logo
Loading...
Towards Privacy-Preserving Social-Media SDKs on Android
Computer ScienceProceedings of the 33rd USENIX Security Symposium

Towards Privacy-Preserving Social-Media SDKs on Android

H. Lu, Y. Liu, et al.

Mobile apps commonly embed social platform SDKs that can enable cross-library data harvesting (XLDH), posing privacy and compliance risks. This study, conducted by Haoran Lu, Yichen Liu, Xiaojing Liao, and Luyi Xing, defines privacy-preserving social SDKs, outlines core challenges, and introduces PESP — a clean-slate, practical system evaluated for effectiveness and performance for broad adoption.... show more
Abstract
Integration of third-party SDKs are essential in the development of mobile apps. However, the rise of in-app privacy threat against mobile SDKs — called cross-library data harvesting (XLDH), targets social media/platform SDKs (called social SDKs) that handles rich user data. Given the widespread integration of social SDKs in mobile apps, XLDH presents a significant privacy risk, as well as raising pressing concerns regarding legal compliance for app developers, social media/platform stakeholders, and policymakers. The emerging XLDH threat, coupled with the increasing demand for privacy and compliance in line with societal expectations, introduces unique challenges that cannot be addressed by existing protection methods against privacy threats or malicious code on mobile platforms. In response to the XLDH threats, in our study, we generalize and define the concept of privacy-preserving social SDKs and their in-app usage, characterize fundamental challenges for combating the XLDH threat and ensuring privacy in design and utilization of social SDKs. We introduce a practical, clean-slate design and end-to-end systems, called PESP, to facilitate privacy-preserving social SDKs. Our thorough evaluation demonstrates its satisfactory effectiveness, performance overhead and practicability for widespread adoption.
Publisher
Proceedings of the 33rd USENIX Security Symposium
Published On
Aug 14, 2024
Authors
Haoran Lu, Yichen Liu, Xiaojing Liao, Luyi Xing
Tags
cross-library data harvesting (XLDH)social SDKsprivacy-preserving social SDKsPESPmobile appsprivacy compliancethird-party SDK integration
Listen, Learn & Level Up
Over 10,000 hours of research content in 25+ fields, available in 22+ languages.
No more digging through PDFs, just hit play and absorb the world's latest research in your language, on your time.
listen to research audio papers with researchbunny