Another big thing about Android is anti-abuse, keeping people from running ad click fraud in apps running on emulators. That is the whole DroidGuard thing that the paper mentions and doesn't explore further. It is a device-specific virtual machine and bytecode for the virtual machine which is intended to authenticate it as a real device, not an emulator.
Anyway check out this slide deck for how Google SRE views mobile as being in their world: https://www.usenix.org/sites/default/files/conference/protec...
PS that team is called MISRE, pronounced "misery" and some of the founders of that team migrated from "SAD SRE" make of that what you will.