← 资料库索引 ← 论文 原始链接 ↗ 🔍
论文

《On the Difficulty of NOT being Unique: Fingerprinting Users from Wi-Fi Data in Mobile Devices》(论「不唯一」之难:从移动设备 Wi-Fi 数据对用户进行指纹识别) 原文标题:On the Difficulty of NOT being Unique: Fingerprinting Users from Wi-Fi Data in Mobile Devices

发表时间:2025-03-31采集时间:2026-10-09 11:00:41来源:www.dcc.fc.up.pt原文语言:en状态:完整

内容概要总结

ACM SAC '25 会议论文(葡萄牙波尔图大学、科英布拉大学、帝国理工学院等)。研究从「用户视角」(即用户手机上已安装的应用)出发,论证即使智能手机不断收紧对唯一标识符(ID)的访问,应用仍可利用 Wi-Fi 扫描数据把用户指纹化,构成事实上的唯一 ID。

数据来自 COP-MODE 实地研究数据集:93 名用户、至少携带一周,共 2180302 次权限请求,其中 41602 次(来自 82 名用户)含 Wi-Fi 和/或位置信息。核心结论:单次 Wi-Fi BSSID(MAC 地址)扫描快照即可唯一识别约 99% 的用户,三次快照达 100%;出现频率最高的 BSSID 足以重识别 >90% 用户,top-2 达 97%;取信号最强 Wi-Fi AP 时,1 个和 2 个 SSID 分别带来约 83%、97% 重识别风险,BSSID 则分别为 94%、99%。k-匿名分析显示 18613 个唯一 BSSID 中有 16064 个(86%)仅被单个用户扫描到,81/82 用户至少扫到过其中之一,即可被重识别。

论文据此呼吁限制数据采集、系统性评估重识别风险、引入匿名化与自动化隐私保护,并指出 Android 上 ACCESS_WIFI_STATE、CHANGE_WIFI_STATE 等 Wi-Fi 权限属安装时权限、自动授予且不可撤销,是风险根源。

翻译内容

原文内容(English)

⚠ 说明:原文为 ACM SAC '25 会议论文 PDF。原始引用链接 www.dcc.fc.up.pt/~joaovilela/publications/sac2025.pdf 直连报证书链错误,改用浏览器 UA 下载 PDF + pdftotext 提取正文。参考文献条目按惯例保留原文(英文),未逐条翻译。

Mariana Cunha —— CRACS/INESC TEC、CISUC、波尔图大学理学院计算机科学系,葡萄牙波尔图,mccunha@dei.uc.pt

Ricardo Mendes —— CISUC、科英布拉大学信息工程系,葡萄牙科英布拉,rscmendes@dei.uc.pt

Yves-Alexandre de Montjoye —— 伦敦帝国理工学院,Exhibition Road, South Kensington,伦敦,英国,demontjoye@imperial.ac.uk

João P. Vilela —— CRACS/INESC TEC、CISUC、波尔图大学理学院计算机科学系,葡萄牙波尔图,jvilela@fc.up.pt

摘要

移动设备的普及催生了大量服务与应用,但也引发了严重的隐私担忧。为避免用户被追踪和/或被指纹识别,智能手机一直在收紧对唯一标识符(unique identifiers)的访问。然而,智能手机应用仍可从可用传感器与手机资源中采集各类数据。本文利用我们开展的一项实地研究(field study)的真实数据,证明了从移动设备的 Wi-Fi 数据对用户进行指纹识别的可能性及其隐私影响。根据所做的分析,我们得出结论:每位用户单次快照(single snapshot)所扫描的 Wi-Fi BSSID(MAC 地址)集合,就足以唯一识别约 99% 的用户。此外,出现频率最高的 Wi-Fi BSSID 就足以重识别超过 90% 的用户,若取扫描频次最高的前 2 个 BSSID,这一比例升至 97%。Wi-Fi SSID(网络名)在取信号最强的 1 个和 2 个 Wi-Fi 接入点(AP)时,也分别带来约 83% 和 97% 的重识别风险。

CCS 概念:· 安全与隐私 —— 安全与隐私的人文与社会层面;· 以人为中心的计算 —— 普适与移动计算;

关键词:隐私、移动设备、指纹识别、重识别风险、Wi-Fi

ACM 引用格式:Mariana Cunha, Ricardo Mendes, Yves-Alexandre de Montjoye, and João P. Vilela. 2025. On the Difficulty of NOT being Unique: Fingerprinting Users from Wi-Fi Data in Mobile Devices. In The 40th ACM/SIGAPP Symposium on Applied Computing (SAC '25), March 31-April 4, 2025, Catania, Italy. ACM, New York, NY, USA, 8 pages. https://doi.org/10.1145/3672608.3707966

本作品采用 Creative Commons 4.0 国际许可协议授权。SAC '25, March 31-April 4, 2025, Catania, Italy © 2025 版权归所有者/作者持有。ACM ISBN 979-8-4007-0629-5/25/03 https://doi.org/10.1145/3672608.3707966

1 引言

智能手机在当今数字社会中的普及,为在众多场景下采集海量异构数据带来了丰富机会。这些数据对用户和服务都有益,但也可能包含敏感信息、引发严重的隐私担忧 [11]。在智能手机语境下,多项研究已证明数据可能通过应用 [6, 38]、日志 [28] 以及权限滥用 [2, 4, 21, 44](例如未经许可的位置追踪)等方式泄露。此外,近期新闻 [9, 23] 报道了隐私泄露的实例:应用被用来在未经用户同意的情况下采集旁侧信息(side information),例如 Wi-Fi 数据。

为增强用户对其个人数据的控制与权利,信息隐私法规相继出台,即欧盟的《通用数据保护条例》(GDPR)[18]。在实践中,智能手机通过权限管理器赋予用户一定控制权,用户可允许/拒绝权限及其对手机数据/资源的访问。然而,在规制与保护用户隐私时,主要挑战之一是对唯一标识符(ID)的访问。就此而言,Android 为开发者定义了关于选择和使用唯一 ID 的最佳实践 [14],例如选择用户可重置的 ID、避免使用硬件 ID,或尊重广告 ID 的用途。最新版本的 Android [5] 将硬件标识符(如 IMEI 和序列号)的访问限制为:设备或配置文件所有者(device/profile owner)应用、拥有特殊运营商权限的应用,或拥有 READ_PRIVILEGED_PHONE_STATE 特权权限的应用 [14]。

