This is generally taken care of using checksums, assuming you trust the source. Of course, trusting the source is the hard part. CyanogenMod, for example, has a chain of trust for their releases; though they host their own binaries.
I'm not an Android user myself, but I will nevertheless suggest that optimally these things would be distributed as source on GitHub, with a deterministic build system guaranteed to be able to reproduce binaries in the future, and only secondarily as binaries.