REVIEW 3 major objections 6 minor 71 references
Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device Fingerprinting
T0 review · 3 major / 6 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read Advertising SDKs account for only about 30 percent of likely fingerprinting behavior in mobile apps, so privacy rules that target ads alone cover less than a third of the problem.
desk verdict A careful, large-scale measurement of fingerprinting-like SDK behavior whose headline market shares are honestly caveated but remain seed-dependent point estimates. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central mechanism is a seed-set threshold static analysis pipeline. The paper starts with 14 SDKs that openly advertise fingerprinting, manually reverse-engineers them to extract 504 unique exfiltrated signals, then uses a taint-flow analysis (called CoFlow) to flag any SDK that sends at least 20 such signals (the minimum observed in the seed set) to a common sink, either a network API or an encryption function. This yields the Extended Set of 723 fingerprinting-like SDK families, which are then labeled by a team of coders into five purpose categories. The machinery operationalizes fingerprinting behavior as exfiltrating more device signals than a self-confessed fingerprinter does, rather than relying on stated intent.
What would settle it
Run the same pipeline with a seed set that includes advertising SDKs that openly admit to fingerprinting; if those SDKs exfiltrate meaningful numbers of signals absent from the current 504-signal vocabulary, the Extended Set composition and the 30.56% Ads share would shift, undermining the conclusion that ad-targeted interventions cover under a third of fingerprinters.
Extended reading notes
Core claim
The central claim is that the fingerprinting ecosystem is broader and more opaque than previous work suggested: of 723 SDK families that exfiltrate at least as many device signals as the least-collecting self-identified fingerprinting SDK, only 221 (30.56%) are advertising SDKs, while 173 (23.92%) have unknown or unclear purpose, 167 are tools or other, 85 are security and authentication, and 77 are analytics. The paper also discovers that the signal space is sparse: only 2% of exfiltrated APIs are shared by more than 75% of likely fingerprinting SDKs, so no small set of permissions or APIs can cleanly separate fingerprinters from legitimate libraries. It further finds that fingerprinting SDKs are disproportionately popular, with roughly 10 times more installs than non-fingerprinting alternatives, and that a user installing a popular app in categories like comics, games, or dating has an 80+% chance of encountering one.
Load-bearing premise
The whole measurement rests on the assumption that the 14 self-identifying fingerprinting SDKs, which are all security or anti-fraud products and none of which is an advertising SDK, use signal types representative of every SDK that fingerprints, so an SDK is only counted once it exfiltrates signals from that vocabulary.
Editorial extensions
If this is right
- Industry anti-tracking interventions that apply only to advertising SDKs, such as app tracking transparency and privacy sandbox rules, would leave out roughly two-thirds of SDK families that exhibit fingerprinting-like behavior.
- The large Unclear/Not Found share (23.92%) means current SDK metadata is too sparse for policy enforcement, and behavioral analysis alone cannot determine purpose; out-of-band labeling is needed.
- Permission- or API-based defenses are likely to be brittle: because signals are sparse and diverse, blocking a handful of APIs would push fingerprinters to other entropy sources, and only 2% of APIs are used by more than 75% of likely fingerprinting SDKs.
- Since likely fingerprinting SDKs are disproportionately popular (about 10x more installs), users of popular apps, especially in games, dating, and comics, have a high probability (80+%) of being exposed to device fingerprinting.
- If advertising and security/authentication SDKs cannot be reliably separated by their exfiltrated signals (as the visualization suggests), automatic enforcement that tries to allow anti-fraud tracking while blocking ad tracking will require classifiers beyond simple permissions.
Reading between the lines
- A direct extension of this result is that the same market composition likely holds on other mobile platforms, because every seed SDK has an iOS version; this would mean privacy rules on iOS also miss the unknown-SDK share.
- The concentration of fingerprinting in analytics and tools suggests that privacy-preserving alternatives for analytics, such as differential privacy or on-device aggregation, could reduce the need to collect raw device signals.
- A testable extension would weight the 504 signals by their actual entropy or uniqueness; doing so could either raise or lower the count of likely fingerprinters and shift the category shares.
