{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T17:11:33Z","timestamp":1776100293295,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":66,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3744877","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:33:16Z","timestamp":1763854396000},"page":"1275-1289","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Fingerprinting SDKs for Mobile Apps and Where to Find Them: Understanding the Market for Device Fingerprinting"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7662-4042","authenticated-orcid":false,"given":"Michael A.","family":"Specter","sequence":"first","affiliation":[{"name":"Georgia Tech, Atlanta, GA, USA and Google LLC, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5808-8015","authenticated-orcid":false,"given":"Mihai","family":"Christodorescu","sequence":"additional","affiliation":[{"name":"Google LLC, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1969-349X","authenticated-orcid":false,"given":"Abbie","family":"Farr","sequence":"additional","affiliation":[{"name":"Google LLC, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-6510-6707","authenticated-orcid":false,"given":"Bo","family":"Ma","sequence":"additional","affiliation":[{"name":"Google LLC, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-2164-5514","authenticated-orcid":false,"given":"Robin","family":"Lassonde","sequence":"additional","affiliation":[{"name":"Google LLC, Mountain View, CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"* * *. The Privacy Sandbox : Technology for a More Private Web. Available online at https:\/\/privacysandbox.com\/intl\/en_us. Last visited: 2024-09-30."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2708685"},{"key":"e_1_3_2_1_3_1","unstructured":"Apple. Describing data use in privacy manifests."},{"key":"e_1_3_2_1_4_1","unstructured":"Apple. Describing use of required reason api. Available online at https:\/\/developer.apple.com\/documentation\/bundleresources\/privacy_manifest_files\/describing_use_of_required_reason_api. Last visited: 2024-09-30."},{"key":"e_1_3_2_1_5_1","unstructured":"Apple. User Privacy and Data Use - App Store. Available online at https:\/\/developer.apple.com\/app-store\/user-privacy-and-data-use\/. Last visited: 2024-09-30."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978333"},{"key":"e_1_3_2_1_7_1","volume-title":"Fp-radar: Longitudinal measurement and early detection of browser fingerprinting","author":"Bahrami Pouneh Nikkhah","year":"2021","unstructured":"Pouneh Nikkhah Bahrami, Umar Iqbal, and Zubair Shafiq. Fp-radar: Longitudinal measurement and early detection of browser fingerprinting, 2021."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-25512-5_12"},{"key":"e_1_3_2_1_9_1","volume-title":"Mobile device identification via sensor fingerprinting","author":"Bojinov Hristo","year":"2014","unstructured":"Hristo Bojinov, Yan Michalevsky, Gabi Nakibly, and Dan Boneh. Mobile device identification via sensor fingerprinting, 2014."},{"key":"e_1_3_2_1_10_1","volume-title":"Andres Mu\u00f1oz Medina, and Umar Syed. Private and communication-efficient algorithms for entropy estimation","author":"Bravo-Hermsdorff Gecia","year":"2023","unstructured":"Gecia Bravo-Hermsdorff, R\u00f3bert Busa-Fekete, Mohammad Ghavamzadeh, Andres Mu\u00f1oz Medina, and Umar Syed. Private and communication-efficient algorithms for entropy estimation, 2023."},{"key":"e_1_3_2_1_11_1","volume-title":"Experimental and quasi-experimental designs for research. Ravenio books","author":"Campbell Donald T","year":"2015","unstructured":"Donald T Campbell and Julian C Stanley. Experimental and quasi-experimental designs for research. Ravenio books, 2015."},{"key":"e_1_3_2_1_12_1","volume-title":"Network and Distributed System Security Symposium","author":"Cao Yinzhi","year":"2017","unstructured":"Yinzhi Cao, Song Li, and Erik Wijmans. (cross-)browser fingerprinting via os and hardware level features. In Network and Distributed System Security Symposium, 2017."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS.2017.00016"},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS '14","author":"Das Anupam","year":"2014","unstructured":"Anupam Das, Nikita Borisov, and Matthew Caesar. Do you hear what I hear? fingerprinting smart devices through embedded acoustic components. In Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, CCS '14, New York, NY, USA, 2014. Association for Computing Machinery."