Navigating Developers' Quagmire: LLM-Enabled Privacy Compliance Analysis for SDK Integrations
Zhaojie Hu, Xueqiang Wang
Abstract
The use of third-party SDKs has become a major source of privacy noncompliance in mobile apps, creating an urgent need for app developers to ensure privacy compliance during SDK integrations. However, existing methods for identifying privacy-noncompliant SDK integrations (PINs) largely rely on predefined noncompliance patterns based on externally observable app behaviors. These methods are limited in their ability to systematically detect PINs due to the lack of generic detection, and in providing concrete development guidance for app developers on SDK integrations due to limited visibility into the SDK integration context. To overcome these limitations, we introduce a new PIN detection paradigm using privacy-contextual consistency analysis, based on a key observation: PINs often manifest as inconsistencies between the privacy implications of SDK APIs and the context of their integrations, which allow for generic, PIN-independent checks. This study takes the first step in validating the feasibility of the new detection paradigm. We first establish the knowledge foundation for this paradigm by defining models that capture API privacy implications, privacy context, and generic consistency analysis rules that describe the proper use and implementation of SDK APIs. Based on the models, we develop an automated framework, PINFINDER, to detect PINs arising from SDK integrations in Android apps – software known for its extensive use of SDKs. The framework combines app analysis techniques for extracting SDK APIs and privacy context, along with large language models (LLMs) for understanding and analyzing privacy-contextual inconsistencies, and targeted enhancements to increase the feasibility of LLMenabled consistency analysis. Our evaluation confirms the effectiveness and coverage of PINFINDER in detecting PINs. Running PINFINDER on 4,683 real-world apps further sheds light on the prevalence and magnitude of PINs, revealing lesser-known manifestations and their underlying causes. These causes highlight the need for greater standardization in SDK integration API design and improved transparency regarding their privacy implications.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get cc1270fc-dabb-47a5-acae-69de3daabe70Related papers
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong et al.USENIX Security 2024 · 3 citations
- Tinker, Tailor, Trust: How Developers Create Privacy Policies With and Without AIShiva Mayahi, Noura Alomar, Nathan MalkinCHI 2026 · 1 citation
- Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device FingerprintingMichael A. Specter, Mihai Christodorescu, Abbie Farr, Bo Ma et al.CCS 2025
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie et al.USENIX Security 2024 · 6 citations
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
