ArXivCSExplorer
☆☆Bookmarks🏆RSSHow to UseFAQ
Built with and by Teycir Ben Soltane•
How to Use•FAQ•GitHub•arXiv.org•
Share:

~ similar to 2603.29668v1· 20 results

cs.CRRecentJun 2, 2026

Don't Trust Us: A privacy-by-design android malware detection pipeline

Emmanuele Massidda, Diego Soi, Giorgio Giacinto

The paper proposes a privacy-by-design pipeline for Android malware detection that achieves strong performance by avoiding the collection of sensitive user data entirely.

View →
cs.CRcs.HCRecentMar 30, 2026

Uncovering Relationships between Android Developers, User Privacy, and Developer Willingness to Reduce Fingerprinting Risks

Alex Berke, Güliz Seray Tuncay, Michael Specter, Mihai Christodorescu

The study surveyed Android developers to assess their willingness to adopt changes that mitigate device fingerprinting risks, finding that developers overwhelmingly support privacy protections even wi…

View →
cs.NIcs.CRcs.CYRecentMay 11, 2026

Democratizing Measurement of Critical Mobile Infrastructure: Security and Privacy in an Increasingly Centralized Communication Ecosystem

Gabriel K. Gegenhuber

The paper addresses the lack of independent measurement tools for modern mobile communication by designing and implementing open-source platforms to study cellular radio networks, operator services, a…

View →
cs.CRRecentMar 17, 2026

Ember: A Serverless Peer-to-Peer End-to-End Encrypted Messaging System over an IPv6 Mesh Network

Hamish Alsop, Leandros Maglaras, Naghmeh Moradpoor

Ember is a serverless, peer-to-peer messaging system that provides end-to-end encrypted communication over a decentralized IPv6 mesh network while enforcing strict data minimization.

View →
cs.CRcs.SERecentApr 20, 2026

Do Privacy Policies Match with the Logs? An Empirical Study of Privacy Disclosure in Android Application Logs

Zhiyuan Chen, Love Jayesh Ahir, Ahmad Suleiman, Kundi Yao +3 more

This study empirically analyzed 1,000 Android apps, finding that privacy policies are often vague and frequently fail to align with the actual sensitive data logged by the applications.

View →
cs.CRcs.AIcs.CLRecentApr 1, 2026

Do Phone-Use Agents Respect Your Privacy?

Zhengyang Tang, Ke Ji, Xidong Wang, Zihan Ye +18 more

The paper introduces MyPhoneBench, a new framework that demonstrates that current phone-use agents often fail to respect user privacy, even when successfully completing simple tasks, primarily due to…

View →
cs.CRRecentMay 26, 2026

Silent Consent, Persistent Risk: Android Permission Groups and Custom Permissions

Olawale Amos Akanji, Manuel Egele, Gianluca Stringhini

The paper analyzes Android's permission system and finds that two legacy mechanisms—permission groups and normal-level custom permissions—allow apps to silently gain excessive permissions and expose s…

View →
cs.CRcs.CYRecentMar 25, 2026

A Large-Scale Study of Telegram Bots

Taro Tsuchiya, Haoxiang Yu, Tina Marjanov, Alice Hutchings +2 more

This paper provides a large-scale characterization of Telegram bots, revealing that while they serve useful functions like crowdsourcing, they are also extensively used for malicious activities such a…

View →
cs.CRcs.AIRecentMay 22, 2026

Unlocking Apple's Private Cloud Compute: An Analysis of Privacy-Preserving Artificial Intelligence

Yannik Dittmar, Marvin Jerome Stephan, Thomas Völkl, Matthias Hollick +1 more

The paper reverse-engineers Apple's Private Cloud Compute (PCC) implementation to independently benchmark its model and evaluate its privacy claims, addressing the lack of transparency in Apple's syst…

View →
cs.CRcs.HCRecentApr 25, 2026

PrivacyAssist: A User-Centric Agent Framework for Detecting Privacy Inconsistencies in Android Apps

Tran Thanh Lam Nguyen, Edoardo Di Tullio, Barbara Carminati, Elena Ferrari

PrivacyAssist is a multi-agent LLM framework that detects inconsistencies between user-granted app permissions and the app's actual data collection practices, finding that most apps are not fully tran…

View →
cs.CRRecentApr 30, 2026

WOOTdroid: Whole-system Online On-device Tracing for Android

Simon Althaus, Nikolaos Alexopoulos, Max Mühlhäuser, Christian Reuter +1 more

WOOTdroid is a novel, non-invasive system for comprehensive on-device tracing on stock Android that simultaneously addresses syscall data loss and the semantic gap in Binder IPC events.