- The sparse-signal finding implies that defenses relying on known fingerprinting API patterns could be evaded by choosing less common signal combinations, so a robust defense would need to reason about the joint entropy of collected data.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper presents a large-scale empirical study of device-fingerprinting behavior in Android SDKs. The authors collect 228,598 SDKs from Maven repositories and 178,054 active Google Play apps, manually identify 14 self-declared fingerprinting SDKs (the Seed Set) and extract the 504 distinct signals they exfiltrate, then use a static taint/CoFlow analysis to detect SDKs that exfiltrate at least as many signals as the weakest Seed Set member (about 20) to a common network sink, producing an Extended Set of 723 SDK families. These are manually labeled (Ads, Analytics, Security/Authentication, Tools/Other, Unclear/Not Found) with a Krippendorff's alpha of 0.804. The headline finding is that Ads SDKs account for only 30.56% of the likely-fingerprinting SDK families, while 23.92% come from SDKs whose purpose is unknown or unclear; this motivates the policy conclusion that advertising-focused interventions such as ATT and Privacy Sandbox may address well under a third of fingerprinting behavior. The paper also reports app-category prevalence, cross-app sharing of fingerprinting SDKs, and signal sparsity.
Significance. If the headline shares are accurate, the paper makes a substantial empirical contribution: it is the largest SDK-level measurement of fingerprinting-like behavior to date and provides the first market-composition breakdown showing that fingerprinting extends well beyond advertising SDKs. The methodology has real strengths: two-analyst manual verification of the seed SDKs, a deliberately conservative inclusion threshold framed as an upper-bar estimate, inter-rater reliability of 0.804 for labeling, and a systematic evaluation of the app-SDK matcher with ground truth (99.89% precision at 46.16% recall on a restricted set). The detailed appendices describing the taint analysis, CoFlow detection, SDK-matching algorithm, and codebook are a useful resource for replication and follow-up work. The central policy conclusion, however, depends on the representativeness of the 14-SDK seed set and the stability of the resulting Extended Set; these are not yet demonstrated with sensitivity analysis, so the quantitative shares should be treated as provisional.
major comments (3)
- [§3.2–§3.3 / Figure 4 / Abstract] The headline market-composition claim (Ads 30.56%, Unclear 23.92%) is computed from an Extended Set defined entirely by the 504-signal vocabulary manually extracted from 14 Seed Set SDKs, none of which is an advertising SDK (Table 2). The detection pipeline recognizes only exfiltration of these seed-derived signals, so any ad SDK that fingerprints using a different signal set (e.g., app-usage timing, sensor contexts, or ad-identifier-related attributes not in the seed list) cannot be included in the Extended Set. The paper itself concedes this in §5.1: 'It may be that SDKs that fingerprint for hidden reasons use alternative techniques, which would not be caught in our later analyses.' No sensitivity analysis is reported, so the 30.56% point estimate has no quantified uncertainty. A concrete test would be to add several well-known advertising SDKs to the seed set, re-run signal extraction and CoFlow detection, and report how the category shares shift; at a minimum, the authors should report the share range as the inclusion threshold varies around the 20-signal cutoff. Without this, the abstract's conclusion that advertising-focused interventions reach under a third of fingerprinting SDKs is not yet supported.
- [§3.3 / Appendix B (Fingerprinting Detection)] The CoFlow-based fingerprinting detector that produces the Extended Set is not validated against ground-truth labels on the wider SDK corpus. The authors manually verified only the 14 Seed Set SDKs; no precision/recall evaluation is reported for the detector's classification of the remaining 228,000+ SDKs, even though all of RQ2 and the market-share percentages depend on that classification. The paper calls the approach 'conservative' and an 'upper-bar estimate,' but a conservative threshold does not by itself establish that the 723-family Extended Set is not substantially contaminated by false positives or missing many true fingerprinters. I recommend manually labeling a random sample of Extended Set and non-Extended Set SDK families (or otherwise constructing a validation set) and reporting detector precision and recall, together with the distribution of N (the number of flows reaching a sink). This would also ground the claim that the pipeline provides an upper bar for the set of fingerprinting-like SDKs.
