{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T20:12:35Z","timestamp":1783714355704,"version":"3.55.0"},"reference-count":112,"publisher":"Springer Science and Business Media LLC","issue":"3","license":[{"start":{"date-parts":[[2025,4,2]],"date-time":"2025-04-02T00:00:00Z","timestamp":1743552000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,4,2]],"date-time":"2025-04-02T00:00:00Z","timestamp":1743552000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100000038","name":"Natural Sciences and Engineering Research Council of Canada","doi-asserted-by":"publisher","award":["RGPIN-2022-03744"],"award-info":[{"award-number":["RGPIN-2022-03744"]}],"id":[{"id":"10.13039\/501100000038","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Hong Kong Research Grant Council\/General Research Fund","award":["16205821"],"award-info":[{"award-number":["16205821"]}]},{"name":"Hong Kong Research Grant Council\/General Research Fund","award":["DGECR-2022-00378"],"award-info":[{"award-number":["DGECR-2022-00378"]}]},{"name":"Hong Kong Research Grant Council\/Postdoctoral Fellowship","award":["PDFS2021-6S06"],"award-info":[{"award-number":["PDFS2021-6S06"]}]},{"DOI":"10.13039\/501100003151","name":"Fonds de recherche du Qu\u00e9bec - Nature et technologies","doi-asserted-by":"publisher","award":["2024-NOVA-346499"],"award-info":[{"award-number":["2024-NOVA-346499"]}],"id":[{"id":"10.13039\/501100003151","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100007567","name":"City University of Hong Kong","doi-asserted-by":"publisher","award":["9610676"],"award-info":[{"award-number":["9610676"]}],"id":[{"id":"10.13039\/100007567","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2025,5]]},"DOI":"10.1007\/s10664-024-10607-9","type":"journal-article","created":{"date-parts":[[2025,4,4]],"date-time":"2025-04-04T06:52:33Z","timestamp":1743749553000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["How far are app secrets from being stolen? a case study on android"],"prefix":"10.1007","volume":"30","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2428-4111","authenticated-orcid":false,"given":"Lili","family":"Wei","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5328-3994","authenticated-orcid":false,"given":"Heqing","family":"Huang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3508-7172","authenticated-orcid":false,"given":"Shing-Chi","family":"Cheung","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kevin","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,4,2]]},"reference":[{"key":"10607_CR1","unstructured":"Adobe IMS APIs (2021). https:\/\/www.adobe.io\/authentication\/auth-methods.html#!AdobeDocs\/adobeio-auth\/master\/Resources\/IMS.md"},{"key":"10607_CR2","unstructured":"Airship (2021). https:\/\/www.airship.com"},{"key":"10607_CR3","doi-asserted-by":"crossref","unstructured":"Al\u00a0Rahat T, Feng Y, Tian Y (2019) OAuthLint: an empirical study on oauth bugs in android applications. In: IEEE\/ACM international conference on automated software engineering (ASE) pp 293\u2013304","DOI":"10.1109\/ASE.2019.00036"},{"key":"10607_CR4","unstructured":"Algolia (2021). https:\/\/www.algolia.com"},{"key":"10607_CR5","unstructured":"ALipay (2021). https:\/\/global.alipay.com\/docs\/"},{"key":"10607_CR6","doi-asserted-by":"crossref","unstructured":"Allix K, Bissyand\u00e9 TF, Klein J, Le\u00a0Traon Y (2016) Androzoo: collecting millions of android apps for the research community. In: Proceedings of the 13th international conference on mining software repositories pp 