裝置端保護措施
透過集合功能整理內容
你可以依據偏好儲存及分類內容。
Google Play 安全防護內建裝置端功能,可協助確保裝置和資料安全無虞。這些裝置端服務會與雲端元件整合,讓 Google 能推送更新,持續提升服務功能。
可能有害的應用程式 (PHA) 掃描服務
Google Play 安全防護會運用雲端應用程式驗證服務,判斷應用程式是否為可能有害的應用程式 (PHA)。Google Play 安全防護會掃描 Android 裝置,找出 PHA 的證據。無論應用程式的下載來源為何,都會檢查裝置上的所有應用程式。
每日 PHA 掃描
Google Play 安全防護每天會掃描裝置一次。如果發現 PHA,通知會要求使用者移除。如果 PHA 對使用者沒有任何好處,Google Play 安全防護可以從受影響的裝置移除 PHA,並封鎖日後的安裝作業。Google Play 安全防護每天會掃描 2,000 億個 Android 應用程式,Google Play 安全防護每天都會掃描裝置,以便快速因應偵測到的威脅,縮短使用者暴露於威脅的時間,並減少受影響的裝置數量。為節省數據用量,這些每日掃描作業只會在偵測到疑似 PHA 時,才與 Google 伺服器聯絡並要求驗證。
雖然 Google Play 安全防護是在背景執行,但使用者可以檢查裝置的上次掃描時間,以及系統掃描的應用程式清單。只要前往 Google Play 應用程式的「Google Play 安全防護」專區即可查看。瞭解如何查看裝置的安全性狀態。
隨選 PHA 掃描
除了系統每日自動執行的簡易掃描以外,使用者隨時都可視需要執行完整裝置掃描。收到要求後,裝置會連線至 Google 伺服器以取得最新資訊,接著掃描裝置上的所有應用程式。如果發現有害應用程式,Google Play 安全防護會通知使用者採取行動,或代表使用者採取行動。這項資訊可讓使用者放心,因為他們隨時都能享有最新防護。
離線掃描可能有害的應用程式
如果裝置離線或網路連線中斷,就可能發生 PHA 安裝作業。為解決這個問題,Google Play 安全防護提供離線掃描功能,可避免裝置在離線時安裝已知 PHA。當離線的裝置重新連上網路後,Play 安全防護便會執行完整掃描。
自動停用 PHA
部分 PHA 比其他 PHA 更具危害性,我們會根據 PHA 分類採取不同的處理方式。系統會自動從裝置中移除最有害的 PHA,並停用危害程度較輕微的 PHA。停用的應用程式無法使用,但仍會保留在裝置上,且與應用程式相關聯的資料可以復原。應用程式自動停用時,使用者會收到通知,並可選擇移除或重新啟用應用程式。如未採取任何行動,應用程式將維持停用狀態。
為非透過 Google Play 安裝的應用程式提供即時防護
Google Play 安全防護機制可保護從 Google Play 以外來源安裝的應用程式。使用者嘗試安裝應用程式時,Play 安全防護會根據 Google Play 安全防護編目的已知有害或惡意樣本,即時檢查應用程式。裝置上的機器學習、相似度比較和其他技術也會檢查應用程式,確認是否可疑。如果應用程式遭判定為惡意或可疑,我們會向使用者發出警告,在極端情況下則會禁止安裝。
Google Play 安全防護也會針對先前未掃描過的新興威脅提供防護。如果 Play 安全防護未從收集的樣本中偵測到任何惡意程式碼,系統會建議對應用程式執行程式碼層級的即時掃描,擷取重要信號供 Google 評估。這有助於防範可能經過變造而躲避偵測的新型惡意應用程式。如果使用者同意掃描應用程式,系統會將應用程式資料上傳至 Google 進行分析。不久後,Play 安全防護就會通知使用者,應用程式能否安心安裝或可能有害。
申訴
您可以對應用程式遭到 Google Play 下架的處置提出申訴。如果我們查明您的應用程式並未違反《Google Play 開發人員計畫政策》和《開發人員發行協議》,並確認先前的處置有誤,就會在適當的情況下讓您的應用程式重新上架。
詳情請參閱「我的應用程式已經從 Google Play 下架」一文。
這個頁面中的內容和程式碼範例均受《內容授權》中的授權所規範。Java 與 OpenJDK 是 Oracle 和/或其關係企業的商標或註冊商標。
上次更新時間:2025-08-16 (世界標準時間)。
[null,null,["上次更新時間:2025-08-16 (世界標準時間)。"],[[["\u003cp\u003eGoogle Play Protect safeguards devices and data with on-device and cloud-based security measures, including daily scans of 125 billion apps to detect and remove Potentially Harmful Applications (PHAs).\u003c/p\u003e\n"],["\u003cp\u003eUsers have the option to initiate on-demand full-device scans for immediate security checks and can view their device's security status in the Google Play app.\u003c/p\u003e\n"],["\u003cp\u003eReal-time protection is provided for apps installed from sources outside of Google Play, using machine learning and code-level scanning to identify and block potential threats.\u003c/p\u003e\n"],["\u003cp\u003eGoogle Play Protect offers offline scanning capabilities to prevent known PHAs from being installed even without network connectivity, ensuring continuous protection.\u003c/p\u003e\n"],["\u003cp\u003eDevelopers can utilize the Play Integrity API to check device compatibility with Google Play Protect and identify potential PHAs, enhancing app security and user trust.\u003c/p\u003e\n"]]],["Google Play Protect scans devices for Potentially Harmful Applications (PHAs) daily, checking all apps regardless of the download source. It can remove severe PHAs or disable less harmful ones, notifying users of actions taken. Users can initiate full-device scans anytime. Offline scanning prevents known PHA installations, with full scans upon reconnection. Real-time checks are performed on non-Play Store installs using machine learning and other methods. New app protections trigger code-level scans. The Play Integrity API allows developers to verify device and app integrity.\n"],null,["# On-device protections\n\nGoogle Play Protect includes on-device capabilities that help keep devices\nand data safe. These on-device services integrate with cloud-based components\nthat allow Google to push updates that constantly improve their\nfunctionality.\n\nPHA scanning services\n---------------------\n\nGoogle Play Protect leverages cloud-based app-verification services to\ndetermine if apps are Potentially Harmful Applications (PHAs). Google Play\nProtect scans Android devices for evidence of PHAs. It checks all apps on a\ndevice, regardless of where the app was downloaded.