- [§4.3 / Appendix C / Figures 6 and 7] The app-level prevalence results (e.g., 39.4% of apps in a category contain a fingerprinting SDK; cross-category sharing probabilities) rest on the SDK-matching algorithm whose published evaluation shows 99.89% precision at 46.16% recall on the restricted 9,683-SDK set, and 65.07% average precision on the larger 302,397-SDK set. The paper correctly describes these as lower bounds, but the magnitude of the undercount is not quantified: a 46% recall on the restricted set implies that the true market reach of fingerprinting SDKs could be substantially higher than the reported 3.2%–10% app prevalence and the cross-app sharing probabilities could be materially understated. I would like the authors to either report recall and precision stratified by SDK category (e.g., for Ads vs. Unclear SDKs) or provide a calibrated correction factor that turns the lower bound into a range. This issue is load-bearing for RQ3, which is one of the paper's three stated research questions, even if it is secondary to the RQ2 market-composition claim.
minor comments (6)
- [Abstract / §1] The abstract and §1 say 'at least 20 signals exfiltrated per SDK,' but §3.3 states the criterion is 'more than the lowest number of signals collected by any SDK in our Seed Set' (i.e., more than 20). Please make the threshold wording consistent (strictly greater vs. at least).
- [§3.1] The text says the crawl covered '9 separate large-scale Maven repositories' but lists only eight names: JCenter, Maven Central, Google, Sonatype, Spring.io, Jitpack, Bintray, and Artifactory. Please add the missing repository or correct the count.
- [Table 2] The table lists 'ThreatMetrix (Lexus Nexus)' — the company name is LexisNexis. Please correct the spelling.
- [§4.2] The sentence 'Only only 6.15% record account-list signals' contains a duplicated 'only.' Please fix the typo.
- [§5.1 / External validity] The phrase 'our choice of actual SDKs from popular Maven repositories and mobile apps from the Google Play store ensure minimize this risk' is ungrammatical; likely 'ensure we minimize' or 'help minimize' was intended.
- [§4.2 / Figure 5] The t-SNE interpretation (e.g., 'the right third of the t-SNE plot contains most of the Security and Authentication SDKs') is based on a stochastic embedding with a single run; please report at least the stability of the visual clusters across multiple t-SNE runs or add a quantitative cluster-separation metric, since the text uses this figure to support the claim that distinguishing Ads from Security/Authentication SDKs is nontrivial.
Circularity Check
No significant circularity: the market-composition claim is an acknowledged seed-dependent measurement, not a self-referential derivation.
full rationale
The paper's load-bearing market-composition claim (Ads 30.56%, Unclear 23.92%, etc., §4.2 / Fig. 4) is a descriptive measurement over the Extended Set, which the paper explicitly constructs as SDKs that exfiltrate more than the minimum seed-SDK signal count (~20) of the 504 signals manually extracted from the 14 self-identifying Seed Set SDKs (§3.2–§3.3). This construction makes the measurement dependent on the seed's signal vocabulary and on the 20-signal threshold; the paper itself acknowledges the resulting coverage limitation: 'It may be that SDKs that fingerprint for hidden reasons use alternative techniques, which would not be caught in our later analyses' (§5.1). That is a selection-bias / external-validity threat, not a circularity: the category shares are not defined in terms of themselves, no parameter fitted to a subset is later presented as a prediction, and no load-bearing result is justified by a self-citation. The self-citations present (e.g., [33] on API proxying; [42] on Android security model) are background and do not carry the argument. The sparse-signal observations are empirical statements about the seed-derived API set, not equations reducible to the seed's definition. Accordingly, no circular step is identified.