},{"key":"e_1_3_2_1_15_1","volume-title":"Exploring ways to mitigate sensor-based smartphone fingerprinting","author":"Das Anupam","year":"2015","unstructured":"Anupam Das, Nikita Borisov, and Matthew Caesar. Exploring ways to mitigate sensor-based smartphone fingerprinting, 2015."},{"key":"e_1_3_2_1_16_1","volume-title":"Romit Roy Choudhury, and Srihari Nelakuditi. Accelprint: Imperfections of accelerometers make smartphones trackable","author":"Dey Sanorita","year":"2014","unstructured":"Sanorita Dey, Nirupam Roy, Wenyuan Xu, Romit Roy Choudhury, and Srihari Nelakuditi. Accelprint: Imperfections of accelerometers make smartphones trackable. In NDSS. The Internet Society, 2014."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3360664.3360671"},{"key":"e_1_3_2_1_18_1","first-page":"1","volume-title":"How unique is your web browser? In Mikhail J","author":"Eckersley Peter","year":"2010","unstructured":"Peter Eckersley. How unique is your web browser? In Mikhail J. Atallah and Nicholas J. Hopper, editors, Privacy Enhancing Technologies, pages 1-18, Berlin, Heidelberg, 2010. Springer Berlin Heidelberg."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978313"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-20810-7_21"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-98989-1_4"},{"key":"e_1_3_2_1_22_1","unstructured":"Google. Play Console Help: Example categories. Online at https:\/\/support.google.com\/googleplay\/android-developer\/answer\/9859673."},{"key":"e_1_3_2_1_23_1","unstructured":"Google. Play console help: View app statistics. Online at https:\/\/support.google.com\/googleplay\/android-developer\/answer\/139628?hl=en&co=GENIE.Platform%3DAndroid."},{"key":"e_1_3_2_1_24_1","unstructured":"Google. Provide information for google play's data safety section."},{"key":"e_1_3_2_1_25_1","unstructured":"Google. SDK Runtime overview."},{"key":"e_1_3_2_1_26_1","volume-title":"Google play sdk index. Online at https:\/\/play.google.com\/sdks","year":"2024","unstructured":"Google. Google play sdk index. Online at https:\/\/play.google.com\/sdks, 2024."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0050"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.5555\/3288994.3289051"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3590777.3590790"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818032"},{"key":"e_1_3_2_1_31_1","volume-title":"Formal analysis of the api proxy problem","author":"Jha Somesh","year":"2023","unstructured":"Somesh Jha, Mihai Christodorescu, and Anh Pham. Formal analysis of the api proxy problem, 2023."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2005.26"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0033"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176313"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1515\/popets-2015-0027"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2017.38"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-16-9229-1_4"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2019.2933269"},{"key":"e_1_3_2_1_39_1","first-page":"656","volume-title":"Proceedings of the 38th International Conference on Software Engineering Companion, ICSE '16","author":"Ma Ziang","year":"2016","unstructured":"Ziang Ma, Haoyu Wang, Yao Guo, and Xiangqun Chen. Libradar: Fast and accurate detection of third-party libraries in android apps. In Proceedings of the 38th International Conference on Software Engineering Companion, ICSE '16, page 653\u2013656, New York, NY, USA, 2016. Association for Computing Machinery."},{"key":"e_1_3_2_1_40_1","volume-title":"Chad Brubaker, Dianne Hackborn, Bram Bonn\u00e9, G\u00fcliz Seray Tuncay, Roger Piqueras Jover, and Michael A. Specter. The android platform security model","author":"Mayrhofer Ren\u00e9","year":"2023","unstructured":"Ren\u00e9 Mayrhofer, Jeffrey Vander Stoep, Chad Brubaker, Dianne Hackborn, Bram Bonn\u00e9, G\u00fcliz Seray Tuncay, Roger Piqueras Jover, and Michael A. Specter. The android platform security model (2023), 2021."},{"key":"e_1_3_2_1_41_1","volume-title":"Hardware fingerprinting using html5","author":"Nakibly Gabi","year":"2015","unstructured":"Gabi Nakibly, Gilad Shelef, and Shiran Yudilevich. Hardware fingerprinting using html5, 2015."},{"key":"e_1_3_2_1_42_1","volume-title":"Proceedings of the 24th International Conference on World Wide Web, WWW '15","author":"Nikiforakis Nick","year":"2015","unstructured":"Nick Nikiforakis, Wouter Joosen, and Benjamin Livshits. Privaricator: Deceiving fingerprinters with little white lies. In Proceedings of the 24th International Conference on World Wide Web, WWW '15, 2015."