USENIX Security2022Top-tier venue
FOAP: Fine-Grained Open-World Android App Fingerprinting
Jianfeng Li, Hao Zhou, Shuohan Wu, Xiapu Luo, Ting Wang, Xian Zhan, Xiaobo Ma
Abstract
Despite the widespread adoption of encrypted communication for mobile apps, adversaries can still identify apps or infer selected user activities of interest from encrypted mobile traffic via app fingerprinting (AF) attacks. However, most existing AF techniques only work under the closed-world assumption, thereby suffering potential precision decline when faced with apps unseen during model training. Moreover, serious privacy leakage often occurs when users conduct some sensitive operations, which are closely associated with specific UI components. Unfortunately, existing AF techniques are too coarse-grained to acquire such fine-grained sensitive information. In this paper, we take the first step to identify method-level fine-grained user action of Android apps in the open-world setting and present a systematic solution, dubbed FOAP, to address the above limitations. First, to effectively reduce false positive risks in the open-world setting, we propose a novel metric, named structural similarity, to adaptively filter out traffic segments irrelevant to the app of interest. Second, FOAP achieves fine-grained user action identification via synthesizing traffic and binary analysis. Specifically, FOAP identifies user actions on specific UI components through inferring entry point methods correlated with them. Extensive evaluations and case studies demonstrate that FOAP is not only reasonably accurate but also practical in fine-grained user activity inference and user privacy analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b76aee9e-9910-40e7-b466-0d764778694bCited by top-tier papers10
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- XPorter: A Study of the Multi-Port Charger Security on Privacy Leakage and Voice InjectionTao Ni, Yongliang Chen, Weitao Xu, Lei Xue et al.MobiCom 2023 · 15 citations
- WiFinger: Fingerprinting Noisy IoT Event Traffic Using Packet-level Sequence MatchingRonghua Li, Shinan Liu, Haibo Hu, Qingqing Ye et al.NDSS 2026 · 6 citations
- Eavesdropping Mobile App Activity via Radio-Frequency Energy HarvestingTao Ni, Guohao Lan, Jia Wang, Qingchuan Zhao et al.USENIX Security 2023
- Time Tells All: Deanonymization of Blockchain RPC Users with Zero Transaction FeeShan Wang, Ming Yang, Yu Liu, Yue Zhang et al.CCS 2025
Builds on13
- Deep Fingerprinting: Undermining Website Fingerprinting Defenses with Deep LearningPayap Sirinam, Mohsen Imani, Marc Juarez, Matthew WrightCCS 2018 · 632 citations
- Website Fingerprinting at Internet ScaleAndriy Panchenko, Fabian Lanze, Jan Pennekamp, Thomas Engel et al.NDSS 2016 · 625 citations
- k-fingerprinting: A Robust Scalable Website Fingerprinting TechniqueJamie Hayes, George DanezisUSENIX Security 2016 · 474 citations
- Automated Website Fingerprinting through Deep LearningVera Rimmer, Davy Preuveneers, Marc Juarez, Tom van Goethem et al.NDSS 2018 · 399 citations
- Triplet Fingerprinting: More Practical and Portable Website Fingerprinting with N-shot LearningPayap Sirinam, Nate Mathews, Mohammad Saidur Rahman, Matthew WrightCCS 2019 · 268 citations
Related papers
- Packet-Level Open-World App Fingerprinting on Wireless TrafficJianfeng Li, Shuohan Wu, Hao Zhou, Xiapu Luo et al.NDSS 2022
- FlowPrint: Semi-Supervised Mobile-App Fingerprinting on Encrypted Network TrafficThijs van Ede, Riccardo Bortolameotti, Andrea Continella, Jingjing Ren et al.NDSS 2020
- WhisperCatcher: Demystifying Unauthorized and Encrypted Private Data Transmission in Android ApplicationsZhaoyu Qiu, Ming Fan, Bocan Ma, Yutian Tang et al.ICSE 2026
- DocFlow: Extracting Taint Specifications from Software DocumentationMarcos Tileria, Jorge Blasco, Santanu Kumar DashICSE 2024 · 5 citations
- Obfuscation-Resilient Privacy Leak Detection for Mobile Apps Through Differential AnalysisAndrea Continella, Yanick Fratantonio, Martina Lindorfer, Alessandro Puccetti et al.NDSS 2017 · 131 citations
