The study highlights that mobile applications have become essential tools in the travel and tourism sector, supporting activities such as transportation booking, hotel reservations, navigation, and digital payments. However, behind this convenience lies a growing concern regarding the collection and processing of sensitive user information, including location data, personal identity, contacts, messages, and device storage access.
According to the researchers, excessive permission requests can create privacy risks when applications request access beyond their functional requirements. Applications that collect unnecessary information may become examples of over-privileged applications, where requested permissions exceed what is needed to provide the intended service.
The research combines computational analysis with a cyberlaw perspective to examine whether Android application permissions reflect potential violations of privacy principles. The study uses a dataset containing 28,771 AndroidManifest.xml metadata files obtained from a public dataset repository. These files contain information about permissions requested by Android applications.
The researchers categorized application permissions into several sensitive groups, including:
Personal information access
Location access
Message access
Google account access
System tools permissions
The applications were classified into two categories: Benign (safe applications) and Malware (applications suspected of violating user privacy).
Using the Decision Tree algorithm implemented through RapidMiner, the researchers conducted classification experiments with the 10-Fold Cross Validation method to evaluate model performance. The model generated decision rules that explain why certain permission combinations are associated with potentially harmful applications.
The experimental results showed that the Decision Tree model achieved an overall accuracy of 67.55%. The model successfully detected malware patterns with a high recall value of 93.99%, indicating strong capability in identifying applications suspected of malicious behavior.
However, the model also revealed a significant challenge. The precision and recall results showed that modern malware applications increasingly imitate legitimate applications by using similar permission patterns. As a result, distinguishing between safe and harmful applications based only on static permission analysis remains difficult.
The researchers identified several important permission patterns through the generated IF–THEN decision rules.
One of the most significant findings was the Aggressive Tracking Combination Pattern. Applications requesting permission to monitor network status, access precise GPS location, and modify browser history or bookmarks were classified as potential malware. This combination indicates a high-risk behavior because it allows applications to monitor user activity, track locations, and access browsing information simultaneously.
Another important finding was the Stealth Malware Application Pattern. The model identified applications that appeared to request very limited permissions but were still classified as malware. This suggests that some malicious applications may intentionally avoid requesting obvious dangerous permissions to reduce suspicion from users during installation.
From a cyberlaw perspective, these findings raise concerns regarding compliance with Indonesia’s Law Number 27 of 2022 concerning Personal Data Protection (UU PDP) and the Electronic Information and Transactions Law (UU ITE).
The researchers explain that excessive permission requests may conflict with the principles of data minimization and purpose limitation, which require organizations to collect only personal data necessary for specific and legitimate purposes. When an application requests access to location history, browser activity, or personal information without a clear relationship to its main function, user consent may become questionable because users may not fully understand how their data will be processed.
The study also emphasizes that hidden data collection activities may potentially relate to unauthorized access violations regulated under cyberlaw. Applications that secretly exploit user data despite appearing harmless could represent a serious challenge for digital privacy protection.
“Static permission analysis alone is no longer sufficient as the only mechanism for protecting user privacy. Modern malware can imitate legitimate permission structures, requiring stronger security approaches,” the researchers concluded.
The findings provide practical benefits for several stakeholders. For application users, the study increases awareness about the risks of automatically approving permission requests. For developers, the results encourage the implementation of privacy by design principles, where applications request only necessary permissions. For regulators and cybersecurity professionals, the generated Decision Tree rules can serve as supporting tools for compliance audits and digital security evaluations.
The researchers recommend future studies combine static permission analysis with dynamic security testing methods, such as sandbox-based monitoring of real-time data flows and API activities. Integrating machine learning models with legal compliance frameworks could provide stronger mechanisms for protecting personal data in the rapidly growing mobile application ecosystem.
Author Profiles
Hafiz Rahmad Putra
Researcher from Universitas Bina Sarana Informatika with interests in information technology, cybersecurity, and Android application security analysis.
Guntur Arya Suta
Researcher from Universitas Bina Sarana Informatika focusing on computing, data analysis, and information security.
Dani Izzudiin
Researcher from Universitas Bina Sarana Informatika involved in studies related to information systems and digital technology.
Amalya Patria Ika
Researcher from Universitas Bina Sarana Informatika with research interests in information technology and data analysis.
Besus Maulana Sulthon
Researcher and corresponding author from Universitas Bina Sarana Informatika. His research interests include cybersecurity, data privacy, machine learning, and digital law.
Research Source
Article Title: Classification of Privacy Violations in Android Application Permissions Using Decision Tree and RapidMiner: A Cyberlaw Perspective
Authors: Hafiz Rahmad Putra, Guntur Arya Suta, Dani Izzudiin, Amalya Patria Ika, & Besus Maulana Sulthon
Institution: Universitas Bina Sarana Informatika
Publication Year: 2026
Journal: International Journal of Applied and Scientific Research (IJASR)
E-ISSN: 3025-7670
DOI: https://doi.org/10.59890/ijasr.v4i7.260
Official Journal Website: https://nvlmultitechpublisher.my.id/index.php/ijasr/index
This open-access article is published under the Creative Commons Attribution 4.0 International License and contributes to discussions on cybersecurity, artificial intelligence-based privacy protection, Android application security, and compliance with Indonesia’s digital regulations.
0 Komentar