Oct 2026· Proceedings on Privacy Enhancing Technologies· Vol 2026, pp. 772-792· 0 citations· 150 references
Computer Science
TL;DR
A substantial misalignment between the privacy expectations of military-affiliated personnel and the data practices and software supply chains of MMMapps is revealed and recommendations are proposed to improve privacy risk mitigation for this at-risk population.
Abstract
A subset of mobile applications is explicitly marketed to military-affiliated personnel. These Military-Marketed Mobile Apps (MMM-apps) collect privacy-sensitive data using the same mechanisms as general-purpose apps. However, when such data belongs to military-affiliated personnel, it may be exploited by malicious actors in ways that threaten personal safety, unit operations, and national security. Despite these risks, the data practices and code provenance of MMMapps, as well as how this population perceives and attempts to mitigate these risks, remain poorly understood. In this paper, we address this gap by combining large-scale app analysis with a user study. We first curate a dataset of 242 MMMapps and leverage app analysis techniques to characterize their data practices and code provenance. Then, we conduct a user study with n = 103 military-affiliated participants in the United States to examine which data practices and code provenance characteristics they consider inappropriate, what threat scenarios they believe those practices enable, and which mitigations they view as most effective. Our results show that MMMapps frequently exhibit data practices and code provenance characteristics that are misaligned with the privacy expectations of military-affiliated personnel. For instance, 40% of MMMapps collect more data than they disclose in their privacy labels or data safety sections. 83.5% of our study participants report using at least one MMMapp that engages in data practices they are uncomfortable with. Additionally, although military-affiliated personnel are generally concerned about third-party libraries accessing their data, 64% of MMMapps include third-party SDKs, some developed in countries perceived as adversarial by a majority of the participants. Overall, our findings reveal a substantial misalignment between the privacy expectations of military-affiliated personnel and the data practices and software supply chains of MMMapps. We propose recommendations at the federal, DoD, app store, and device levels to improve privacy risk mitigation for this at-risk population.
The augmented multi-party shuffle DP (AMP-SDP) model is proposed, which re-architects the data pipeline with a lightweight, versatile secret-shared intermediary layer that decentralizes trust while minimizing online communication costs and provides structural security hardening against both shuffler compromise and user-sid...
Wentao Dong, Yang Cao, Cong Wang et al.· 0 citations
With the rapid development and widespread application of big data technologies, while personal data generates immense social value, the risk of privacy breaches is also escalating. How to effectively protect personal privacy while ensuring data usability has become a central issue of shared societal concern. Existing r...
Zhen-Yuan Zhou· Applied and Computational En...· 0 citations
This review synthesizes the research literature relevant to building such applications, with specific attention to the cross-platform reality in which much of the mobile ecosystem, prominently React Native applications, is actually built, and identifies directions for research and practice.
Serif Oyindamola Oyesiji, Kingsley Chinazaekpere Ndupu, Chukwudera Obumneke Anunagba et al.· Journal of Engineering Resea...· 0 citations
Private AI is used in this paper as a deployment-based umbrella term for AI systems whose data and computation are constrained within a defined trust boundary. That boundary may be local or on-device, on-premises or private-network infrastructure, a private or dedicated cloud, or a managed cloud service that provides l...
Karim Mualla· International Journal of Eth...· 0 citations
Cloud computing is increasingly leveraged by Bangladeshi organizations, including utilities, financial institutions, and technology firms, for scalable data storage and analytic capabilities. However, migrating sensitive operational and personal data to cloud environments introduces serious privacy challenges. This stu...
Moskura Hoque, Mostofa Kamal Nasir· MBSTU Journal of Science and...· 0 citations
Recommendations for the design and deployment of secure LLM-enabled XR systems, emphasizing strategies such as security defense in depth, privacy-aware data practices, layered technical safeguards, continuous monitoring, and governance mechanisms that align security controls with the specific risks of immersive and int...