尽管在赋能用户重掌数据控制权方面有所进展 [27, 30],智能手机当前的权限模型仍有局限,未能考虑数据关联性与上下文依赖性。例如,访问位置数据的权限被视为运行时/危险权限、需要权限提示,但通过 Wi-Fi [2, 4, 49] 或蓝牙等旁侧信息获取位置,仍可在无显式权限的情况下实现 [44]。这引发了超越人身安全的严重隐私担忧,因为人类移动轨迹高度唯一,可能暴露用户身份、习惯、社会关系甚至健康状况 [7, 12, 36]。考虑到这一点,本文证明:即使其他类型的标识符被禁止访问,智能手机应用可获取的数据(如 Wi-Fi 接入点(AP)的 BSSID 与 SSID)仍可作为用户指纹。

本文展示通过已安装的智能手机应用(即从用户视角)访问 Wi-Fi 数据所带来的指纹识别与重识别风险。尽管人们努力避免使用其他更显式的唯一标识符、并知晓访问此类数据会带来众所周知的风险,我们仍得出结论:Wi-Fi 数据可以被用作唯一标识符来对用户进行指纹识别。直到 Android 9(约 2018 年),访问 Wi-Fi 数据只需安装时权限(install-time permissions),这意味着用户既无感知、也无法撤销该访问。这一问题普遍存在于其他仍允许访问位置或 Wi-Fi 数据的设备上(例如笔记本电脑)。尽管较新的 Android 权限有所改进,但事实是:99% 的智能手机应用仍会请求完整网络访问、72% 的应用可查看 Wi-Fi 连接、三分之一的应请求位置权限 [16],这凸显了探究通过位置与 Wi-Fi 数据对用户进行指纹识别的重要性。

为此,我们依赖于一项实地研究采集的真实数据,参与者携带我们的智能手机至少一周 [29, 30]。基于通过智能手机应用采集的上下文数据(如位置与扫描到的 Wi-Fi 设备),我们进行指纹识别与重识别分析。本文证明,用 Wi-Fi 数据对用户进行指纹识别是可行的:对于单次扫描的 Wi-Fi BSSID 快照(即攻击者仅持有一组扫描到的 Wi-Fi BSSID),约 99% 的用户被重识别。当考虑攻击者掌握信号最强的 Wi-Fi AP 信息时,使用信号强度最高的 1 个和 2 个 SSID/网络名,分别有近 83% 和 97% 的用户被重识别;而使用信号强度最高的 1 个和 2 个 BSSID 时,这一比例为 94% 和 99%。与这些结果一致,重识别风险评估显示:82 名用户中有 81 名至少单次扫描到过某个 Wi-Fi BSSID(MAC 地址),出现频率最高的 AP 足以重识别超过 90% 的用户,前 2 个被扫描的 BSSID 足以重识别超过 97% 的用户。类似地,取 Wi-Fi SSID、Wi-Fi 位置或 GPS 位置的前 4 项,即可重识别超过 95% 的用户(与先前工作 [12] 一致)。这凸显了访问 Wi-Fi 信息的隐私风险,也呼吁提高用户隐私意识,并研发能兼顾异构数据源之间数据关联性的隐私保护机制。

本文其余部分组织如下。第 2 节概述背景概念与相关工作;第 3 节详述数据集;第 4 节给出所进行的指纹识别分析,并通过重识别指标评估隐私风险;第 5 节讨论 Wi-Fi 指纹识别的隐私影响及相应的隐私保护策略;第 6 节给出主要结论。全文中,智能手机应用有时简称为 app。

2 背景与相关工作

智能手机日益增长且不可或缺的使用,带来了对各类个人与敏感数据的访问。这催生了考虑用户画像与偏好的个性化服务与新应用。应用以「提供更贴合用户的更好服务」为名,从移动设备采集个人可识别信息(PII),例如唯一标识符(ID),用以区分设备/用户,同时也用于追踪它们 [33, 47]。

Android 操作系统(OS)提供了若干 ID,它们在以下方面具有不同特性:作用域(即哪些系统可访问该 ID)、可重置性与持久性(即 ID 的生命周期及其重置方式)、唯一性(即发生碰撞的可能性),以及完整性保护与不可否认性(即难以伪造的 ID)[14]。为确保所提供的 ID 被妥善处理,Android 为开发者定义了关于选择和使用唯一 ID 的最佳实践 [14],例如选择用户可重置的 ID、避免硬件 ID,或尊重广告 ID 的用途。最新版本的 Android [5] 将硬件标识符(如 IMEI 和序列号)的访问限制为:设备/配置文件所有者应用(即对设备或特定配置文件拥有管理控制权的应用)、拥有特殊运营商权限(即仅限于与移动运营商关联应用的权限)的应用,或拥有仅对固件内置或设备制造商安装的系统应用开放的特殊特权权限(READ_PRIVILEGED_PHONE_STATE)的应用。

尽管有上述约束与处理 Android ID 的官方指南 [14],先前研究已证明,唯一 ID——特别是持久 ID——仍在被访问并常被用于追踪用户 [31, 37, 38]。[31] 的作者识别出 51 个独特漏洞,证明在最新 Android 手机上普遍存在对用户不可重置标识符(UUIs)的错误处理。本文进一步证明:当前的对策并不充分,且忽视了通过其他较不显式的 ID 识别用户的风险。特别是,我们得出结论:Wi-Fi 数据可被用作唯一标识符来对用户进行指纹识别。

由于暴露唯一 ID 的隐私影响,当前研究一直在考察多种场景下人类行为的唯一性 [52],包括移动应用使用数据 [1, 26, 42, 46] 与移动模式 [8, 12]。就移动应用使用数据而言,仅四个应用就足以唯一重识别约 90% 的用户 [1, 42, 46]。对该数据的分析更进一步,可以重识别出学生是否抑郁 [3]。自 Android 11(约 2020 年)起,在应用内访问已安装应用默认被过滤,需要 QUERY_ALL_PACKAGES 权限才能查询设备上全部已安装应用 [15]。

在移动模式方面,位置数据的唯一性已成为一项令人担忧的挑战。人类移动轨迹高度唯一,使得推断用户身份、习惯、社会关系甚至健康状况成为可能 [7]。事实上,四个时空点就足以重识别约 95% 的个体 [8, 12]。这促使智能手机 OS 通过要求访问精细或粗略位置的权限来保护位置数据的采集。然而,这些权限仍常被请求(三分之一的应请求 [16]),且拥有此类数据访问权的应用能够用位置构建指纹来唯一识别用户 [25]。

受大量可访问 Wi-Fi 信息的智能手机应用 [16] 的启发,我们区别于先前工作,证明此类信息的唯一性以及通过扫描到的 Wi-Fi 接入点创建指纹的可能性。尽管从 Wi-Fi [34] 等旁侧信息推断位置的风险、以及通过 Wi-Fi 的移动轨迹唯一性 [8] 已广为人知,我们的工作不同之处在于聚焦用户视角(即用户智能手机上安装的应用),以及扫描到的 Wi-Fi AP 的采集如何构成一个唯一 ID。我们的目标是展示通过 Wi-Fi 信息对用户进行指纹识别的隐私影响,并评估扫描此类数据带来的重识别风险。