468\u2013471","DOI":"10.1145\/2901739.2903508"},{"key":"10607_CR7","unstructured":"Amazon Simple Storage Service Documentation (2021). https:\/\/docs.aws.amazon.com\/s3\/index.html"},{"key":"10607_CR8","unstructured":"Amplitude (2021). https:\/\/amplitude.com"},{"key":"10607_CR9","unstructured":"Android Developers - Save key-value data (2021). https:\/\/developer.android.com\/training\/data-storage\/shared-preferences"},{"key":"10607_CR10","unstructured":"AndroidAPKsFree (2021). https:\/\/androidapksfree.com"},{"key":"10607_CR11","unstructured":"Apktool (2021). https:\/\/ibotpeaches.github.io\/Apktool\/"},{"key":"10607_CR12","unstructured":"AppDynamics (2021). https:\/\/www.appdynamics.com"},{"key":"10607_CR13","unstructured":"AppMetrica (2021). https:\/\/appmetrica.yandex.com\/about"},{"key":"10607_CR14","unstructured":"Appodeal (2021). https:\/\/appodeal.com"},{"key":"10607_CR15","unstructured":"AppsFlyer (2021). https:\/\/www.appsflyer.com"},{"key":"10607_CR16","unstructured":"Aptoide (2021) https:\/\/en.aptoide.com"},{"issue":"6","key":"10607_CR17","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1145\/2666356.2594299","volume":"49","author":"S Arzt","year":"2014","unstructured":"Arzt S, Rasthofer S, Fritz C, Bodden E, Bartel A, Klein J, Le Traon Y, Octeau D, McDaniel P (2014) Flowdroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for android apps. Acm Sigplan Notices 49(6):259\u2013269","journal-title":"Acm Sigplan Notices"},{"key":"10607_CR18","unstructured":"Authorization Code Request (2021). https:\/\/www.oauth.com\/oauth2-servers\/access-tokens\/authorization-code-request\/"},{"key":"10607_CR19","unstructured":"Azure Speech Service Documentation (2021). https:\/\/docs.microsoft.com\/en-us\/azure\/cognitive-services\/Speech-Service\/"},{"key":"10607_CR20","doi-asserted-by":"crossref","unstructured":"Basak SK, Neil L, Reaves B, Williams L (2023) What challenges do developers face about checked-in secrets in software artifacts?. In: 2023 IEEE\/ACM 45th international conference on software engineering (ICSE). IEEE pp 1635\u20131647","DOI":"10.1109\/ICSE48619.2023.00141"},{"key":"10607_CR21","unstructured":"BitMovin (2021). https:\/\/bitmovin.com"},{"key":"10607_CR22","unstructured":"Box Platform (2021). https:\/\/developer.box.com"},{"key":"10607_CR23","unstructured":"BuzzAd (2021). https:\/\/buzzvil.atlassian.net\/wiki\/spaces\/BDG\/pages\/723845555\/BuzzAd%2BBenefit%2B2.0%2B-%2BAndroid%2BSDK%2BIntegration%2BGuide,"},{"key":"10607_CR24","unstructured":"Bytecode Viewer (2021). https:\/\/bytecodeviewer.com"},{"key":"10607_CR25","doi-asserted-by":"crossref","unstructured":"Chen EY, Pei Y, Chen S, Tian Y, Kotcher R, Tague P (2014) Oauth demystified for mobile application developers. In: ACM conference on computer and communications security (CCS) pp 892\u2013903","DOI":"10.1145\/2660267.2660323"},{"key":"10607_CR26","doi-asserted-by":"crossref","unstructured":"Chen S, Fan L, Meng G, Su T, Xue M, Xue Y, Liu Y, Xu L (2020) An empirical assessment of security risks of global android banking apps. In: Proceedings of the ACM\/IEEE 42nd international conference on software engineering pp 1310\u20131322","DOI":"10.1145\/3377811.3380417"},{"key":"10607_CR27","unstructured":"Client Credentials (2021). https:\/\/www.oauth.com\/oauth2-servers\/access-tokens\/client-credentials\/"},{"key":"10607_CR28","unstructured":"Cloudinary Admin API (2021). https:\/\/cloudinary.com\/documentation\/admin_api"},{"key":"10607_CR29","unstructured":"Countly (2021). https:\/\/support.count.ly\/hc\/en-us"},{"key":"10607_CR30","unstructured":"CWE-321: Use of Hard-coded Cryptographic