{"id":"e8185905-b296-4a49-9742-23330188d39a","arxiv_id":"2607.02627","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":5.5,"correctness_risk":"low","formal_verification":"none","parameter_count":2,"one_line_summary":"A reproducible static-analysis pipeline yields 334k app-version observations of 99k Android apps linked to 246 tracking SDKs and 197 providers, released with code and networks.","lead":"The paper releases a large open dataset linking ~100k Android apps to 246 third-party tracking SDKs and their corporate providers, built via static analysis of AndroZoo APKs with Exodus rules. It enables network studies of software dependencies, concentration, and privacy infrastructure in the mobile ecosystem.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.5","headline":"No significant objection identified beyond the already-flagged static-detection limits.","rationale":"The manuscript is a carefully engineered Data Descriptor whose strongest claim is the construction and open release of a large, documented app–SDK–provider dataset plus reproducible pipeline. That claim is supported by concrete counts, validation tables (processing success 99.998%, metadata merge 100%, provider coverage 100%), external prevalence correlation with Exodus, and public Zenodo/GitHub artifacts. The reader’s weakest_assumption correctly names the principal scientific caveat—static Exodus matching—but the authors already surface it, quantify external agreement, and frame the resource as a high-confidence approximation rather than an exhaustive census. No additional load-bearing flaw (e.g., hidden selection bias that invalidates the released numbers, broken provider mapping, or non-reproducible pipeline) is evident from the full text. Therefore the CONDITIONAL verdict (users must treat detections as approximate and obtain AndroZoo credentials for full reconstruction) remains appropriate; no upgrade or downgrade is warranted.","tokens_in":20688,"tokens_out":515,"duration_ms":4972,"concrete_test":"Independently re-run the released pipeline (or a random 1,000-APK subsample) with an orthogonal detector such as LibRadar/LiteRadar after provider-level aggregation; if the top-20 SDK/provider prevalence ranks or the app-SDK edge density shift by more than ~15% relative to the published Exodus-based figures, the approximation is less reliable for concentration analyses than claimed.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper’s central claim is the existence, scale, and usability of a released app–SDK–provider resource (334k app-version observations, 246 SDKs, provider mapping, bipartite/projected networks), not a causal or theoretical result. The reader correctly isolates the weakest assumption: static namespace/regex matching against Exodus without de-obfuscation or runtime analysis can produce false negatives (obfuscated/dynamic SDKs) and false positives (inactive code), which would bias prevalence, co-occurrence, and concentration statistics. The authors already document this in “Limitations of static SDK detection,” report external plausibility (Pearson 0.874 vs Exodus top trackers), 100% provider-mapping coverage, and internal consistency (zero SDK-count mismatches). No deeper internal inconsistency, circular derivation, or unacknowledged failure mode appears that would undermine the Data Descriptor claim itself.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.5","summary":"This Data Descriptor presents a large-scale open dataset linking Google Play Android apps to embedded third-party tracking SDKs. The authors combine AndroZoo APKs/metadata with Exodus Privacy detection rules in a fully scripted static-analysis pipeline (namespace-prefix and regex matching on DEX bytecode), then map SDKs to operating companies. The released resource covers 334,719 unique app-version observations (99,722 packages), 246 empirically observed SDKs, 197 provider entities, and hundreds of thousands of app–SDK relationships, plus app- and SDK-level metadata. The data support bipartite app–SDK and app–provider networks and their one-mode projections, with public code (GitHub) and frozen data (Zenodo).","tokens_in":20925,"tokens_out":1102,"duration_ms":11003,"significance":"Open, large-scale app–SDK–provider linkage remains scarce relative to proprietary mobile-intelligence products. The contribution is a reusable research infrastructure rather than a novel theoretical result: a reproducible pipeline, a frozen multi-version sample, a carefully documented canonical provider mapping, and ready-to-use network edge lists. Strengths that raise the value of the resource include near-complete processing success (99.998%), 100% metadata merge and provider-mapping coverage after validation, zero internal SDK-count inconsistencies, external prevalence checks against Exodus (Pearson 0.874, substantial top-20 overlap), and full public release of scripts and data (subject to AndroZoo APK redistribution limits). If the static-detection caveats are kept in view, the dataset can support concentration, co-occurrence, privacy-infrastructure, and longitudinal dependency studies that are otherwise hard to