Assumptions & free parameters
free parameters (6)
- Extended Set inclusion threshold =
About 20 signals (more than the minimum in the Seed Set)
- App audience cutoff =
10,000 active devices
- SDK-matching class similarity threshold (eta) =
0.2
- SDK-matching class-count threshold (gamma) =
0.55
- Version exclusion set =
{alpha, beta, test, dev, debug, qa}
- Location, app-usage, and account-list signal subsets =
24 location APIs, 3 app-usage APIs, 2 account-list APIs
assumptions (5)
- domain assumption Seed Set SDKs self-report honestly: their advertising copy reflects actual fingerprinting behavior
- ad hoc to paper SDKs exfiltrating about 20 or more seed-derived signals to a common sink are fingerprinting-like, and SDKs below the bar are not
- domain assumption Static taint/CoFlow analysis and the SDK-matching metric correctly capture runtime exfiltration behavior
- domain assumption All signals are equally fingerprintable and independent
- domain assumption Manual labels reflect the true purpose of each SDK
Cite this review
Pith. "Pith review of Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device Fingerprinting." pith.science (2026). https://pith.science/paper/266PPCXY
@misc{pith2026250622639,
author = {Pith},
title = {Pith review of: Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device Fingerprinting},
year = {2026},
howpublished = {\url{https://pith.science/paper/266PPCXY}},
note = {Machine review of arXiv:2506.22639}
}
read the original abstract
This paper presents a large-scale analysis of fingerprinting-like behavior in the mobile application ecosystem. We take a market-based approach, focusing on third-party tracking as enabled by applications' common use of third-party SDKs. Our dataset consists of over 228,000 SDKs from popular Maven repositories, 178,000 Android applications collected from the Google Play store, and our static analysis pipeline detects exfiltration of over 500 individual signals. To the best of our knowledge, this represents the largest-scale analysis of SDK behavior undertaken to date. We find that Ads SDKs (the ostensible focus of industry efforts such as Apple's App Tracking Transparency and Google's Privacy Sandbox) appear to be the source of only 30.56% of the fingerprinting behaviors. A surprising 23.92% originate from SDKs whose purpose was unknown or unclear. Furthermore, Security and Authentication SDKs are linked to only 11.7% of likely fingerprinting instances. These results suggest that addressing fingerprinting solely in specific market-segment contexts like advertising may offer incomplete benefit. Enforcing anti-fingerprinting policies is also complex, as we observe a sparse distribution of signals and APIs used by likely fingerprinting SDKs. For instance, only 2% of exfiltrated APIs are used by more than 75% of SDKs, making it difficult to rely on user permissions to control fingerprinting behavior.
Figures
Figures from the paper (8 more)
Reference graph
Works this paper leans on
-
[1]
The Privacy Sandbox: Technology for a More Private Web
* * *. The Privacy Sandbox: Technology for a More Private Web. Available online at https://privacysandbox.com/intl/en_us. Last visited: 2024-09-30
work page 2024
-
[2]
Smartphone fingerprinting combining features of on-board sensors
Irene Amerini, Rudy Becarelli, Roberto Caldelli, Alessio Melani, and Moreno Niccolai. Smartphone fingerprinting combining features of on-board sensors. IEEE Transactions on Information Forensics and Security, 12(10), 2017
work page 2017
- [3]
-
[4]
Describing use of required reason api
Apple. Describing use of required reason api. Available on- line at https://developer.apple.com/documentation/bundleresources/ privacy_manifest_files/describing_use_of_required_reason_api. Last vis- ited: 2024-09-30
work page 2024
-
[5]
User Privacy and Data Use - App Store
Apple. User Privacy and Data Use - App Store. Available online at https:// developer.apple.com/app-store/user-privacy-and-data-use/ . Last visited: 2024- 09-30
work page 2024
-
[6]
Reliable third-party library detection in android and its security applications
Michael Backes, Sven Bugiel, and Erik Derr. Reliable third-party library detection in android and its security applications. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, CCS ’16, page 356–367, New York, NY , USA, 2016. Association for Computing Machinery
work page 2016
-
[7]
Fp-radar: Longitudinal measurement and early detection of browser fingerprinting, 2021
Pouneh Nikkhah Bahrami, Umar Iqbal, and Zubair Shafiq. Fp-radar: Longitudinal measurement and early detection of browser fingerprinting, 2021
work page 2021
-
[8]
Smartphone verification and user profiles linking across social networks by camera fingerprint- ing
Flavio Bertini, Rajesh Sharma, Andrea Iannì, and Danilo Montesi. Smartphone verification and user profiles linking across social networks by camera fingerprint- ing. In Joshua I. James and Frank Breitinger, editors, Digital Forensics and Cyber Crime, pages 176–186, Cham, 2015. Springer International Publishing
work page 2015
Show all 71 references
-
[9]
Mobile device identification via sensor fingerprinting, 2014
Hristo Bojinov, Yan Michalevsky, Gabi Nakibly, and Dan Boneh. Mobile device identification via sensor fingerprinting, 2014. 11
2014
-
[10]
Private and communication-efficient algo- rithms for entropy estimation, 2023
Gecia Bravo-Hermsdorff, Róbert Busa-Fekete, Mohammad Ghavamzadeh, An- dres Muñoz Medina, and Umar Syed. Private and communication-efficient algo- rithms for entropy estimation, 2023
2023
-
[11]
Experimental and quasi-experimental designs for research
Donald T Campbell and Julian C Stanley. Experimental and quasi-experimental designs for research. Ravenio books, 2015
2015
-
[12]
(cross-)browser fingerprinting via os and hardware level features
Yinzhi Cao, Song Li, and Erik Wijmans. (cross-)browser fingerprinting via os and hardware level features. In Network and Distributed System Security Symposium, 2017
2017
-
[13]
Charge-depleting of the batteries makes smartphones recognizable
Jing Chen, Yingying Fang, Kun He, and Ruiying Du. Charge-depleting of the batteries makes smartphones recognizable. In 2017 IEEE 23rd International Conference on Parallel and Distributed Systems (ICPADS), pages 33–40, 2017
2017
-
[14]
Do you hear what I hear? fin- gerprinting smart devices through embedded acoustic components
Anupam Das, Nikita Borisov, and Matthew Caesar. Do you hear what I hear? fin- gerprinting smart devices through embedded acoustic components. InProceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS ’14, New York, NY , USA, 2014. Association...
