards obfuscation-resilient mobile application repackaging detection,
F. Zhang, H. Huang, S. Zhu, D. Wu, and P. Liu, “Viewdroid: To- wards obfuscation-resilient mobile application repackaging detection,” in Proceedings of the 2014 ACM conference on Security and privacy in wireless & mobile networks , pp. 25–36, 2014
2014
-
[27]
Android application forensics: A survey of obfuscation, obfuscation detection and deobfuscation techniques and their impact on investigations,
X. Zhang, F. Breitinger, E. Luechinger, and S. O’Shaughnessy, “Android application forensics: A survey of obfuscation, obfuscation detection and deobfuscation techniques and their impact on investigations,” Forensic Science International: Digital Investigation , vol. 39, p. 30...
2021
-
[28]
A multi-modal neural embeddings approach for detecting mobile counterfeit apps: A case study on google play store,
N. Karunanayake, J. Rajasegaran, A. Gunathillake, S. Seneviratne, and G. Jourjon, “A multi-modal neural embeddings approach for detecting mobile counterfeit apps: A case study on google play store,” IEEE Transactions on Mobile Computing , vol. 21, no. 1, pp. 16–30, 2020
2020
-
[30]
Spam mobile apps: Characteristics, detection, and in the wild analysis,
S. Seneviratne, A. Seneviratne, M. A. Kaafar, A. Mahanti, and P. Mo- hapatra, “Spam mobile apps: Characteristics, detection, and in the wild analysis,” ACM Transactions on the Web (TWEB), vol. 11, no. 1, pp. 1– 29, 2017
2017
-
[31]
Stytr2: Image style transfer with transformers,
Y . Deng, F. Tang, W. Dong, C. Ma, X. Pan, L. Wang, and C. Xu, “Stytr2: Image style transfer with transformers,” in Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition , pp. 11326–11336, 2022
2022
-
[32]
An image is worth 16x16 words: Transformers for image recognition at scale,
A. Dosovitskiy, L. Beyer, A. Kolesnikov, D. Weissenborn, X. Zhai, T. Unterthiner, M. Dehghani, M. Minderer, G. Heigold, S. Gelly, et al., “An image is worth 16x16 words: Transformers for image recognition at scale,” arXiv preprint arXiv:2010.11929 , 2020
2010 arXiv
-
[33]
An exploration of encoder- decoder approaches to multi-label classification for legal and biomedical text,
Y . Kementchedjhieva and I. Chalkidis, “An exploration of encoder- decoder approaches to multi-label classification for legal and biomedical text,” arXiv preprint arXiv:2305.05627 , 2023
2023
-
[34]
Mpnet: Masked and permuted pre-training for language understanding,
K. Song, X. Tan, T. Qin, J. Lu, and T.-Y . Liu, “Mpnet: Masked and permuted pre-training for language understanding,” Advances in Neural Information Processing Systems , vol. 33, pp. 16857–16867, 2020
2020
-
[35]
Bert: Pre-training of deep bidirectional transformers for language understanding,
J. Devlin, M.-W. Chang, K. Lee, and K. Toutanova, “Bert: Pre-training of deep bidirectional transformers for language understanding,” arXiv preprint arXiv:1810.04805, 2018
2018 arXiv
-
[36]
Xlnet: Generalized autoregressive pretraining for language understanding,
Z. Yang, Z. Dai, Y . Yang, J. Carbonell, R. R. Salakhutdinov, and Q. V . Le, “Xlnet: Generalized autoregressive pretraining for language understanding,” Advances in neural information processing systems , vol. 32, 2019
2019
-
[37]
Billion-scale similarity search with gpus,
J. Johnson, M. Douze, and H. Jégou, “Billion-scale similarity search with gpus,” IEEE Transactions on Big Data , vol. 7, no. 3, pp. 535–547, 2019
2019
-
[38]
Bayesian Optimization: Open source constrained global optimization tool for Python,
F. Nogueira, “Bayesian Optimization: Open source constrained global optimization tool for Python,” 2014–
2014
-
[39]
Android’s latest statistics 2024: How many people have androids?,
Sam Nguyen, “Android’s latest statistics 2024: How many people have androids?,” September 06, 2023
2024
-
[40]
Android - statistics & facts,
Ahmed Sherif, “Android - statistics & facts,” January 10, 2024
2024
-
[41]
Insights into the 2.3 billion android smartphones in use around the world,
“Insights into the 2.3 billion android smartphones in use around the world,” January 13, 2018
2018
-
[42]
Uno (video game),
“Uno (video game),” 2022. Accessed on May, 2023
2022
-
[43]
Accessed on May, 2023
“Flickr,” 2022. Accessed on May, 2023
2022
-
[44]
App miscat- egorization detection: A case study on google play,
D. Surian, S. Seneviratne, A. Seneviratne, and S. Chawla, “App miscat- egorization detection: A case study on google play,” IEEE Transactions on Knowledge and Data Engineering , vol. 29, no. 8, pp. 1591–1604, 2017
2017
-
[45]
Transfer app to a different developer account,
“Transfer app to a different developer account,” 2023. Accessed on May, 2023
2023
-
[46]
Kiloo - subway surfers wiki
Subway Surfers Wiki, “Kiloo - subway surfers wiki.” Accessed on May, 2023
2023
-
[47]
Uraniborg’s device preloaded app risks scoring metrics,
B. Lau, J. Zhang, A. R. Bereford, D. Thomas, and R. Mayrhofer, “Uraniborg’s device preloaded app risks scoring metrics,” Institute of Networks and Security: Linz, Austria , 2020. Dishanika Denipitiyage received her Bachelors de- gree in Electronic and Telecommunication Enginee...
2020
-
[48]
Before moving into research, he worked nearly six years in the telecommunications industry in core network plan- ning and operations
His current research interests include privacy and security in mobile systems, AI applications in security, and behavior biometrics. Before moving into research, he worked nearly six years in the telecommunications industry in core network plan- ning and operations. He receive...
2005
-
[49]
He received his PhD from the University of Tennessee (USA) in 1995. His research is in data mining and machine learning with a specialization in spatio-temporal data mining, outlier detection, class imbalanced classification, and adversarial learning
1995
Reviewed May 23, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.