reproduce.","major_comments":[{"comment":"Methods, “SDK detection rules” / “Limitations of static SDK detection”: the central usability claim for prevalence, co-occurrence, and concentration analyses rests on static namespace/regex matching against Exodus without de-obfuscation, dynamic loading analysis, or runtime confirmation. The manuscript already flags false negatives (obfuscation/dynamic load) and false positives (inactive code). For a Data Descriptor this is acceptable only if the abstract, Data Records, and network-statistics sections more explicitly frame all reported degrees, densities, and provider concentration figures as upper/lower bounds on observable code presence rather than realized tracking. A short quantitative sensitivity note (e.g., the LiteRadar provider-level overlap already mentioned in a footnote, or a stratified check on heavily obfuscated packages) would make the load-bearing assumption falsifiable ra","section":null},{"comment":"Data Records / Table 6–7 and network construction: package-level aggregation (union of SDKs across versions of the same app) is used for the headline bipartite and projection statistics, while the raw resource preserves multi-version observations. The manuscript should state more clearly which analyses use the union, which use latest-version only, and how multi-version edges are collapsed when computing the 214,421 app–SDK relationships versus the 845,010 app-version–SDK edges. Without that, users can easily mis-specify longitudinal versus cross-sectional concentration measures.","section":null}],"minor_comments":[{"comment":"Abstract vs. body: abstract reports 334,719 unique app-version observations; Background & Technical Validation also cite 334,711 successfully processed APKs and occasional 334,711/99,722 figures. Align the headline counts and define “observation” vs. “successfully processed APK” once in Data Records.","section":null},{"comment":"Table 1 / dex_date: placeholder 1980/1981 dates are correctly flagged; a one-line recommendation on how users should filter temporal snapshots would reduce misuse of Figure 2.","section":null},{"comment":"Table 7: assortativity and clustering for bipartite vs. one-mode projections are reported without stating whether they are computed on weighted or unweighted graphs; a short note would help reproducibility.","section":null},{"comment":"Provider mapping (Table 3–4): ownership is frozen at October 2025. Explicitly label company_canonical as time-stamped and point users to the audit CSV for re-mapping after future acquisitions.","section":null},{"comment":"Sample representativeness (Tables 9–11): free-app over-representation is well explained by the tracking focus; still, state in the abstract or Data Records that the resource is not a monetization-stratified sample of Google Play.","section":null},{"comment":"Minor consistency: “334,719” vs. earlier “334,711” and “845,000” vs. “845,010” appear in different sections; pick one rounding convention for the abstract.","section":null}],"recommendation":"minor_revision","confidential_remarks":"Fit for a Data Descriptor / Scientific Data–style venue is strong. The static-detection limitation is real but already disclosed; I would not treat it as grounds for major revision or reject. No novelty or citation-pattern concerns. Recommend minor revision mainly to tighten framing of what the network statistics measure and to align headline counts."},"author_rebuttal":null,"desk_editor":{"model":"grok-4.5","letter":"This is infrastructure, not a theory paper. What is new is the released artifact: ~335k app-version observations (~100k packages), 246 observed tracking SDKs, a hybrid automated+manual provider canonicalization to ~197 firms, and ready bipartite/projected networks, all with a fully scripted GitHub pipeline and Zenodo dump. Combining AndroZoo APKs with Exodus rules is the natural next step; the scale, the provider mapping, and the network-ready packaging are the actual additions.\n\nThey do the Data Descriptor job carefully. Internal checks are clean (near-100% processing success, zero SDK-count mismatches, 100% provider coverage after mapping). External plausibility against Exodus prevalence (Pearson ~0.87, solid top-20 overlap) and 42matters category/game shares is transparent. Free-app skew and AndroZoo temporal concentration are reported rather than hidden. The math is just bipartite adjacency and standard projections—nothing fancy, nothing broken. Citations sit on AndroZoo, Exodus, and prior SDK work without padding.\n\nThe soft spot is exactly the one the reader and stress-test name: static namespace/regex matching without de-obfuscation or runtime analysis. False negatives (obfuscated/dynamic load) and false positives (dead code) will bias prevalence and co-occurrence. The authors put this in the Limitations section and treat the resource as a high-confidence approximation, not a census. That is proportionate; it does not invalidate the release for concentration or dependency studies that need an open starting graph. Raw APKs stay behind AndroZoo credentials—annoying but not an author failure.