Skip to main navigation Skip to search Skip to main content

Detecting and Measuring Aggressive Location Harvesting in Mobile Apps via Data-flow Path Embedding

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

Today, location-based services have become prevalent in the mobile platform, where mobile apps provide specific services to a user based on his or her location. Unfortunately, mobile apps can aggressively harvest location data with much higher accuracy and frequency than they need because the coarse-grained access control mechanism currently implemented in mobile operating systems (e.g., Android) cannot regulate such behavior. This unnecessary data collection violates the data minimization policy, yet no previous studies have investigated privacy violations from this perspective, and existing techniques are insufficient to address this violation. To fill this knowledge gap, we take the first step toward detecting and measuring this privacy risk in mobile apps at scale. Particularly, we annotate and release the first dataset to characterize those aggressive location harvesting apps and understand the challenges of automatic detection and classification. Next, we present a novel system, LocationScope, to address these challenges by (i) uncovering how an app collects locations and how to use such data through a fine-Tuned value set analysis technique, (ii) recognizing the fine-grained location-based services an app provides via embedding data-flow paths, which is a combination of program analysis and machine learning techniques, extracted from its location data usages, and (iii) identifying aggressive apps with an outlier detection technique achieving a precision of 97% in aggressive app detection. Our technique has further been applied to millions of free Android apps from Google Play as of 2019 and 2021. Highlights of our measurements on detected aggressive apps include their growing trend from 2019 to 2021 and the app generators' significant contribution of aggressive location harvesting apps. © 2023 Owner/Author.
Original languageEnglish
Title of host publicationSIGMETRICS '23 Abstracts - Abstract Proceedings of the 2023 ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems
Place of PublicationNew York, NY
PublisherAssociation for Computing Machinery
Pages45-46
ISBN (Print)9798400700743
DOIs
Publication statusPublished - 2023
Event8th ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems (SIGMETRICS 2023) - Orlando, United States
Duration: 19 Jun 202323 Jun 2023

Publication series

NameSIGMETRICS - Abstract Proceedings of the ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems

Conference

Conference8th ACM SIGMETRICS International Conference on Measurement and Modeling of Computer Systems (SIGMETRICS 2023)
Abbreviated titleACM SIGMETRICS 2023
PlaceUnited States
CityOrlando
Period19/06/2323/06/23

Funding

We thank our shepherd Dr. Luoyi Fu and anonymous reviewers for their insightful and constructive comments. This work was partly supported by NSF awards 2112471, 1850725, CityU APRC grant 9610563, and CityU SRG-Fd grant 7005853. Any opinions, findings, and conclusions in this paper are those of the authors and do not necessarily reflect the views of the supported organizations.

Research Keywords

  • aggressive location harvesting
  • location privacy
  • location-based service

Fingerprint

Dive into the research topics of 'Detecting and Measuring Aggressive Location Harvesting in Mobile Apps via Data-flow Path Embedding'. Together they form a unique fingerprint.

Cite this