View →
cs.CRRecentMay 25, 2026

Ecosystem-Driven Privacy Exposure in Mobile Gaming Apps: A Configuration-Aware Empirical Analysis

Bakheet Aljedaani

This study empirically demonstrates that privacy exposure in mobile gaming apps is primarily driven by complex, configuration-level SDK ecosystems rather than just the permissions the app explicitly r…

View →
cs.CRRecentMar 25, 2026

An Empirical Analysis of Google Play Data Safety Disclosures: A Consistency Study of Privacy Indicators in Mobile Gaming Apps

Bakheet Aljedaani

This study empirically analyzed 41 mobile gaming apps, finding that while device ID disclosures were relatively consistent, location and personal information disclosures showed significant mismatches…

View →
cs.CRcs.CYRecentMay 15, 2026

Read This Paper to Get $50 Million:* An Analysis of Mobile Messaging Scams Using Reddit Data

Allison Lu, Bernardo B. P. Medeiros, Kevin R. B. Butler, Patrick Traynor

This study analyzes a large dataset of mobile messaging scams from Reddit, finding that rapidly growing reply-based scams are poorly detected by current off-the-shelf tools, necessitating the developm…

View →
cs.CRRecentApr 30, 2026

Static Attribution of Android Residential Proxy Malware Using Graph Kernels

Peter Clark, Yong Guan, Zhonghao Liao

The paper introduces a static analysis pipeline using graph kernels to automatically attribute unknown Android proxy malware to specific commercial proxy networks with high accuracy.

View →
cs.NIcs.CRRecentMay 2, 2026

ShieldShare: Building a VPN-backed Android Hotspot for Secure Internet Sharing with Per-User Traffic Accounting

Carlos Semeho Edorh, Jialu Bi, Hanchen Ye, Dawood Sajjadi +1 more

ShieldShare is a novel, non-root Android application that enables secure, VPN-backed hotspot sharing with accurate per-user traffic accounting, addressing limitations in current mobile VPN implementat…

View →
cs.CRcs.NIRecentApr 25, 2026

ARIstoteles -- Dissecting Apple's Baseband Interface

Tobias Kröll, Stephan Kleber, Frank Kargl, Matthias Hollick +1 more

The authors reverse-engineered and fuzz-tested the undocumented Apple Remote Invocation (ARI) interface, revealing a significant, untested Remote Code Execution (RCE) attack surface on iOS.

View →
cs.CRRecentApr 14, 2026

Practical Evaluation of the Crypto-Agility Maturity Model

Leonie Wolf, Samson Umezulike, Gurur Öndarö, Sebastian Schinzel +1 more

This paper evaluates the Crypto Agility Maturity Model (CAMM) and finds that it suffers from ambiguities, lack of operationalization, and structural flaws, proposing concrete improvements for reliable…

View →
cs.CRcs.SERecentApr 27, 2026

Evaluating Cryptographic API Misuse Detectors for Go

Vivi Andersson, Martin Monperrus

This paper provides the first comprehensive study of cryptographic API misuse detection in Go, evaluating four state-of-the-art tools and discovering 7,473 instances of cryptographic API misuses acros…

View →
cs.CRRecentMay 6, 2026

A Pragmatic Comparison of Cryptographic Computation Technologies for Machine Learning

Marcus Taubert, Adam Skuta, Thomas Loruenser

This paper provides a comparative analysis and benchmarking of Secure Multi-Party Computation (SMPC) and Fully Homomorphic Encryption (FHE) for machine learning, finding that the optimal choice depend…

View →