DARKFLEECE: Probing the Dark Side of Android Subscription Apps
DC Field | Value | Language |
---|---|---|
dc.contributor.author | Yue, Chang | - |
dc.contributor.author | Zhong, Chen | - |
dc.contributor.author | Chen, Kai | - |
dc.contributor.author | Zhang, Zhiyu | - |
dc.contributor.author | Lee, Yeonjoon | - |
dc.date.accessioned | 2024-10-08T06:30:19Z | - |
dc.date.available | 2024-10-08T06:30:19Z | - |
dc.date.issued | 2024-08 | - |
dc.identifier.uri | https://scholarworks.bwise.kr/erica/handle/2021.sw.erica/120649 | - |
dc.description.abstract | Fleeceware, a novel category of malicious subscription apps, is increasingly tricking users into expensive subscriptions, leading to substantial financial consequences. These apps' ambiguous nature, closely resembling legitimate subscription apps, complicates their detection in app markets. To address this, our study aims to devise an automated method, named DARKFLEECE, to identify fleeceware through their prevalent use of dark patterns. By recruiting domain experts, we curated the first-ever fleeceware feature library, based on dark patterns extracted from user interfaces (UI). A unique extraction method, which integrates UI elements, layout, and multifaceted extraction rules, has been developed. DARKFLEECE boasts a detection accuracy of 93.43% on our dataset and utilizes Explainable Artificial Intelligence (XAI) to present user-friendly alerts about potential fleeceware risks. When deployed to assess Google Play's app landscape, DARKFLEECE examined 13, 597 apps and identified an alarming 75.21% of 589 subscription apps that displayed different levels of fleeceware, totaling around 5 billion downloads. Our results are consistent with user reviews on Google Play. Our detailed exploration into the implications of our results for ethical app developers, app users, and app market regulators provides crucial insights for different stakeholders. This underscores the need for proactive measures against the rise of fleeceware. © USENIX Security Symposium 2024.All rights reserved. | - |
dc.format.extent | 18 | - |
dc.language | 영어 | - |
dc.language.iso | ENG | - |
dc.publisher | USENIX Association | - |
dc.title | DARKFLEECE: Probing the Dark Side of Android Subscription Apps | - |
dc.type | Article | - |
dc.publisher.location | 미국 | - |
dc.identifier.scopusid | 2-s2.0-85204974792 | - |
dc.identifier.bibliographicCitation | Proceedings of the 33rd USENIX Security Symposium, pp 1543 - 1560 | - |
dc.citation.title | Proceedings of the 33rd USENIX Security Symposium | - |
dc.citation.startPage | 1543 | - |
dc.citation.endPage | 1560 | - |
dc.type.docType | Conference paper | - |
dc.description.isOpenAccess | N | - |
dc.description.journalRegisteredClass | scopus | - |
dc.identifier.url | https://www.usenix.org/conference/usenixsecurity24/presentation/yue | - |
Items in ScholarWorks are protected by copyright, with all rights reserved, unless otherwise indicated.
55 Hanyangdeahak-ro, Sangnok-gu, Ansan, Gyeonggi-do, 15588, Korea+82-31-400-4269 sweetbrain@hanyang.ac.kr
COPYRIGHT © 2021 HANYANG UNIVERSITY. ALL RIGHTS RESERVED.
Certain data included herein are derived from the © Web of Science of Clarivate Analytics. All rights reserved.
You may not copy or re-distribute this material in whole or in part without the prior written consent of Clarivate Analytics.