2014
-
[15]
Exploring ways to mitigate sensor-based smartphone fingerprinting, 2015
Anupam Das, Nikita Borisov, and Matthew Caesar. Exploring ways to mitigate sensor-based smartphone fingerprinting, 2015
2015
-
[16]
Accelprint: Imperfections of accelerometers make smartphones track- able
Sanorita Dey, Nirupam Roy, Wenyuan Xu, Romit Roy Choudhury, and Srihari Nelakuditi. Accelprint: Imperfections of accelerometers make smartphones track- able. In NDSS. The Internet Society, 2014
2014
-
[17]
Efraimidis
Antonios Dimitriadis, George Drosatos, and Pavlos S. Efraimidis. How much does a zero-permission android app know about us? In Proceedings of the Third Central European Cybersecurity Conference, CECC 2019, New York, NY , USA,
2019
-
[18]
How unique is your web browser? In Mikhail J
Peter Eckersley. How unique is your web browser? In Mikhail J. Atallah and Nicholas J. Hopper, editors, Privacy Enhancing Technologies, pages 1–18, Berlin, Heidelberg, 2010. Springer Berlin Heidelberg
2010
-
[19]
Online tracking: A 1-million-site measurement and analysis
Steven Englehardt and Arvind Narayanan. Online tracking: A 1-million-site measurement and analysis. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 1388–1401. ACM, 2016
2016
-
[20]
Facebook Research. Faiss. Online at https://github.com/facebookresearch/faiss. Last accessed June 5, 2023
2023
-
[21]
Fp- guard: Detection and prevention of browser fingerprinting
Amin FaizKhademi, Mohammad Zulkernine, and Komminist Weldemariam. Fp- guard: Detection and prevention of browser fingerprinting. In Pierangela Samarati, editor, Data and Applications Security and Privacy XXIX, 2015
2015
-
[22]
Investigating fingerprinters and fingerprinting-alike behaviour of android applications
Christof Ferreira Torres and Hugo Jonker. Investigating fingerprinters and fingerprinting-alike behaviour of android applications. In European Symposium on Research in Computer Security, pages 60–80. Springer, 2018
2018
-
[23]
Play Console Help: Example categories
Google. Play Console Help: Example categories. Online at https://support.google. com/googleplay/android-developer/answer/9859673
-
[24]
Play console help: View app statistics
Google. Play console help: View app statistics. Online at https:// support.google.com/googleplay/android-developer/answer/139628?hl= en&co=GENIE.Platform%3DAndroid
-
[25]
Provide information for google play’s data safety section
Google. Provide information for google play’s data safety section
-
[26]
SDK Runtime overview
Google. SDK Runtime overview
-
[27]
Google play sdk index
Google. Google play sdk index. Online at https://play.google.com/sdks, 2024
2024
-
[28]
Google Research. ScaNN. Online at https://github.com/google-research/google- research/tree/master/scann. Last accessed June 5, 2023
2023
-
[29]
Bamberger, and Serge Egel- man
Catherine Han, Irwin Reyes, Álvaro Feal, Joel Reardon, Primal Wijesekera, Narseo Vallina-Rodriguez, Amit Elazar, Kenneth A. Bamberger, and Serge Egel- man. The price is (not) right: Comparing privacy in free and paid apps. Proceed- ings on Privacy Enhancing Technologies, 2020(3), 2020
2020
-
[30]
Identify and inspect libraries in android applications
Hongmu Han, Ruixuan Li, and Junwei Tang. Identify and inspect libraries in android applications. Wirel. Pers. Commun., 103(1):491–503, nov 2018