Key (2021). https:\/\/cwe.mitre.org\/data\/definitions\/321.html"},{"key":"10607_CR31","unstructured":"CWE-798: Use of Hard-coded Credentials (2021). https:\/\/cwe.mitre.org\/data\/definitions\/798.html"},{"key":"10607_CR32","unstructured":"Developers - Dropbox (2021). https:\/\/www.dropbox.com\/developers"},{"key":"10607_CR33","doi-asserted-by":"crossref","unstructured":"Egele M, Brumley D, Fratantonio Y, Kruegel C (2013) An empirical study of cryptographic misuse in android applications. In: ACM conference on computer & communications securit (CCS) pp 73\u201384","DOI":"10.1145\/2508859.2516693"},{"issue":"2","key":"10607_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2619091","volume":"32","author":"W Enck","year":"2014","unstructured":"Enck W, Gilbert P, Han S, Tendulkar V, Chun B-G, Cox LP, Jung J, McDaniel P, Sheth AN (2014) Taintdroid: an information-flow tracking system for realtime privacy monitoring on smartphones. ACM Trans Comput Syst (TOCS) 32(2):1\u201329","journal-title":"ACM Trans Comput Syst (TOCS)"},{"key":"10607_CR35","unstructured":"Facebook for Developers (2021). https:\/\/developers.facebook.com"},{"key":"10607_CR36","doi-asserted-by":"crossref","unstructured":"Felt AP, Chin E, Hanna S, Song D, Wagner D (2011) Android permissions demystified. In: ACM conference on computer and communications security (CCS) pp 627\u2013638","DOI":"10.1145\/2046707.2046779"},{"key":"10607_CR37","doi-asserted-by":"crossref","unstructured":"Feng R, Yan Z, Peng S, Zhang Y (2022) Automated detection of password leakage from public github repositories. In: 2022 IEEE\/ACM 44th international conference on software engineering (ICSE) pp 175\u2013186","DOI":"10.1145\/3510003.3510150"},{"key":"10607_CR38","unstructured":"Firebase Cloud Messaging (2021). https:\/\/firebase.google.com\/docs\/cloud-messaging"},{"key":"10607_CR39","unstructured":"Firebase Cloud Messaging Service Takeover: A small research that led to 30k\\$+ in bounties (2021). https:\/\/abss.me\/posts\/fcm-takeover\/"},{"key":"10607_CR40","unstructured":"Flurry (2021). https:\/\/www.flurry.com"},{"issue":"3","key":"10607_CR41","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1016\/j.istr.2005.08.001","volume":"10","author":"A Fuchsberger","year":"2005","unstructured":"Fuchsberger A (2005) Intrusion detection systems and intrusion prevention systems. Inf Secur Techn Rep 10(3):134\u2013139","journal-title":"Inf Secur Techn Rep"},{"key":"10607_CR42","doi-asserted-by":"crossref","unstructured":"Gamba J, Rashed M, Razaghpanah A, Tapiador J, Vallina-Rodriguez N (2020) An analysis of pre-installed android software. In: IEEE symposium on security and privacy (S &P) pp 1039\u20131055","DOI":"10.1109\/SP40000.2020.00013"},{"key":"10607_CR43","unstructured":"GET favorites\/list (2021). https:\/\/developer.twitter.com\/en\/docs\/twitter-api\/v1\/tweets\/post-and-engage\/api-reference\/get-favorites-list,"},{"key":"10607_CR44","unstructured":"Google Analytics (2021). https:\/\/analytics.google.com\/analytics\/web\/provision\/#\/provision"},{"key":"10607_CR45","unstructured":"Google Cloud Translation (2021a). https:\/\/cloud.google.com\/translate,"},{"key":"10607_CR46","unstructured":"Google Cloud Vision API (2021b). https:\/\/cloud.google.com\/vision"},{"key":"10607_CR47","unstructured":"Google Maps Platform API (2021). https:\/\/developers.google.com\/maps"},{"key":"10607_CR48","unstructured":"Google Play Store (2021). https:\/\/play.google.com\/store"},{"key":"10607_CR49","doi-asserted-by":"crossref","unstructured":"Guo Y, Liu J, Tang W, Huang C (2021) Exsense: Extract sensitive information from unstructured data. Comput Secur 102:102156. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404820304296","DOI":"10.1016\/j.cose.2020.102156"},{"key":"10607_CR50","doi-asserted-by":"crossref","unstructured":"Harty J, Zhang H, Wei L, Pascarella L, Aniche M, Shang W (2021) Logging practices with mobile analytics: an empirical study on firebase. In: IEEE\/ACM international conference on mobile software engineering and systems (MOBILESoft) pp 56\u201360","DOI":"10.1109\/MobileSoft52590.2021.00013"},{"key":"10607_CR51","unstructured":"HockeyApp (2021). https:\/\/marketplace.visualstudio.com\/items?itemName=ms.hockeyapp"},{"key":"10607_CR52","doi-asserted-by":"publisher","first-page":"265","DOI":"10.4135\/9781848607941.n13","volume":"3","author":"JA Holton","year":"2007","unstructured":"Holton JA (2007) The coding process and its challenges. The Sage Handbook of Grounded Theory 3:265\u2013289","journal-title":"The Sage Handbook of Grounded Theory"},{"key":"10607_CR53","unstructured":"How apps and software are getting more complicated (2021). https:\/\/knowtechie.com\/complimenting-tech-how-apps-and-software-are-getting-more-complicated\/"},{"key":"10607_CR54","unstructured":"How to fix Exposed AWS Credentials (2024). https:\/\/support.google.com\/faqs\/answer\/9093739?hl=en"},{"key":"10607_CR55","unstructured":"HTTP Status Code Registry (2021). https:\/\/www.iana.org\/assignments\/http-status-codes\/http-status-codes.xhtml,"},{"key":"10607_CR56","unstructured":"Insecure Storage and Overly Permissive API Keys in Android App (2021). https:\/\/hackerone.com\/reports\/753868"},{"key":"10607_CR57","unstructured":"Integrate Flurry SDK for Android (2021) https:\/\/developer.yahoo.com\/flurry\/docs\/integrateflurry\/android\/"},{"key":"10607_CR58","unstructured":"Iterable (2021). https:\/\/iterable.com"},{"key":"10607_CR59","unstructured":"Keen - Event Streaming Platform (2021). https:\/\/keen.io"},{"key":"10607_CR60","unstructured":"KeyHacks (2021). https:\/\/github.com\/streaak\/keyhacks"},{"key":"10607_CR61","unstructured":"Leanplum (2021). https:\/\/www.leanplum.com"},{"key":"10607_CR62","doi-asserted-by":"crossref","unstructured":"Li L, Bartel A, Bissyand\u00e9 TF, Klein J, Le\u00a0Traon Y, Arzt S, Rasthofer S, Bodden E, Octeau D, McDaniel P (2015) Iccta: detecting inter-component privacy leaks in android apps. In: ACM international conference on software engineering pp 280\u2013291","DOI":"10.1109\/ICSE.2015.48"},{"key":"10607_CR63","unstructured":"LINE Developers (2021). https:\/\/developers.line.biz\/en\/"},{"key":"10607_CR64","doi-asserted-by":"crossref","unstructured":"Liu L, Wei L, Zhang W, Wen M, Liu Y, Cheung S (2021) Characterizing transaction-reverting statements in ethereum smart contracts. In: IEEE\/ACM international conference on automated software engineering (ASE) pp 13","DOI":"10.1109\/ASE51524.2021.9678597"},{"key":"10607_CR65","unstructured":"Many Mobile Apps Unnecessarily Leak Hardcoded Keys: Analysis (2021). https:\/\/www.securityweek.com\/many-mobile-apps-unnecessarily-leak-hardcoded-keys-analysis,"},{"key":"10607_CR66","unstructured":"Map Box (2021). https:\/\/www.mapbox.com"},{"key":"10607_CR67","doi-asserted-by":"crossref","unstructured":"Meli M, McNiece MR, Reaves B (2019) How bad can it git? characterizing secret leakage in public github repositories. In: The network and distributed system security symposium (NDSS)","DOI":"10.14722\/ndss.2019.23418"},{"key":"10607_CR68","unstructured":"Mi Push (2021). https:\/\/dev.mi.com\/console\/doc\/detail?pId=1244"},{"key":"10607_CR69","unstructured":"Microsoft