相比之下,既有文献主要从 Wi-Fi 接入点或其他能监控无线网络的实体的视角研究设备指纹 [50]。指纹通常被依赖相关特征来识别设备的设备识别系统所使用。尽管使用设备指纹增强无线安全有潜在益处,多项研究已证明:不仅能追踪用户/设备,还能利用可获取的数据(例如用户设备发出的、包含唯一标识发送设备的 MAC 地址的 Wi-Fi 探测请求(probe requests)[10, 20])来推断附近用户的信息 [32, 39, 45]。特别是,MAC 地址随机化正是为应对由此产生的隐私侵害而出现的 [48]。与这些研究不同,本文考察的是通过用户设备上安装的应用、从 Wi-Fi 数据中进行指纹识别的另一个视角(用户视角),强调扫描到的 Wi-Fi AP 所带来的重识别风险,并探究 Wi-Fi 数据如何在移动设备中构成一个唯一 ID。

3 数据集与概览

本节首先描述用于研究通过 Wi-Fi 数据对用户进行指纹识别的隐私影响及由此产生的重识别风险的数据集,随后分析已安装应用与所请求权限。

3.1 数据集特征

为在智能手机语境下研究用户的指纹识别,我们选用了 COP-MODE 数据集 [29, 30]。该数据集来自一项有 93 名用户的真实世界实地研究,参与者携带智能手机至少一周,手机上预装了其个人应用,以及一个负责数据采集的应用。该应用在每次权限检查时提示用户(见图 1),并采集用户的输入以及提示时的其他上下文特征。本文聚焦于对本工作相关的特定上下文特征,即:

  • Datetime:权限请求提示的时间戳。
  • Location:时间戳、纬度、经度与精度。
  • Wi-Fi:每个被扫描设备的时间戳、BSSID、SSID 与 RSSI。
  • Semantic location(语义位置):语义位置来自用户输入,可能取值为:home(家)、work(工作)、traveling(出行)或 other(其他)。

图 1:因应用 WhatsApp 检查联系人权限而弹出的权限提示示例。

需要指出,位置数据与「最后已知位置」读取相关 [13],可能并不对应当前位置,因为参与者可能已关闭定位。就 Wi-Fi 数据而言,被扫描的 Wi-Fi 设备对应于通过每 5 分钟尝试一次扫描所获得的周边设备。这些因素将在随后的探索性数据分析中加以考虑。

COP-MODE 数据集由来自 93 名参与者的 2180302 次权限请求构成。其中 65261 次(占总请求的 2.99%)被参与者回答,其余要么未被处理,要么由 30 分钟缓存、超时或忽略作答。本工作中,我们只考虑用户已作答的请求,因为只有这些才带有选定的语义位置。在 65261 次已作答请求中,有 41602 次请求(占已作答请求的 63.75%)带有 Wi-Fi 和/或位置信息,来自共计 82 名参与者。该数据构成本文的分析对象。

3.2 已安装应用与所请求权限

为更好地理解可访问 Wi-Fi 数据的应用、进而理解该问题的严重性,我们首先研究已安装应用与所请求权限的语境。在 Android 中,应用分为系统应用(即拥有系统特权的应用)与非系统应用(即权限受限的应用)。COP-MODE 数据集共含 3926 个不同应用与 1737 个不同的非系统应用。关于所请求权限,我们现在分析哪些应用请求了访问 Wi-Fi 数据所需的权限,以及相应的授予/拒绝结果。

随着新 Android 版本的发布,扫描附近 Wi-Fi 设备的方式一直在变化,首个强制性位置限制在 Android 9 中引入。考虑到 COP-MODE 数据集是在 Android 9 设备上采集的,应用需要 ACCESS_COARSE_LOCATION 或 ACCESS_FINE_LOCATION 权限,外加 CHANGE_WIFI_STATE 权限才能启动 Wi-Fi 设备扫描,并需要 ACCESS_WIFI_STATE 权限才能获取被扫描到的 Wi-Fi 设备。尽管有上述约束(即此类对已扫描 Wi-Fi 设备的访问还需要位置权限),COP-MODE 数据集显示有超过 300 个应用(占全部应用的 10%)满足这些条件;一项近期工作 [43] 也印证了这些权限是跨多个 Android 版本的应用中最常被请求的权限之一。此外,Wi-Fi 相关权限被归类为安装时权限,因此在应用安装时即自动授予且不可撤销,这仍使应用能在无显式请求的情况下访问某些 Wi-Fi 信息(例如 RSSI)和/或更改 Wi-Fi 状态。

根据所做的分析,ACCESS_WIFI_STATE 与 CHANGE_WIFI_STATE 权限分别被 1499 个(38%)应用和 581 个(15%)应用请求并自动授予。此外,位置相关权限被 24% 的应用请求,其中超过 50% 的权限请求获得授予。这与近期分析 [16] 一致:该分析称 99% 的智能手机应用仍会请求完整网络访问、72% 的应用可查看 Wi-Fi 连接、三分之一的应请求位置权限。此类权限被可按 Google Play 商店分类的多种应用请求。图 2 展示了各类别中请求上述每种权限的不同应用的百分比。取决于应用类别以及用户对应用目标的预期,权限决定可能受到影响 [29]。例如,TRAVEL_AND_LOCAL 类别的应用被预期请求位置权限,因此用户往往授予它。另一方面,由于 Wi-Fi 相关权限会独立于应用类别和用户偏好而被自动授予,隐私风险随之产生,导致对用户的指纹识别与识别。

(图 2:各类别中请求该权限(纵轴)的不同应用的百分比。ACCESS_COARSE_LOCATION、ACCESS_FINE_LOCATION、ACCESS_WIFI_STATE、CHANGE_WIFI_STATE 分别对应横轴百分比 0–100;类别包括 BUSINESS、COMMUNICATION、ENTERTAINMENT、FINANCE、FOOD_AND_DRINK、GAME、HEALTH_AND_FITNESS、LIFESTYLE、MAPS_AND_NAVIGATION、MUSIC_AND_AUDIO、PERSONALIZATION、PHOTOGRAPHY、PRODUCTIVITY、SHOPPING、SOCIAL、TOOLS、TRAVEL_AND_LOCAL。为简化可视化,应用百分比低于 1% 的类别已从图中移除。)

4 从 Wi-Fi 数据进行的指纹识别与重识别风险

基于能够采集位置和/或 Wi-Fi 数据的大量应用,本节通过研究由此产生的指纹识别与重识别风险,分析采集 Wi-Fi 数据的隐私影响。在本分析全文中,我们用 Wi-Fi SSID 与 Wi-Fi BSSID 分别指代 Wi-Fi 网络名与 Wi-Fi 接入点(AP)的 MAC 地址。