},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.43"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-29883-2_18"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/3407023.3407055"},{"key":"e_1_3_2_1_46_1","first-page":"470","volume-title":"Proceedings, Part I","author":"Quiring Erwin","year":"2019","unstructured":"Erwin Quiring, Matthias Kirchner, and Konrad Rieck. On the security and applicability of fragile camera fingerprints. In Computer Security \u2013 ESORICS 2019: 24th European Symposium on Research in Computer Security, Luxembourg, September 23\u201327, 2019, Proceedings, Part I, page 450\u2013470, Berlin, Heidelberg, 2019. Springer-Verlag."},{"key":"e_1_3_2_1_47_1","volume-title":"Network and Distributed System Security Symposium","author":"Ren Jingjing","year":"2018","unstructured":"Jingjing Ren, Martina Lindorfer, Daniel J. Dubois, Ashwin Rao, David R. Choffnes, and Narseo Vallina-Rodriguez. Bug fixes, improvements, ... and privacy leaks - a longitudinal study of pii leaks across android app versions. In Network and Distributed System Security Symposium, 2018."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243796"},{"key":"e_1_3_2_1_49_1","volume-title":"Fingerprinting sdks for mobile apps and where to find them: Understanding the market for device fingerprinting. Online at https:\/\/arxiv.org\/abs\/2506.22639","author":"Specter Michael A.","year":"2025","unstructured":"Michael A. Specter, Mihai Christodorescu, Abbie Farr, Bo Ma, Robin Lassonde, Xiaoyang Xu, Xiang Pan, Fengguo Wei, Saswat Anand, and Dave Kleidermacher. Fingerprinting sdks for mobile apps and where to find them: Understanding the market for device fingerprinting. Online at https:\/\/arxiv.org\/abs\/2506.22639, 2025."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196510"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.18"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3131408"},{"key":"e_1_3_2_1_53_1","first-page":"415","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Tuncay G\u00fcliz Seray","year":"2020","unstructured":"G\u00fcliz Seray Tuncay, Jingyu Qian, and Carl A. Gunter. See no evil: Phishing for permissions with false transparency. In 29th USENIX Security Symposium (USENIX Security 20), pages 415-432. USENIX Association, August 2020."},{"issue":"86","key":"e_1_3_2_1_54_1","first-page":"2579","article-title":"Visualizing data using t-sne","volume":"9","author":"van der Maaten Laurens","year":"2008","unstructured":"Laurens van der Maaten and Geoffrey Hinton. Visualizing data using t-sne. Journal of Machine Learning Research, 9(86):2579-2605, 2008.","journal-title":"Journal of Machine Learning Research"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-30806-7_7"},{"key":"e_1_3_2_1_56_1","volume-title":"2018 IEEE\/ACM 5th International Conference on Mobile Software Engineering and Systems (MOBILESoft)","author":"Wang Yan","year":"2018","unstructured":"Yan Wang, Haowei Wu, Hailong Zhang, and Atanas Rountev. Orlis: Obfuscation-resilient library detection for android. In 2018 IEEE\/ACM 5th International Conference on Mobile Software Engineering and Systems (MOBILESoft), 2018."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.23915\/distill.00002"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2016.2626395"},{"issue":"1","key":"e_1_3_2_1_59_1","first-page":"167","article-title":"Rapid, online, and accurate detection of tpls on android","volume":"21","author":"Xu Jian","year":"2022","unstructured":"Jian Xu and Qianting Yuan. Libroad: Rapid, online, and accurate detection of tpls on android. IEEE Transactions on Mobile Computing, 21(1):167-180, 2022.","journal-title":"IEEE Transactions on Mobile Computing"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE43902.2021.00150"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3324884.3416582"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3114381"},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2021.3115506"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00072"},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3039685"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660300"}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3744877","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:17:58Z","timestamp":1766441878000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3744877"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":66,"alternative-id":["10.1145\/3719027.3744877","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3744877","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}