Withdrawing is believing? Detecting Inconsistencies between Withdrawal Choices and Third-party Data Collections in Mobile Apps
Xiaolin Du, Zhemin Yang, Jiapeng Lin, Yinzhi Cao, Min Yang
摘要
Popular privacy regulations such as General Data Protection Regulation (GDPR) often allow consumers to withdraw from providing data, e.g., the famous right to opt-out. Modern computer software, e.g., mobile applications (apps), often provide withdrawal interfaces, which stop data collection— e.g., from third-party ads and analytics libraries—to respect users’ withdrawal decisions. While such interfaces are marked as "withdrawal", their correlated withdrawal decisions are often inconsistent with the apps’ actual data collection behavior, especially from third parties, which is defined as withdrawal inconsistency in the paper.Prior works have either studied website withdrawal inconsistency or privacy leaks of mobile apps. However, the mobile withdrawal inconsistency problem is different yet more complex than those in websites due to the diversity in mobile withdrawal interface and the variety of private information. At the same time, none of the existing works detecting privacy leaks of mobile apps understand users’ withdrawal decisions let alone correlate them with withdrawal behaviors.In this paper, we design and implement a novel approach, called MowChecker, to detect mobile apps’ inconsistencies in third-party data collection. The key insight is that withdrawal choices should have either a control-flow dependency on personal information flow or a data-flow dependency on withdrawal APIs provided by third-party data collection libraries. Our evaluation of MowChecker on real-world Android apps reveals 157 manually-confirmed, zero-day withdrawal inconsistencies. We have responsibly reported them to app developers and received 23 responses with two being fixed.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Abandon All Hope Ye Who Enter Here: A Dynamic, Longitudinal Investigation of Android's Data Safety SectionIoannis Arkalakis, Michalis Diamantaris, Serafeim Moustakas, Sotiris Ioannidis 等USENIX Security 2024 · 被引用 13 次
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong 等USENIX Security 2024 · 被引用 3 次
- Setting the Course, but Forgetting to Steer: Analyzing Compliance with GDPR's Right of Access to Data by Instagram, TikTok, and YoutubeSai Keerthana Karnam, Abhisek Dash, Antariksh Das, Sepehr Mousavi 等S&P 2026 · 被引用 3 次
- Breaking the Illusion: Automated Reasoning of GDPR Consent ViolationsYing Li, Wenjun Qiu, Faysal Hossain Shezan, Kunlin Cai 等S&P 2026 · 被引用 1 次
- I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-appsYifeng Cai, Ziqi Zhang, Mengyu Yao, Junlin Liu 等USENIX Security 2025
它引用的顶会 Paper19
- Dark Patterns after the GDPR: Scraping Consent Pop-ups and Demonstrating their InfluenceMidas Nouwens, Ilaria Liccardi, Michael Veale, David R. Karger 等CHI 2020 · 被引用 491 次
- (Un)informed Consent: Studying GDPR Consent Notices in the FieldChristine Utz, Martin Degeling, Sascha Fahl, Florian Schaub 等CCS 2019 · 被引用 429 次
- Apps, Trackers, Privacy, and Regulators: A Global Study of the Mobile Tracking EcosystemAbbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan 等NDSS 2018 · 被引用 271 次
- Do Cookie Banners Respect my Choice? : Measuring Legal Compliance of Banners from IAB Europe's Transparency and Consent FrameworkCélestin Matte, Nataliia Bielova, Cristiana Teixeira SantosS&P 2020 · 被引用 212 次
- TaintART: A Practical Multi-level Information-Flow Tracking System for Android RunTimeMingshen Sun, Tao Wei, John C. S. LuiCCS 2016 · 被引用 188 次
相关 Paper
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 被引用 20 次
- Do Opt-Outs Really Opt Me Out?Duc Bui, Brian Tang, Kang G. ShinCCS 2022 · 被引用 9 次
- Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheckBenjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck 等USENIX Security 2020
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 被引用 32 次
- Demystifying Privacy Policy of Third-Party Libraries in Mobile AppsKaifa Zhao, Xian Zhan, Le Yu, Shiyao Zhou 等ICSE 2023 · 被引用 22 次