Edge for Android Information Disclosure Vulnerability (2021). https:\/\/msrc.microsoft.com\/update-guide\/en-US\/vulnerability\/CVE-2021-26439,"},{"key":"10607_CR70","unstructured":"Midtrans (2021). https:\/\/midtrans.com"},{"key":"10607_CR71","unstructured":"Mintegral (2021). https:\/\/www.mintegral.com\/cn\/"},{"key":"10607_CR72","unstructured":"MixPanel (2021). https:\/\/mixpanel.com"},{"key":"10607_CR73","unstructured":"mParticle (2021). https:\/\/www.mparticle.com"},{"key":"10607_CR74","unstructured":"myTracker (2021). https:\/\/tracker.my.com\/promo"},{"key":"10607_CR75","unstructured":"New Relic (2021). https:\/\/newrelic.com"},{"key":"10607_CR76","unstructured":"OAuth 2.0 (2021) https:\/\/oauth.net\/2\/"},{"key":"10607_CR77","unstructured":"Open Weather (2021). https:\/\/openweathermap.org"},{"key":"10607_CR78","unstructured":"Parse (2021). https:\/\/parseplatform.org"},{"key":"10607_CR79","unstructured":"Plaid (2021). https:\/\/plaid.com"},{"key":"10607_CR80","unstructured":"Rate limits: Standard v1.1 (2021). https:\/\/developer.twitter.com\/en\/docs\/twitter-api\/v1\/rate-limits"},{"key":"10607_CR81","unstructured":"Reardon J, Feal \u00c1, Wijesekera P, On AEB, Vallina-Rodriguez N, Egelman S (2019) 50 Ways to leak your data: an exploration of apps\u2019 circumvention of the android permissions system. In: USENIX security symposium (USENIX Security 19) pp 603\u2013620"},{"key":"10607_CR82","unstructured":"reCAPTCHA (2021). https:\/\/www.google.com\/recaptcha\/about\/"},{"key":"10607_CR83","unstructured":"Restricting API keys (2021). https:\/\/developers.google.com\/maps\/documentation\/android-sdk\/get-api-key#restrict_key,"},{"key":"10607_CR84","unstructured":"Saleforce - MarketingCloudSDK (2021). https:\/\/salesforce-marketingcloud.github.io\/MarketingCloudSDK-Android\/"},{"key":"10607_CR85","unstructured":"Sample Size Calculator (2021) https:\/\/www.calculator.net\/sample-size-calculator.html"},{"key":"10607_CR86","unstructured":"Schoology (2021). https:\/\/developers.schoology.com"},{"key":"10607_CR87","unstructured":"Secret tokens found hard-coded in hundreds of Android apps (2024). https:\/\/www.zdnet.com\/article\/secret-tokens-found-hard-coded-in-hundreds-of-android-apps\/"},{"key":"10607_CR88","unstructured":"SecretValidator (2021). https:\/\/github.com\/appsecretleak\/SecretValidator"},{"key":"10607_CR89","unstructured":"Shen B, Wei L, Xiang C, Wu Y, Shen M, Zhou Y, Jin X (2021) Can systems explain permissions better? understanding users\u2019 misperceptions under smartphone runtime permission model. In: USENIX security symposium (USENIX Security)"},{"key":"10607_CR90","unstructured":"Sift (2021). https:\/\/sift.com"},{"key":"10607_CR91","unstructured":"Smali: Assembler for Android\u2019s VM (2021). https:\/\/mobsecguys.medium.com\/smali-assembler-for-dalvik-e37c8eed22f9,"},{"key":"10607_CR92","unstructured":"Stripe (2021). https:\/\/stripe.com"},{"key":"10607_CR93","unstructured":"Tencent Open Platform (2021). https:\/\/open.qq.com\/eng\/"},{"key":"10607_CR94","unstructured":"The Client ID and Secret (2021). https:\/\/www.oauth.com\/oauth2-servers\/client-registration\/client-id-secret\/"},{"key":"10607_CR95","unstructured":"The mobile measurement company - Adjust (2021). https:\/\/www.adjust.com"},{"key":"10607_CR96","unstructured":"They Said So (2021). https:\/\/theysaidso.com\/"},{"key":"10607_CR97","unstructured":"TMap API (2021). https:\/\/tmapapi.sktelecom.com\/index.html"},{"key":"10607_CR98","doi-asserted-by":"crossref","unstructured":"Tuncay GS, Demetriou S, Ganju