4.1 从 Wi-Fi 数据对用户进行指纹识别

指纹是由唯一标识个体的特征组合而成。这虽可能带来益处(例如个性化服务),但应用能够唯一识别其用户这一事实可能对用户隐私构成威胁。为缓解此问题,如前所述,智能手机 OS 已收紧对唯一标识符的访问。本节讨论从 Wi-Fi 数据构建指纹。一个初始指纹可由每位参与者在 COP-MODE 实地研究期间扫描到的所有 Wi-Fi BSSID 组成。在这种情况下,所有用户都会有唯一指纹,因为在整个实地研究期间,用户拥有一组唯一的被扫描 BSSID。然而,一般地,可能无法访问 Wi-Fi BSSID 的全部历史数据,因为自 Android 10(约 2019 年)起,关于已配置 Wi-Fi 网络的完整信息仅限设备所有者(DO)、配置文件所有者(PO)与系统应用访问 [5]。因此,我们将考虑以下更贴近现实的指纹识别设定:

(1)攻击者只能访问所有被扫描 Wi-Fi BSSID 的单次快照,而非持续访问被扫描的 Wi-Fi 网络。这对应一个更弱的攻击者模型,其掌握的(被扫描 Wi-Fi 网络的)信息要少得多(仅单次快照)。这可对应应用被安装后立即卸载的情形;

(2)攻击者能访问信号强度(RSSI)最高的被扫描 Wi-Fi 网络的 SSID(网络名),即代表用户通常会连接的那个 Wi-Fi 网络。

在第一种场景中,假设攻击者模型掌握较少信息(例如部分数据而非全部数据),我们考虑一个随机时间快照及相应的被扫描 Wi-Fi BSSID 集合。为具统计显著性,每次选取执行 100 次,因此结果将以 95% 置信区间呈现。结果显示:每位用户单次快照的被扫描 Wi-Fi BSSID 为约 99% 的参与者创建了唯一指纹,这意味着仅采集一次被扫描 Wi-Fi AP 集合,就足以唯一识别超过 99% 的用户。当考虑三个时间快照时,这一比例升至 100%,如图 3 所示。

(图 3:在选取随机快照(横轴)与被扫描 Wi-Fi BSSID 集合时,被识别用户的百分比及其 95% 置信区间。纵轴 Re-identification (%) 范围约 99.05–100.00,横轴 Number of snapshots 为 0–3。)

在第二种场景中,我们假设攻击者能访问信号强度(RSSI)最高网络的 SSID,这代表攻击者可获取用户通常会连接的网络 [35]。该信息可在运行时从当前 Wi-Fi 连接获得。图 4a 呈现了该场景的结果,其中考察了可获取的不同数量的已连接 Wi-Fi SSID(网络名)下的唯一指纹识别风险。该比率从单个网络名时的 83%、2 个网络名时的 97%,升至 5 个网络名时的 100%。若攻击者获取的不是网络名而是 BSSID/MAC 地址,则其唯一性使指纹识别风险在单个实例时就升至 94%,如图 4b 所示。这可由多个 Wi-Fi AP 共享同一 SSID 来解释(例如 eduroam(education roaming),即一种在高校校园范围内提供互联网连接的全球漫游接入服务)。这些结果表明源自 Wi-Fi 连接的信息作为用户指纹手段的重要性,并凸显:5 个已连接 Wi-Fi 网络名就足以重识别数据集中的全部用户。本节讨论的结果强调了暴露附近或已连接 Wi-Fi AP 设备及其唯一性所带来的隐私风险。

(图 4:在选取随机时间快照(横轴)与信号强度(RSSI)最高的 Wi-Fi SSID/BSSID 时,被识别用户的百分比及 95% 置信区间。(a) Wi-Fi SSID:横轴 Number of networks/points 为 0–5,纵轴约 80–100;(b) Wi-Fi BSSID:横轴 0–5,纵轴约 90–100.0。)

4.2 通过 Top-N 的重识别风险

在指纹识别分析的基础上,本节评估通过 Wi-Fi 数据的重识别风险。重识别风险是一项相关的隐私度量,评估暴露某个个体隐私信息的可能性。数据隐私中最受关注的问题之一是身份披露,通常通过移除显式标识符来缓解。然而,还有其他被称为准标识符(Quasi-Identifiers, QIDs)的属性,它们能生成唯一组合,从而实现用户重识别。为评估重识别风险,我们将著名的「top-N」位置攻击 [51] 改造为「top-N」特征/属性攻击。该攻击包括选取某用户的前 N 个特征/属性(即出现频率最高的 N 个)并评估其唯一性。若所选 top 唯一,则该用户被视为被识别。

图 5 首先呈现对每位用户 top-N Wi-Fi AP BSSID(N 从 1 到 3)的语义分析。结合选定的语义位置(Home、Work、Traveling 或 Other),我们能够对 top-N Wi-Fi BSSID 在 5 分钟区间内最频繁出现的位置进行分类。图中所示的基线(baseline)是被扫描 BSSID 按语义位置的分布,其中 84% 在家、9% 在工作、4% 在其他位置、3% 在出行途中。正如预期,top-1(即最频繁的 BSSID)在超过 90% 的情况下对应家庭位置。类似地,top-2 与 top-3 在超过 85% 的情况下包含家庭位置,这可解释为用户在家可能扫描到不止一个 Wi-Fi AP,它们会出现在最频繁被扫描的 BSSID 中。与基线相比,主要差异在于其余位置的分布:与基线相比,「其他位置」在最频繁位置中出现的百分比更高。所做的分析强调了保护用户轨迹端点(特别是家庭与工作位置)的必要性,因为它们具有被重识别的潜在风险 [22]。

(图 5:被扫描 Wi-Fi BSSID(基线)与每位用户 top-N Wi-Fi BSSID(N 从 1 到 3,在采集数据与权限请求提示之间 5 分钟区间内)的语义分析。图例:Home、Work、Traveling、Other;横轴为 Baseline、1、2、3(N),纵轴 Percentage (%) 0–100。)

图 6 呈现了在考虑 top-N 攻击(N 从 1 到 7)时,对以下特征被重识别用户的百分比:GPS 位置、Wi-Fi 位置、Wi-Fi SSID 与 Wi-Fi BSSID。与先前工作 [8, 12] 的结论一致,四个点就足以唯一识别超过 95% 的用户。从图 6 可见,重识别率最低值出现在 Wi-Fi SSID 的 top-1,这可由存在大量名称常见的公共 Wi-Fi 热点来解释(例如互联网服务提供商(ISP)提供的热点)。另一方面,通过最常被扫描的 Wi-Fi BSSID 可重识别超过 90% 的用户,通过 top-2 则超过 97%。这尤其令人担忧,因为如语义分析所支持的那样,最频繁位置(即 top 位置)与一个私人位置——家——相关。

