PP-CSA: Practical Privacy-Preserving Software Call Stack Analysis
Zhaoyu Wang, Pingchuan Ma, Huaijin Wang, Shuai Wang
Abstract
Software call stack is a sequence of function calls that are executed during the runtime of a software program. Software call stack analysis (CSA) is widely used in software engineering to analyze the runtime behavior of software, which can be used to optimize the software performance, identify bugs, and profile the software. Despite the benefits of CSA, it has recently come under scrutiny due to concerns about privacy. To date, software is often deployed at user-side devices like mobile phones and smart watches. The collected call stacks may thus contain privacy-sensitive information, such as healthy information or locations, depending on the software functionality. Leaking such information to third parties may cause serious privacy concerns such as discrimination and targeted advertisement. This paper presents PP-CSA, a practical and privacy-preserving CSA framework that can be deployed in real-world scenarios. Our framework leverages local differential privacy (LDP) as a principled privacy guarantee, to mutate the collected call stacks and protect the privacy of individual users. Furthermore, we propose several key design principles and optimizations in the technical pipeline of PP-CSA, including an encoder-decoder scheme to properly enforce LDP over software call stacks, and several client/server-side optimizations to largely improve the efficiency of PP-CSA. Our evaluation over real-world Java and Android programs shows that our privacy-preserving CSA pipeline can achieve high utility and privacy guarantees while maintaining high efficiency. We have released our implementation of PP-CSA as an open-source project at https://github.com/wangzhaoyu07/PP-CSA for results reproducibility. We will provide more detailed documents to support and the usage and extension of the community.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 7d7aef35-8cdd-4822-9fb1-49705ab98951Cited by top-tier papers2
- Preserving Privacy in Software Composition Analysis: A Study of Technical Solutions and EnhancementsHuaijin Wang, Zhibo Liu, Yanbo Dai, Shuai Wang et al.ICSE 2025 · 2 citations
- Protecting Source Code Privacy When Hunting Memory BugsJielun Wu, Bing Shui, Hongcheng Fan, Shengxin Wu et al.ASE 2025
Related papers
- Differentially-private software frequency profiling under linear constraintsHailong Zhang, Yu Hao, Sufian Latif, Raef Bassily et al.OOPSLA 2020 · 1 citation
- Real-Time Trajectory Synthesis with Local Differential PrivacyYujia Hu, Yuntao Du, Zhikun Zhang, Ziquan Fang et al.ICDE 2024 · 20 citations
- Differentially-Private Control-Flow Node Coverage for Software Usage AnalysisHailong Zhang, Sufian Latif, Raef Bassily, Atanas RountevUSENIX Security 2020
- Otus: A Gaze Model-based Privacy Control Framework for Eye Tracking ApplicationsMiao Hu, Zhenxiao Luo, Yipeng Zhou, Xuezheng Liu et al.INFOCOM 2022 · 8 citations
- "I inherently just trust that it works": Investigating Mental Models of Open-Source Libraries for Differential PrivacyPatrick Song, Jayshree Sarathy, Michael Shoemate, Salil P. VadhanCSCW 2024 · 1 citation