\n\nWho it is for: people doing mobile privacy, digital-markets concentration, or software-supply-chain networks who want an open bipartite graph instead of scraping commercial intel. Not for anyone who needs ground-truth runtime tracking. I would send it to peer review; a serious editor should. I would cite the dataset if I needed the graph, and I would put it on a methods/reading-group list for the infrastructure value.","headline":"Solid, usable Data Descriptor: large open app–SDK–provider graph with a real pipeline; static-detection limits are real but already flagged and do not sink the claim.","tokens_in":21536,"tokens_out":522,"would_cite":true,"duration_ms":5969,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.5","headline":"A public dataset of 99,722 Android apps linked to 246 tracking SDKs and their providers, built by static signature matching of APKs.","keywords":["Android apps","third-party SDKs","tracking libraries","static analysis","app-SDK bipartite network","provider concentration","privacy infrastructure","open dataset"],"falsifier":"A large, independently labeled sample of the same APKs in which dynamic or de-obfuscated inspection finds systematically different presence or co-occurrence rates for the top trackers and providers than the static pipeline reports.","tokens_in":21543,"feed_emoji":"📱","tokens_out":636,"duration_ms":5966,"temperature":0.7,"pith_summary":"Most Android apps do not build every feature themselves. They embed third-party software kits for ads, analytics, login, crash reports, and location. Those kits sit inside the app binary, inherit its permissions, and can feed data back to a small set of upstream companies. This paper releases a large open resource that makes those hidden links visible at scale. It pairs hundreds of thousands of app packages with detection rules for tracking SDKs, matches namespaces inside the compiled code, and then maps each SDK to the firm that controls it. The result is both a ready-to-use table of app-version observations and the scripts needed to rebuild bipartite app-SDK networks and firm-level projections. A sympathetic reader cares because the mobile economy’s data and software dependencies have been hard to measure without proprietary scanners; this release turns that layer into a public, reproducible research object.","feed_headline":"99,722 Android apps linked to 246 tracking SDKs","feed_subtitle":"Open tables and code turn hidden third-party dependencies into public network data","key_machinery":"The bipartite app-SDK edge list (and its provider-mapped counterpart) obtained by namespace-prefix and regular-expression matching of APK bytecode against a public tracker rule base, then aggregated into one-mode projections on apps, SDKs, and firms.","core_discovery":"A fully scripted static-analysis pipeline that samples Google Play APKs, extracts Dalvik namespaces, matches them against open tracker rules, and maps detected SDKs to companies yields a released corpus of 334,719 unique app-version observations (99,722 packages), 246 observed tracking SDKs, 197 providers, and more than 845,000 app-SDK relationships, complete with app and SDK metadata that support bipartite and projected network analysis of technological concentration.","pith_inferences":[],"forward_implications":[],"fun_headline_variants":["99,722 apps mapped to 246 third-party SDKs via static analysis","334,719 app versions expose 845k+ SDK dependency links","Open corpus ties Android packages to 246 trackers and 197 firms","Scripted pipeline links Google Play APKs to SDK code signatures","Released tables turn hidden app-SDK ties into network data"],"cache_read_input_tokens":16512,"weakest_assumption_plain":"That matching namespace prefixes and regexes inside APK bytecode against a fixed public tracker list is complete enough for ecosystem statistics, even when code is obfuscated, loaded at runtime, or present but inactive.","fun_headline_variants_meta":{"raw":{"variants":["99,722 apps mapped to 246 third-party SDKs via static analysis","334,719 app versions expose 845k+ SDK dependency links","Open corpus ties Android packages to 246 trackers and 197 firms","Scripted pipeline links Google Play APKs to SDK code signatures","Released tables turn hidden app-SDK ties into network data"]},"model":"grok-4.5","effort":"low","cost_usd":0.006632,"raw_usage":{"total_tokens":1766,"prompt_tokens":847,"num_sources_used":0,"completion_tokens":96,"cost_in_usd_ticks":66320000,"prompt_tokens_details":{"text_tokens":847,"audio_tokens":0,"image_tokens":0,"cached_tokens":384},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":823,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":847,"tokens_out":96,"duration_ms":6723,"temperature":1.0,"reasoning_tokens":823,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-07-12T08:23:49.172091+00:00","model_set":{"reader":"grok-4.5"},"falsifier":"A large, independently labeled sample of the same APKs in which dynamic or de-obfuscated inspection finds systematically different presence or co-occurrence rates for the top trackers and providers than the static pipeline reports.","supporting_citations":[],"review_version":1}