尽管此处重识别风险评估依赖于每位用户最频繁的 Wi-Fi AP,第 4.1 节呈现的指纹识别分析考虑了两种攻击者场景,即攻击者可访问(1)每位用户的一组被扫描 BSSID 与(2)信号强度最高的 SSID。这些方法解释了重识别百分比上的差异。例如,图 6 的 top-1 BSSID 考虑的是每位用户最频繁的 BSSID,而图 3 的随机时间快照包含该时间段内所有被扫描的 Wi-Fi BSSID,因而解释了更高的重识别风险。下一节通过 k-匿名(k-anonymity)展示重识别风险——k-匿名是一种可用于尝试最小化指纹识别与重识别风险的隐私原则。

(图 6:在考虑 top-N 攻击(N 从 1 到 7)时,对以下特征被识别用户的百分比:GPS location、Wi-Fi BSSID、Wi-Fi SSID 与 Wi-Fi location。)

4.3 通过 k-匿名的重识别风险

保护用户隐私、缓解重识别风险的常见做法是降低数据唯一性。例如,k-匿名原则保证:在 k 个个体组成的集合中,任一人的身份不能从同一集合中至少 k-1 个个体中被区分出来 [40, 41]。所达到的隐私水平可用 k 值衡量,k 值越高对应隐私水平越高(即越难去匿名化)。基于此概念,对于一组准标识符(QIDs)的给定数量 k 的组合,若具有相同 QID 组合的记录频率为 1,则用户可被单独识别出来。本节依据该概念作为评估重识别风险的度量 [17]。

对于 k=1,即每个集合由 COP-MODE 数据集中 18613 个唯一被扫描 Wi-Fi BSSID 之一组成,我们计算具有相同 QID 的记录频率(即扫描到同一 BSSID 的用户数)。若该频率为 1,则该用户被视为被单独识别,因而被重识别。图 7 呈现了记录频率及其相应计数。由这些结果,16064 个 Wi-Fi BSSID 的频率为 1,意味着 86% 的 Wi-Fi BSSID 只被一个用户扫描到。在这种情况下,82 名用户中有 81 名单次扫描到过这些 Wi-Fi AP 中的至少一个,这意味着只要知道该集合中的一个被扫描 BSSID,就可能重识别出某个个体。

本节所做的评估以强调 Wi-Fi 数据的唯一性(86% 的 Wi-Fi BSSID 为单次扫描)以及由此产生的将此类数据用作唯一标识符的可能性,为本文分析作结。这对用户隐私有严重影响,下文将予以讨论。

(图 7:Wi-Fi BSSID 的记录频率。横轴为频率值 1–17(含 f9k),纵轴为计数 0–15000。)

5 Wi-Fi 指纹识别的隐私影响

以增强与用户偏好和行为相契合的个性化服务为名,应用被允许采集多样化数据。然而,这是以损害用户隐私、缺乏匿名为代价换来的。本文已表明,相当数量的应用拥有采集位置和/或 Wi-Fi 数据所需的权限,从而导致高指纹识别与重识别风险。这凸显了即使智能手机对显式唯一 ID 的访问已有现有限制,应用仍难以做到不被唯一识别。唯一识别用户的能力可被用来发起进一步攻击以侵害用户隐私,产生本节将讨论的严重隐私影响。

尽管对用户和服务提供者而言都有无数机会与益处,指纹识别与画像(profiling)是当今数字社会中严重隐私问题的典型,并因数据的高唯一性而加剧。画像是指基于用户数据创建详细而准确的用户模型,从而可以识别与追踪他们。当存在数据关联或其他可链接数据时,由此产生的隐私风险进一步加剧。基于本文所做的、强调 Wi-Fi 数据唯一性的分析,攻击者将能够基于 Wi-Fi 数据创建用户画像,并可用其他上下文信息(例如一天中的时段或位置)来丰富这些画像,以对用户进行指纹识别甚至追踪。例如,追踪用户可使实体得知用户是否在家,这带来的隐私风险超出人身安全范畴。这是一个真实且日益令人担忧的问题,近期新闻 [23, 24] 即为证明。[23] 中呈现的隐私泄露报道了一个真实世界的电池监测应用,它能够采集并分享 GPS 坐标、附近手机基站、Wi-Fi 接入点以及用户的街道地址。这尤其关键,因为位置数据(即便经过匿名化)也可被用于对用户画像并推断敏感信息(例如宗教,如新闻文章 [19] 所披露)。这些真实案例强化了本文的洞见:它们可能成为潜在隐私问题的助推者。

由于指纹识别可能以微妙而普遍的方式实施,在有效的指纹识别与用户隐私之间寻求折中,仍是当前隐私威胁格局中的一大挑战。尽管用户往往不知道关于自己的大量数据被采集、以及这些信息如何被用于识别其画像,移动设备的普及却为采集个人数据带来了丰富机会。如本文所讨论,尽管人们努力限制对唯一 ID 的访问,通过 Wi-Fi 数据对用户进行指纹识别仍然可行。这是移动设备普遍存在的问题,并非仅存在于智能手机。

5.1 隐私保护策略

为缓解上述隐私影响,必须实施能进一步保护用户隐私的数据保护机制与策略,概述如下。

  • 限制数据采集:限制采集可能永远不会被使用的非必要数据,尤其要阻止个人数据的采集与留存,以降低用户暴露于隐私风险的程度。
  • 风险分析与重识别风险评估:风险分析与重识别风险评估应以更系统的方式进行,并成为批准访问任何数据类型流程的一部分。
  • 使用匿名化方法:在识别出隐私风险后,应考虑使用匿名化技术,以提供适当的隐私-效用权衡。特别是,除用户位置外(近来的移动 OS 已提供位置模糊化),当前权限系统通常以「全有或全无」方式运作,即要么用户能访问数据(完全效用、无隐私),要么完全无法访问。应探索通过匿名化方法实现中间地带,且应通过自动化隐私保护机制实现,因为普通用户没有足够时间/知识来设置和配置此类技术。
  • 促进数据透明:公司与组织应清楚了解其正在与谁交互,确保用户的数字身份安全、隐私受尊重。此外,应提供让用户行使其隐私权的方法,例如控制敏感个人数据的使用与披露。
  • 增强用户意识与教育:用户应了解其在线活动与身份的隐私影响,同时也应接受隐私教育,以便就数据分享与保护做出知情决定。

这些隐私保护策略旨在保护用户免遭对其数据的潜在未授权访问。作为使用最广泛的设备之一,智能手机一直处于引入保护用户隐私限制的前沿,然而,仍有许多工作要做,尤其是在其他移动设备方面。