2018
-
[31]
Towards detecting device finger- printing on ios with api function hooking
Kris Heid, Vincent Andrae, and Jens Heider. Towards detecting device finger- printing on ios with api function hooking. EICC ’23, New York, NY , USA, 2023. Association for Computing Machinery
2023
-
[32]
Thomas Hupperich, Davide Maiorca, Marc Kührer, Thorsten Holz, and Giorgio Giacinto. On the robustness of mobile device fingerprinting: Can mobile users escape modern web-tracking mechanisms? In Proceedings of the 31st Annual Computer Security Applications Conference, ACSAC ’15, 2015
2015
-
[33]
Formal analysis of the api proxy problem, 2023
Somesh Jha, Mihai Christodorescu, and Anh Pham. Formal analysis of the api proxy problem, 2023
2023
-
[34]
Kohno, A
T. Kohno, A. Broido, and K.C. Claffy. Remote physical device fingerprinting. IEEE Transactions on Dependable and Secure Computing, 2(2):93–108, 2005
2005
-
[35]
Are iPhones Really Better for Privacy? A Comparative Study of iOS and Android Apps
Konrad Kollnig, Anastasia Shuba, Reuben Binns, Max Van Kleek, and Nigel Shadbolt. Are iPhones Really Better for Privacy? A Comparative Study of iOS and Android Apps. 2022(2):6–24
2022
-
[36]
Cross-app tracking via nearby bluetooth low energy devices
Aleksandra Korolova and Vinod Sharma. Cross-app tracking via nearby bluetooth low energy devices. In Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy, CODASPY ’18, page 43–52, New York, NY , USA, 2018. Association for Computing Machinery
2018
-
[37]
Fingerprinting mobile devices using personalized configurations
Andreas Kurtz, Hugo Gascon, Tobias Becker, Konrad Rieck, and Felix C Freiling. Fingerprinting mobile devices using personalized configurations. Proc. Priv. Enhancing Technol., 2016(1):4–19, 2016
2016
-
[38]
Libd: Scalable and precise third-party library detection in android markets
Menghao Li, Wei Wang, Pei Wang, Shuai Wang, Dinghao Wu, Jian Liu, Rui Xue, and Wei Huo. Libd: Scalable and precise third-party library detection in android markets. In 2017 IEEE/ACM 39th International Conference on Software Engineering (ICSE), pages 335–346, 2017
2017
-
[39]
Fpflow: Detect and prevent browser fingerprinting with dynamic taint analysis
Tianyi Li, Xiaofeng Zheng, Kaiwen Shen, and Xinhui Han. Fpflow: Detect and prevent browser fingerprinting with dynamic taint analysis. In Wei Lu, Yuqing Zhang, Weiping Wen, Hanbing Yan, and Chao Li, editors,Cyber Security, pages 51–67, Singapore, 2022. Springer Nature Singapore
2022
-
[40]
Finding the stars in the fireworks: Deep un- derstanding of motion sensor fingerprint
Xiang-Yang Li, Huiqi Liu, Lan Zhang, Zhenan Wu, Yaochen Xie, Ge Chen, Chunxiao Wan, and Zhongwei Liang. Finding the stars in the fireworks: Deep un- derstanding of motion sensor fingerprint. IEEE/ACM Transactions on Networking, 27(5):1945–1958, 2019
1945
-
[41]
Libradar: Fast and accurate detection of third-party libraries in android apps
Ziang Ma, Haoyu Wang, Yao Guo, and Xiangqun Chen. Libradar: Fast and accurate detection of third-party libraries in android apps. In Proceedings of the 38th International Conference on Software Engineering Companion, ICSE ’16, page 653–656, New York, NY , USA, 2016. Associatio...