\n\n### Daily PHA scan\n\nGoogle Play Protect scans devices once everyday. If a PHA is found, a\nnotification asks the user to remove it. In cases where the PHA has no benefit\nto users, Google Play Protect can remove the PHA from affected devices and block\nfuture installs. Google Play Protect scans 200 billion Android apps every day. Daily\nscanning allows Google Play Protect to respond quickly to a detected threat,\nreducing how long users could be exposed to the threat and how many devices may\nbe affected. To conserve data, these daily scans only contact Google servers to\nrequest verification when a suspected PHA is detected.\n\nThough Google Play Protect works in the background, users can check when\ntheir device was last scanned and view the list of scanned apps in the Google\nPlay Protect section of their Google Play app. [Learn how to check your\ndevice's security status.](https://support.google.com/android/answer/2812853)\n\n### On-demand PHA scan\n\nIn addition to a lightweight, daily, automatic scan, users can start a\nfull-device scan at any time. Upon request, the device contacts Google servers\nfor the latest information and scans all apps on the device. If a harmful app is\ndiscovered, Google Play Protect notifies the user to take action or takes action\non their behalf. This visibility gives users peace of mind that they have the\nlatest protection at all times.\n\n### Offline PHA scan\n\nPHA installations can occur when a device is offline or has lost network\nconnectivity. To address this, Google Play Protect has offline scanning, which\nhelps prevent well-known PHAs from being installed offline. When the device\nregains network connectivity, it undergoes a full scan.\n\n### Automatically disable PHAs\n\nSome PHAs are more harmful than others and we treat them differently\ndepending on the PHA classification. The most harmful PHAs are automatically\nremoved from the device, while less severe PHAs are disabled. A disabled app is\nunusable but remains on the device, and any data associated with the app is\nrecoverable. When an app is automatically disabled, users are notified and can\nmake the decision to remove the app or re-enable it to make it usable again. If\nno action is taken, the app remains disabled.\n\n### Real-time protections for non-Play installs\n\nGoogle Play Protect offers protection for apps that are installed\nfrom sources outside of Google Play. When a user tries to install an\napp, Play Protect conducts a real-time check of the app against known\nharmful or malicious samples that Google Play Protect has cataloged..\nThe app is also checked by on-device machine learning, similarity\ncomparisons and other techniques to confirm if it's suspicious. If\nthe app is identified as malicious or suspicious, we will warn users\nor block the installation in extreme cases.\n\nGoogle Play Protect also offers new protections for emerging threats\nthat were previously not scanned before. When Play Protect does not\nrecognize any malicious code from the collected samples, it recommends a real-time\ncode-level scan of the app to extract important signals for\nevaluation by Google. This helps combat novel malicious apps that may\nhave been altered to avoid detection. If a user agrees to scan the\napp, they will upload the app data to Google for analysis. A short\ntime later, Play Protect will let users know if the app appears safe\nto install or is potentially harmful.\n\nAppeals\n-------\n\nYou can appeal your app's removal from Google Play. We will reinstate apps in\nappropriate circumstances, including if an error was made and we find that your\napp does not violate the Google Play [Developer Program\nPolicies](https://play.google.com/about/developer-content-policy/) and [Developer\nDistribution Agreement](https://play.google.com/about/developer-distribution-agreement.html).\n\nFor more information see, [My\napp has been removed from Google Play](https://support.google.com/googleplay/android-developer/answer/2477981)."]]