6 结论

移动设备的激增催生了大量服务与应用,也为采集海量数据带来了丰富机会。特别是,对个性化服务的高需求带来了对唯一识别用户的特殊兴趣。由于数据唯一性带来的隐私风险,智能手机已收紧对唯一标识符(ID)的访问。本文借助一个采集了用户至少一周数据的数据集,证明了通过位置与 Wi-Fi 数据对用户进行指纹识别的可能性,表明尽管人们努力避免唯一 ID,仍可依赖可获取的数据对用户进行指纹识别。根据所做的分析,我们得出结论:每位用户单次扫描的 Wi-Fi BSSID(MAC 地址)集合快照,就足以唯一识别约 99% 的用户。出现频率最高的 Wi-Fi BSSID 足以重识别超过 90% 的用户,前 2 个被扫描的 BSSID 则升至 97%。此外,若能访问用户会连接的最强 Wi-Fi AP,使用信号最强的 1 个和 2 个 SSID(网络名)分别带来约 83% 和 97% 的重识别风险。因此,基于我们的结果、依据 COP-MODE 数据集,超过 300 个应用能够将位置和/或 Wi-Fi 数据用作唯一标识符,即便其他类型的标识符已被禁止访问。尽管指纹识别有助于提供与用户偏好和行为契合的个性化服务,其后果与由此产生的隐私风险不容忽视。用户往往不知道通过其移动设备、特别是通过已安装的智能手机应用所采集的数据。事实上,由于信息采集方式微妙而普遍,用户难以控制或退出此类采集,也缺乏缓解被追踪的技术。例如,追踪用户可使实体得知用户是否在家,这带来的隐私风险超出人身安全范畴。因此,在有效的指纹识别与用户隐私保护之间寻求折中,在当前永远在线的移动设备格局中仍是一大关键挑战。

致谢

本工作由葡萄牙资助机构 FCT - Fundação para a Ciência e a Tecnologia 通过国家基金在项目 LA/P/0063/2020(DOI 10.54499/LA/P/0063/2020)内资助。作者感谢项目 CISUC - UID/CEC/00326/2020 的支持,以及欧洲社会基金通过 FCT 的 Regional Operational Program Centro 2020 的支持,并感谢由智能网络与服务联合执行体(SNS JU)在欧盟「地平线欧洲」研究与创新计划下、依据第 101096110 号资助协议资助的 PRIVATEER 项目。文中观点与意见仅代表作者,不一定反映欧盟或 SNS JU 的观点。Mariana Cunha 感谢葡萄牙资助机构 Fundação para a Ciência e a Tecnologia (FCT) 依据资助号 2020.04714.BD(DOI 10.54499/2020.04714.BD)提供的财务支持。

参考文献

(以下参考文献条目为原文照录,保留原语言与格式,未作翻译。)

[1] Jagdish Prasad Achara, Gergely Acs, and Claude Castelluccia. 2015. On the Unicity of Smartphone Applications. In Proceedings of the 14th ACM Workshop on Privacy in the Electronic Society (WPES '15). ACM, 27-36.

[2] Jagdish Prasad Achara, Mathieu Cunche, Vincent Roca, and Aurélien Francillon. 2014. Short paper: Wifileaks: Underestimated privacy implications of the ACCESS_WIFI_STATE Android permission. In Proceedings of the 2014 ACM Conference on Security and Privacy in Wireless & Mobile Networks. ACM, 231-236.

[3] Md Sabbir Ahmed and Nova Ahmed. 2021. Exploring unique app signature of the depressed and non-depressed through their fingerprints on apps. In International Conference on Pervasive Computing Technologies for Healthcare. Springer, 218-239.

[4] Efthimios Alepis and Constantinos Patsakis. 2017. There's Wally! Location Tracking in Android without Permissions. In Proceedings of the 3rd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP. INSTICC, SciTePress, 278-284.

[5] Android. 2024. Android 10. https://developer.android.com/guide/topics/connectivity/wifi-scan. Accessed: 2024-07-05.

[6] John S. Atkinson, John E. Mitchell, Miguel Rio, and George Matich. 2018. Your WiFi is leaking: What do your mobile apps gossip about you? Future Generation Computer Systems 80 (2018), 546-557. https://doi.org/10.1016/j.future.2016.05.030

[7] Benjamin Baron and Mirco Musolesi. 2020. Where you go matters: a study on the privacy implications of continuous location tracking. Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies 4, 4 (2020), 1-32.

[8] Antoine Boutet and Sonia Ben Mokhtar. 2021. Uniqueness assessment of human mobility on multi-sensor datasets. In Proceedings of the 16th International Conference on Availability, Reliability and Security. ACM, 1-10.

[9] Federal Trade Commission. 2016. Mobile Advertising Network InMobi Settles FTC Charges It Tracked Hundreds of Millions of Consumers' Locations Without Permission. https://www.ftc.gov/news-events/news/press-releases/2016/06/mobile-advertising-network-inmobi-settles-ftc-charges-it-tracked-hundreds-millions-consumers. Accessed: 2024-07-17.

[10] Mathieu Cunche, Mohamed Ali Kaafar, and Roksana Boreli. 2012. I know who you will meet this evening! linking wireless devices using wi-fi probe requests. In 2012 IEEE International Symposium on a World of Wireless, Mobile and Multimedia Networks (WoWMoM). IEEE, 1-9.

[11] Mariana Cunha, Ricardo Mendes, and João P Vilela. 2021. A survey of privacy-preserving mechanisms for heterogeneous data types. Computer science review 41 (2021), 100403.

[12] Yves-Alexandre De Montjoye, César A Hidalgo, Michel Verleysen, and Vincent D Blondel. 2013. Unique in the crowd: The privacy bounds of human mobility. Scientific reports 3, 1 (2013), 1-5.

[13] Android Developers. 2023. Get the last known location. https://developer.android.com/training/location/retrieve-current. Accessed: 2024-07-05.

[14] Android Developers. 2024. Best practices for unique identifiers. https://developer.android.com/identity/user-data-ids. Accessed: 2024-07-05.

[15] Android Developers. 2024. Package visibility filtering on Android. https://developer.android.com/training/package-visibility. Accessed: 2024-07-05.

[16] Edvardas Mikalauskas. 2022. Android apps are asking for too many dangerous permissions. Here's how we know. https://cybernews.com/privacy/android-apps-are-asking-for-too-many-dangerous-permissions-heres-how-we-know/. Accessed: 2024-07-05.

[17] Khaled El Emam and Fida Kamal Dankar. 2008. Protecting privacy using k-anonymity. Journal of the American Medical Informatics Association 15, 5 (2008), 627-637.

[18] European Parliament and Council of the European Union. 2016. Regulation (EU) 2016/679 of the European Parliament and of the Council. http://data.europa.eu/eli/reg/2016/679/oj

[19] Lorenzo Franceschi-Bicchierai. 2015. Redditor cracks anonymous data trove to pinpoint Muslim cab drivers. https://mashable.com/archive/redditor-muslim-cab-drivers. Accessed: 2024-11-11.