2016
-
[42]
René Mayrhofer, Jeffrey Vander Stoep, Chad Brubaker, Dianne Hackborn, Bram Bonné, Güliz Seray Tuncay, Roger Piqueras Jover, and Michael A. Specter. The android platform security model (2023), 2021
2023
-
[43]
Microsoft. SPTAG. Online at https://github.com/microsoft/SPTAG. Last accessed June 5, 2023
2023
-
[44]
Hardware fingerprinting using html5, 2015
Gabi Nakibly, Gilad Shelef, and Shiran Yudilevich. Hardware fingerprinting using html5, 2015
2015
-
[45]
Privaricator: Deceiving fingerprinters with little white lies
Nick Nikiforakis, Wouter Joosen, and Benjamin Livshits. Privaricator: Deceiving fingerprinters with little white lies. In Proceedings of the 24th International Conference on World Wide Web, WWW ’15, 2015
2015
-
[46]
Cookieless Monster: Exploring the Ecosys- tem of Web-Based Device Fingerprinting
Nick Nikiforakis, Alexandros Kapravelos, Wouter Joosen, Christopher Kruegel, Frank Piessens, and Giovanni Vigna. Cookieless Monster: Exploring the Ecosys- tem of Web-Based Device Fingerprinting. In 2013 IEEE Symposium on Security and Privacy, pages 541–555, May 2013
2013
-
[47]
The leak- ing battery
Łukasz Olejnik, Gunes Acar, Claude Castelluccia, and Claudia Diaz. The leak- ing battery. In Joaquin Garcia-Alfaro, Guillermo Navarro-Arribas, Alessandro Aldini, Fabio Martinelli, and Neeraj Suri, editors, Data Privacy Management, and Security Assurance , pages 254–263, Cham, ...
2016
-
[48]
Androprint: Analysing the fingerprintability of the android api
Gerald Palfinger and Bernd Prünster. Androprint: Analysing the fingerprintability of the android api. In Proceedings of the 15th International Conference on Availability, Reliability and Security , ARES ’20, New York, NY , USA, 2020. Association for Computing Machinery
2020
-
[49]
On the security and applicability of fragile camera fingerprints
Erwin Quiring, Matthias Kirchner, and Konrad Rieck. On the security and applicability of fragile camera fingerprints. In Computer Security – ESORICS 2019: 24th European Symposium on Research in Computer Security, Luxembourg, September 23–27, 2019, Proceedings, Part I, page 450...
2019
-
[50]
Dubois, Ashwin Rao, David R
Jingjing Ren, Martina Lindorfer, Daniel J. Dubois, Ashwin Rao, David R. Choffnes, and Narseo Vallina-Rodriguez. Bug fixes, improvements, ... and privacy leaks - a longitudinal study of pii leaks across android app versions. In Network and Distributed System Security Symposium, 2018
2018
-
[51]
Clock around the clock: Time-based device fingerprinting
Iskander Sanchez-Rola, Igor Santos, and Davide Balzarotti. Clock around the clock: Time-based device fingerprinting. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, CCS ’18, page 1502–1514, New York, NY , USA, 2018. Association for Com...
2018
-
[52]
Prochar- vester: Fully automated analysis of procfs side-channel leaks on android
Raphael Spreitzer, Felix Kirchengast, Daniel Gruss, and Stefan Mangard. Prochar- vester: Fully automated analysis of procfs side-channel leaks on android. In Proceedings of the 2018 on Asia Conference on Computer and Communications Security, ASIACCS ’18, 2018
2018
-
[53]
Starov and N
O. Starov and N. Nikiforakis. Xhound: Quantifying the fingerprintability of browser extensions. In 2017 IEEE Symposium on Security and Privacy (SP) , pages 941–956, Los Alamitos, CA, USA, may 2017. IEEE Computer Society
2017
-
[54]
Mobile device fingerprint identification using gyroscope resonance
Junze Tian, Jianyi Zhang, Xiuying Li, Changchun Zhou, Ruilong Wu, Yuchen Wang, and Shengyuan Huang. Mobile device fingerprint identification using gyroscope resonance. IEEE Access, 9:160855–160867, 2021
2021
-
[55]
Güliz Seray Tuncay, Jingyu Qian, and Carl A. Gunter. See no evil: Phishing for permissions with false transparency. In 29th USENIX Security Symposium (USENIX Security 20), pages 415–432. USENIX Association, August 2020
2020
-
[56]
