SANER 2026
Tue 17 - Fri 20 March 2026 Limassol, Cyprus

Mobile logging libraries are essential tools for debugging and monitoring Android applications, yet their privacy implications remain largely unexplored. This paper presents the first large-scale empirical study of privacy risks in Android logging practices, analyzing 48,702 applications from Google Play to identify sensitive data leakage through third-party logging frameworks. Our findings indicate that while only 3.4% of applications use third-party logging, nearly half (49.3%) of logging-enabled apps exhibit privacy leaks, with three dominant libraries, such as Timber, SLF4J, and Firebase, accounting for 99.7% of violations. Analysis reveals that privacy leaks predominantly stem from indirect data flows (62.5%) with moderate complexity (2-4 statements), originating primarily from user-info sources, although user-input sources represent a substantial risk. Distinct logging patterns emerge across frameworks: SLF4J shows balanced log level distribution, Timber concentrates heavily on DEBUG levels (78.5%), and Firebase is dominated by Analytics Events (98.0%). Longitudinal analysis demonstrates improving privacy practices over time (68.2% of apps reduced leaks), though persistent vulnerabilities underscore the need for systematic protection measures. This study identifies logging-based privacy risks in Android applications and provides actionable insights for developers and library maintainers. It highlights the critical need for practitioners to address both user information and user input as significant privacy threats when using third-party logging frameworks in Android applications.

Wed 18 Mar

Displayed time zone: Athens change

16:00 - 17:30
Session 3B - Evolution and Security of Mobile SystemsResearch Track / Short Papers and Posters Track at Megaron Beta
Chair(s): Vadim Zaytsev University of Twente
16:00
15m
Talk
Relocate and Emulate: Re-Hosting Android’s Application Layer
Research Track
Thomas Sutter University of Bern, Timo Kehrer University of Bern, Marc Rennhard Zurich University of Applied Sciences, Bernhard Tellenbach Armasuisse Cyber-Defence Campus
16:15
15m
Talk
Scratching the Iceberg: Unveiling the Outdated Third-Party Native Libraries in Android Apps
Research Track
Shiyang Zhang Tianjin University, Chengwei Liu Nankai University, Sen Chen Nankai University, Lyuye Zhang Nanyang Technological University, Yang Liu Nanyang Technological University
16:30
15m
Talk
Dialing Danger: Large-Scale Mining and Risk Assessment of Android Secret Codes in OEM Firmware
Research Track
Ruoyan Lin Shandong University, Shishuai Yang Zhengzhou University of Aeronautics, Fenghao Xu Southeast University, Wenrui Diao Shandong University
16:45
15m
Talk
InstruMate: A Systematic Framework for Assessing Android App Repackaging Resilience
Research Track
Leandro de Souza Oliveira , Rodrigo Bonifácio Informatics Center - CIn/UFPE and Computer Science Department / University of Brasília, Joanna C. S. Santos University of Notre Dame, Rui Rua New York University Abu Dhabi
17:00
15m
Talk
An Empirical Study of Privacy Leakage Vulnerability in Third-Party Android Logs Libraries
Research Track
Yixi Zhao University of Waterloo, Kundi Yao Ontario Tech University, Yiming Tang Rochester Institute of Technology, Weiyi Shang University of Waterloo
17:15
7m
Talk
AMF-GR: Adaptive Matrix Factorization and Graph Fusion for Android Library Recommendation
Short Papers and Posters Track
Abhinav Jamwal Dept. of Computer Science & Engineering, Indian Institute of Technology, Roorkee, India, Sandeep Kumar Dept. of Computer Science & Engineering, Indian Institute of Technology, Roorkee, India
17:22
7m
Talk
BUPLinker: Bridging Users and Developers in Mobile Application Evolution
Short Papers and Posters Track
Ayana Uematsu Waseda University, Hironori Washizaki Waseda University, Naoyasu Ubayashi Waseda University, Masanari Kondo Kyushu University, Juichi Takahashi AGEST, Inc, Yohei Takagi AGEST Inc.