[20] Julien Freudiger. 2015. How talkative is your mobile device? an experimental study of Wi-Fi probe requests. In Proceedings of the 8th ACM Conference on Security & Privacy in Wireless and Mobile Networks (WiSec '15). ACM, Article 8, 6 pages.

[21] Julien Gamba, Álvaro Feal, Eduardo Blazquez, Vinuri Bandara, Abbas Razaghpanah, Juan Tapiador, and Narseo Vallina-Rodriguez. 2023. Mules and Permission Laundering in Android: Dissecting Custom Permissions in the Wild. IEEE Transactions on Dependable and Secure Computing (2023), 1-18.

[22] Philippe Golle and Kurt Partridge. 2009. On the anonymity of home/work location pairs. In International Conference on Pervasive Computing. Springer, 390-397.

[23] haxrob. 2023. Discovering that your car battery monitor is siphoning up your location data. https://haxrob.net/discovering-that-your-bluetooth-car-battery-monitor-is-siphoning-up-your-location-data/. Accessed: 2024-11-11.

[24] Misha Rykov Jen Caltrider and Zoë MacDonald. 2023. Discovering that your car battery monitor is siphoning up your location data. https://foundation.mozilla.org/en/privacynotincluded/articles/its-official-cars-are-the-worst-product-category-we-have-ever-reviewed-for-privacy/. Accessed: 2024-11-11.

[25] Kathryn Zickuhr. 2013. Main Report. https://www.pewresearch.org/internet/2013/09/12/location-based-services-2/. Accessed: 2024-07-05.

[26] Tong Li, Tong Xia, Huandong Wang, Zhen Tu, Sasu Tarkoma, Zhu Han, and Pan Hui. 2022. Smartphone app usage analysis: datasets, methods, and applications. IEEE Communications Surveys & Tutorials 24, 2 (2022), 937-966.

[27] Bin Liu, Mads Schaarup Andersen, Florian Schaub, Hazim Almuhimedi, Shikun Aerin Zhang, Norman Sadeh, Yuvraj Agarwal, and Alessandro Acquisti. 2016. Follow my recommendations: A personalized privacy assistant for mobile app permissions. In 12th Symposium on Usable Privacy and Security (SOUPS). 27-41.

[28] Allan Lyons, Julien Gamba, Austin Shawaga, Joel Reardon, Juan Tapiador, Serge Egelman, Narseo Vallina-Rodriguez, et al. 2023. Log: It's Big, It's Heavy, It's Filled with Personal Data! Measuring the Logging of Sensitive Information in the Android Ecosystem. In Usenix Security Symposium.

[29] Ricardo Mendes, André Brandão, João P Vilela, and Alastair R Beresford. 2022. Effect of user expectation on mobile app privacy: a field study. In 2022 IEEE international conference on pervasive computing and communications (PerCom). IEEE, 207-214.

[30] Ricardo Mendes, Mariana Cunha, João P Vilela, and Alastair R Beresford. 2022. Enhancing User Privacy in Mobile Devices Through Prediction of Privacy Preferences. In Computer Security-ESORICS 2022: 27th European Symposium on Research in Computer Security, Copenhagen, Denmark, September 26-30, 2022, Proceedings, Part I. Springer, 153-172.

[31] Mark Huasong Meng, Qing Zhang, Guangshuai Xia, Yuwei Zheng, Yanjun Zhang, Guangdong Bai, Zhi Liu, Sin G Teo, and Jin Song Dong. 2023. Post-GDPR Threat Hunting on Android Phones: Dissecting OS-level Safeguards of User-unresettable Identifiers. In 30th annual Network and Distributed System Security Symposium.

[32] ABM Musa and Jakob Eriksson. 2012. Tracking unmodified smartphones using wi-fi monitors. In Proceedings of the 10th ACM conference on embedded network sensor systems. Association for Computing Machinery, 281-294.

[33] Suman Nath. 2015. MAdScope: Characterizing Mobile In-App Targeted Ads. In Proceedings of the 13th Annual International Conference on Mobile Systems, Applications, and Services (Florence, Italy) (MobiSys '15). Association for Computing Machinery, New York, NY, USA, 59-73. https://doi.org/10.1145/2742647.2742653

[34] Le Nguyen, Yuan Tian, Sungho Cho, Wookjong Kwak, Sanjay Parab, Yuseung Kim, Patrick Tague, and Joy Zhang. 2013. Unlocin: Unauthorized location inference on smartphones without being caught. In 2013 International Conference on Privacy and Security in Mobile Systems (PRISMS). IEEE, 1-8.

[35] Changhua Pei, Zhi Wang, Youjian Zhao, Zihan Wang, Yuan Meng, Dan Pei, Yuanquan Peng, Wenliang Tang, and Xiaodong Qu. 2017. Why it takes so long to connect to a WiFi access point. In IEEE INFOCOM 2017-IEEE Conference on Computer Communications. IEEE, 1-9.

[36] The Associated Press. 2021. Priest outed via Grindr app highlights rampant data tracking. https://www.nbcnews.com/tech/security/priest-outed-grindr-app-highlights-rampant-data-tracking-rcna1493. Accessed: 2024-07-05.

[37] Abbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Mark Allman, Christian Kreibich, Phillipa Gill, et al. 2018. Apps, trackers, privacy, and regulators: A global study of the mobile tracking ecosystem. In The 25th annual Network and Distributed System Security Symposium (NDSS).

[38] Joel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On, Narseo Vallina-Rodriguez, and Serge Egelman. 2019. 50 ways to leak your data: An exploration of apps' circumvention of the android permissions system. In 28th USENIX security symposium (USENIX security 19). USENIX Association, Santa Clara, CA, 603-620.

[39] Fergus Ryan and Michael Schukat. 2019. Wi-fi user profiling via access point honeynets. In 2019 30th Irish Signals and Systems Conference (ISSC). IEEE, 1-4.

[40] Pierangela Samarati and Latanya Sweeney. 1998. Generalizing data to provide anonymity when disclosing information. In PODS, Vol. 98. Citeseer, 188.

[41] Pierangela Samarati and Latanya Sweeney. 1998. Protecting privacy when disclosing information: k-anonymity and its enforcement through generalization and suppression. Technical Report. technical report, SRI International.

[42] Vedran Sekara, Laura Alessandretti, Enys Mones, and Håkan Jonsson. 2021. Temporal and cultural limits of privacy in smartphone app usage. Scientific reports 11, 1 (2021), 1-9.

[43] Yash Sharma and Anshul Arora. 2024. A comprehensive review on permissions-based Android malware detection. International Journal of Information Security (2024), 1-36.

