Analysis of Privacy Protections in Fitness Tracking Social Networks -or- You can run, but can you hide?
Wajih Ul Hassan, Saad Hussain, Adam Bates
摘要
Mobile fitness tracking apps allow users to track their workouts and share them with friends through online social networks. Although the sharing of personal data is an inherent risk in all social networks, the dangers presented by sharing personal workouts comprised of geospatial and health data may prove especially grave. While fitness apps offer a variety of privacy features, at present it is unclear if these countermeasures are sufficient to thwart a determined attacker, nor is it clear how many of these services' users are at risk. In this work, we perform a systematic analysis of privacy behaviors and threats in fitness tracking social networks. Collecting a month-long snapshot of public posts of a popular fitness tracking service (21 million posts, 3 million users), we observe that 16.5% of users make use of Endpoint Privacy Zones (EPZs), which conceal fitness activity near user-designated sensitive locations (e.g., home, office). We go on to develop an attack against EPZs that infers users' protected locations from the remaining available information in public posts, discovering that 95.1% of moderately active users are at risk of having their protected locations extracted by an attacker. Finally, we consider the efficacy of state-of-the-art privacy mechanisms through adapting geo-indistinguishability techniques as well as developing a novel EPZ fuzzing technique. The affected companies have been notified of the discovered vulnerabilities and at the time of publication have incorporated our proposed countermeasures into their production systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- On (The Lack Of) Location Privacy in Crowdsourcing ApplicationsSpyros Boukoros, Mathias Humbert, Stefan Katzenbeisser, Carmela TroncosoUSENIX Security 2019 · 被引用 28 次
- A Run a Day Won't Keep the Hacker Away: Inference Attacks on Endpoint Privacy Zones in Fitness Tracking Social NetworksKarel Dhondt, Victor Le Pochat, Alexios Voulimeneas, Wouter Joosen 等CCS 2022 · 被引用 11 次
- Swipe Left for Identity Theft: An Analysis of User Data Privacy Risks on Location-based Dating AppsKarel Dhondt, Victor Le Pochat, Yana Dimova, Wouter Joosen 等USENIX Security 2024 · 被引用 4 次
- Everyone's Privacy Matters! An Analysis of Privacy Leakage from Real-World Facial Images on Twitter and Associated User BehaviorsYuqi Niu, Weidong Qiu, Peng Tang, Lifan Wang 等CSCW 2025 · 被引用 3 次
- Watch your Watch: Inferring Personality Traits from Wearable Activity TrackersNoé Zufferey, Mathias Humbert, Romain Tavenard, Kévin HugueninUSENIX Security 2023
它引用的顶会 Paper2
相关 Paper
- Users Can Deduce Sensitive Locations Protected by Privacy Zones on Fitness Tracking AppsJaron Mink, Amanda Rose Yuile, Uma Pal, Adam J. Aviv 等CHI 2022 · 被引用 11 次
- From Options to Action: Evaluating Adoption of Privacy Features in Fitness - Tracking PlatformsPantelina Ioannou, Angeliki Aktypi, Elias AthanasopoulosCHI 2026 · 被引用 1 次
- If This Then What?: Controlling Flows in IoT AppsIulia Bastys, Musard Balliu, Andrei SabelfeldCCS 2018 · 被引用 119 次
- "I'm not as afraid as a woman might be about sharing my exact location: " On the Intersection of Identity and Privacy Concerns in Fitness TrackingYeeun Jo, Mahnoor Jameel, Camille Cobb, Adam BatesCHI 2025 · 被引用 1 次
- Understanding Fitness Tracker Users' Security and Privacy Knowledge, Attitudes and BehavioursSandra Gabriele, Sonia ChiassonCHI 2020 · 被引用 61 次