Visualizing data using t-sne
Laurens van der Maaten and Geoffrey Hinton. Visualizing data using t-sne. Journal of Machine Learning Research, 9(86):2579–2605, 2008
2008
-
[57]
Accelerometer-based device fingerprinting for multi-factor mobile authentication
Tom Van Goethem, Wout Scheepers, Davy Preuveneers, and Wouter Joosen. Accelerometer-based device fingerprinting for multi-factor mobile authentication. In Juan Caballero, Eric Bodden, and Elias Athanasopoulos, editors, Engineering Secure Software and Systems, Cham, 2016
2016
-
[58]
Orlis: Obfuscation- resilient library detection for android
Yan Wang, Haowei Wu, Hailong Zhang, and Atanas Rountev. Orlis: Obfuscation- resilient library detection for android. In 2018 IEEE/ACM 5th International Conference on Mobile Software Engineering and Systems (MOBILESoft), 2018
2018
-
[59]
How to use t-sne effec- tively
Martin Wattenberg, Fernanda Viégas, and Ian Johnson. How to use t-sne effec- tively. Distill, 2016
2016
-
[60]
Efficient fingerprinting-based android device identification with zero-permission identifiers
Wenjia Wu, Jianan Wu, Yanhao Wang, Zhen Ling, and Ming Yang. Efficient fingerprinting-based android device identification with zero-permission identifiers. IEEE Access, 4:8073–8083, 2016
2016
-
[61]
Libroad: Rapid, online, and accurate detection of tpls on android
Jian Xu and Qianting Yuan. Libroad: Rapid, online, and accurate detection of tpls on android. IEEE Transactions on Mobile Computing, 21(1):167–180, 2022
2022
-
[62]
Yahoo! JAPAN. NGT. Online at https://github.com/yahoojapan/NGT. Last accessed June 5, 2023
2023
-
[63]
Yandex. Hnswlib. Online at https://github.com/nmslib/hnswlib. Last accessed June 5, 2023. 12
2023
-
[64]
Atvhunter: Reliable version detection of third-party libraries for vul- nerability identification in android applications
Xian Zhan, Lingling Fan, Sen Chen, Feng Wu, Tianming Liu, Xiapu Luo, and Yang Liu. Atvhunter: Reliable version detection of third-party libraries for vul- nerability identification in android applications. In Proceedings of the 43rd International Conference on Software Enginee...
2021
-
[65]
Xian Zhan, Lingling Fan, Tianming Liu, Sen Chen, Li Li, Haoyu Wang, Yifei Xu, Xiapu Luo, and Yang Liu. Automated third-party library detection for android applications: Are we there yet? In 2020 35th IEEE/ACM International Conference on Automated Software Engineering (ASE), pa...
2020
-
[66]
Research on third-party libraries in android apps: A taxonomy and systematic literature review
Xian Zhan, Tianming Liu, Lingling Fan, Li Li, Sen Chen, Xiapu Luo, and Yang Liu. Research on third-party libraries in android apps: A taxonomy and systematic literature review. IEEE Transactions on Software Engineering, 48(10):4181–4213, 2022
2022
-
[67]
A systematic assessment on android third-party library detection tools
Xian Zhan, Tianming Liu, Yepang Liu, Yang Liu, Li Li, Haoyu Wang, and Xiapu Luo. A systematic assessment on android third-party library detection tools. IEEE Transactions on Software Engineering, 48(11):4249–4273, 2022
2022
-
[68]
Beresford, and Ian Sheret
Jiexin Zhang, Alastair R. Beresford, and Ian Sheret. Sensorid: Sensor calibration fingerprinting for smartphones. In 2019 IEEE Symposium on Security and Privacy (SP), pages 638–655, 2019
2019
-
[69]
Beresford, and Ian Sheret
Jiexin Zhang, Alastair R. Beresford, and Ian Sheret. Factory calibration finger- printing of sensors. IEEE Transactions on Information Forensics and Security, 16:1626–1639, 2021
2021
-
[70]
Art and Design
Zhe Zhou, Wenrui Diao, Xiangyu Liu, and Kehuan Zhang. Acoustic fingerprinting revisited: Generate stable device id stealthily with inaudible sound. InProceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS ’14, page 429–440. Association for C...
2014
-
[2019]
Association for Computing Machinery
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.