K, Gunter C (2018) Resolving the predicament of android custom permissions. In: The network and distributed system security symposium (NDSS)","DOI":"10.14722\/ndss.2018.23210"},{"key":"10607_CR99","unstructured":"Twitter Developer Platform (2021). https:\/\/developer.twitter.com\/en"},{"key":"10607_CR100","unstructured":"Unauthorized Google Maps API Key Usage Cases, and Why You Need to Care (2021). https:\/\/ozguralp.medium.com\/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e"},{"key":"10607_CR101","unstructured":"Use CodePush to update your app live (2021). https:\/\/docs.microsoft.com\/en-us\/appcenter\/distribution\/codepush\/"},{"key":"10607_CR102","doi-asserted-by":"crossref","unstructured":"Viennot N, Garcia E, Nieh J (2014) A measurement study of google play. In: ACM international conference on measurement and modeling of computer systems pp 221\u2013233","DOI":"10.1145\/2591971.2592003"},{"key":"10607_CR103","unstructured":"Warning- AWS Credentials exposed on Google Play Console (2024). https:\/\/stackoverflow.com\/questions\/53260569\/warning-aws-credentials-exposed-on-google-play-console"},{"key":"10607_CR104","unstructured":"WeChat Open Platform (2021). https:\/\/open.weixin.qq.com"},{"key":"10607_CR105","unstructured":"Weibo Open Platform (2021). https:\/\/open.weibo.com"},{"key":"10607_CR106","doi-asserted-by":"crossref","unstructured":"Wei L, Liu Y, Cheung S-C (2019) Pivot: learning api-device correlations to facilitate android compatibility issue detection. In: IEEE\/ACM international conference on software engineering (ICSE). IEEE pp 878\u2013888","DOI":"10.1109\/ICSE.2019.00094"},{"key":"10607_CR107","unstructured":"What Is an APK File? (2021). https:\/\/www.lifewire.com\/apk-file-4152929"},{"key":"10607_CR108","unstructured":"Where to keep static information securely in Android app? (2024) https:\/\/stackoverflow.com\/questions\/61724202\/where-to-keep-static-information-securely-in-android-app"},{"key":"10607_CR109","unstructured":"Wijesekera P, Baokar A, Hosseini A, Egelman S, Wagner D, Beznosov K (2015) Android permissions remystified: a field study on contextual integrity. In: USENIX security symposium (USENIX Security) pp 499\u2013514"},{"key":"10607_CR110","unstructured":"Yammi (2021). https:\/\/yammi.io"},{"key":"10607_CR111","unstructured":"YouTube - Google Developers (2021). https:\/\/developers.google.com\/youtube"},{"key":"10607_CR112","doi-asserted-by":"crossref","unstructured":"Zuo C, Lin Z, Zhang Y (2019) Why does your data leak? uncovering the data leakage in cloud from mobile apps. In: IEEE symposium on security and privacy (S &P). IEEE pp 1296\u20131310","DOI":"10.1109\/SP.2019.00009"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-024-10607-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-024-10607-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-024-10607-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,20]],"date-time":"2025-11-20T13:29:36Z","timestamp":1763645376000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-024-10607-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,2]]},"references-count":112,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,5]]}},"alternative-id":["10607"],"URL":"https:\/\/doi.org\/10.1007\/s10664-024-10607-9","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,2]]},"assertion":[{"value":"18 December 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 April 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declared that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of Interest"}}],"article-number":"90"}}