[44] Vincent Toubiana and Mathieu Cunche. 2021. No need to ask the Android: Bluetooth-Low-Energy scanning without the location permission. In Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks (Abu Dhabi, United Arab Emirates) (WiSec '21). ACM, 147-152.

[45] Martin W Traunmueller, Nicholas Johnson, Awais Malik, and Constantine E Kontokosta. 2018. Digital footprints: Using WiFi probe and locational data to analyze human mobility trajectories in cities. Computers, Environment and Urban Systems 72 (2018), 4-12.

[46] Zhen Tu, Runtong Li, Yong Li, Gang Wang, Di Wu, Pan Hui, Li Su, and Depeng Jin. 2018. Your Apps Give You Away: Distinguishing Mobile Users by Their App Usage Fingerprints. Proc. ACM Interact. Mob. Wearable Ubiquitous Technol. 2, 3 (2018), 23 pages.

[47] Imdad Ullah, Roksana Boreli, and Salil S Kanhere. 2023. Privacy in targeted advertising on mobile devices: a survey. International Journal of Information Security 22, 3 (2023), 647-678.

[48] Mathy Vanhoef, Célestin Matte, Mathieu Cunche, Leonardo S. Cardoso, and Frank Piessens. 2016. Why MAC Address Randomization is not Enough: An Analysis of Wi-Fi Network Discovery Mechanisms. In Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security. ACM, 413-424.

[49] Gabriella Verga, Salvatore Calcagno, Andrea Fornaia, and Emiliano Tramontana. 2019. Smart Cities and Open WiFis: When Android OS Permissions Cease to Protect Privacy. In Internet and Distributed Computing Systems. Springer International Publishing, Cham, 457-467.

[50] Qiang Xu, Rong Zheng, Walid Saad, and Zhu Han. 2015. Device fingerprinting in wireless networks: Challenges and opportunities. IEEE Communications Surveys & Tutorials 18, 1 (2015), 94-104.

[51] Hui Zang and Jean Bolot. 2011. Anonymization of location data does not work: A large-scale measurement study. In Proceedings of the 17th annual international conference on Mobile computing and networking. ACM, 145-156.

[52] Wanyi Zhang, Qiang Shen, Stefano Teso, Bruno Lepri, Andrea Passerini, Ivano Bison, and Fausto Giunchiglia. 2021. Putting human behavior predictability in context. EPJ Data Science 10, 1 (2021), 42.

On the Difficulty of NOT being Unique: Fingerprinting Users from Wi-Fi Data in Mobile Devices

Mariana Cunha

CRACS/INESC TEC, CISUC, and Department of Computer Science, Faculty of Sciences, University of Porto Porto, Portugal mccunha@dei.uc.pt

Ricardo Mendes

CISUC and Department of Informatics Engineering, University of Coimbra Coimbra, Portugal rscmendes@dei.uc.pt

Yves-Alexandre de Montjoye

Imperial College London, Exhibition Road, South Kensington

London, United Kingdom demontjoye@imperial.ac.uk

Abstract

The pervasiveness of mobile devices has fostered a multitude of services and applications, but also raised serious privacy concerns. In order to avoid users' tracking and/or users' fingerprinting, smartphones have been tightening the access to unique identifiers. Nevertheless, smartphone applications can still collect diverse data from available sensors and smartphone resources. Using real-world data from a field study we performed, this paper demonstrates the possibility of fingerprinting users from Wi-Fi data in mobile devices and the consequent privacy impact. From the performed analysis, we concluded that a single snapshot of a set of scanned Wi-Fi BSSIDs (MAC addresses) per user is enough to uniquely identify about 99% of the users. In addition, the most frequent Wi-Fi BSSID is sufficient to re-identify more than 90% of the users, a percentage that goes up to 97% of the users with the top-2 scanned BSSIDs. The Wi-Fi SSID (network name) also leads to a re-identification risk of about 83% and 97% with 1 and 2 of the strongest Wi-Fi Access Points (APs), respectively.

CCS Concepts

· Security and privacy Human and societal aspects of security and privacy; · Human-centered computing Ubiquitous and mobile computing;

Keywords

Privacy, Mobile Devices, Fingerprinting, Re-identification Risk, WiFi

ACM Reference Format: Mariana Cunha, Ricardo Mendes, Yves-Alexandre de Montjoye, and João P. Vilela. 2025. On the Difficulty of NOT being Unique: Fingerprinting Users from Wi-Fi Data in Mobile Devices. In The 40th ACM/SIGAPP Symposium on Applied Computing (SAC '25), March 31-April 4, 2025, Catania, Italy. ACM, New York, NY, USA, 8 pages. https://doi.org/10.1145/3672608.3707966

This work is licensed under a Creative Commons 4.0 International License. SAC '25, March 31-April 4, 2025, Catania, Italy © 2025 Copyright held by the owner/author(s). ACM ISBN 979-8-4007-0629-5/25/03 https://doi.org/10.1145/3672608.3707966

João P. Vilela

CRACS/INESC TEC, CISUC, and Department of Computer Science, Faculty of Sciences, University of Porto Porto, Portugal jvilela@fc.up.pt

1 Introduction

The prevalence of smartphones in the current digital society has brought a rich opportunity to collect large amounts of heterogeneous data in a multitude of contexts. While beneficial to both users and services, such data might contain sensitive information and raise serious privacy concerns [11]. Within the smartphone's context, several works have demonstrated possible manners of leaking data through applications [6, 38], logs [28], and misuse of permissions [2, 4, 21, 44] (e.g. location tracking without permissions). In addition, recent news [9, 23] report examples of privacy-breaches, where applications were being used to collect side information, such as Wi-Fi data, without user consent.

In an attempt to enhance user's control and rights over their personal data, regulations on information privacy have been created, namely the General Data Protection Regulation (GDPR) in European Union [18]. In practice, smartphones give users some control through permission managers, where users can allow/deny permissions and consequent access to smartphone data/resources. Nonetheless, one of the main challenges when regulating and protecting user's privacy is the access to unique identifiers (IDs). In this regard, Android defines best practices for developers related to the selection and use of unique IDs [14], such as choosing userresettable IDs, avoiding hardware IDs, or respecting the purpose of the advertising ID. The latest versions of Android [5] restrict the access to hardware identifiers (e.g. IMEI and serial number) to applications that are device or profile owner applications, have special carrier permissions, or have the READ_PRIVILEGED_PHONE_STATE privileged permission [14].

Despite the developments to empower users to regain control over their data [27, 30], the current permission model of smartphones still has limitations and fails to account for data correlation and contextual dependency. For instance, while the permission to access location data is considered as runtime/dangerous and, hence, requires a permission prompt, obtaining location through side information, such as Wi-Fi [2, 4, 49] or Bluetooth, is still possible without explicit permission [44]. This raises serious privacy concerns that go beyond physical safety, since human mobility traces are highly unique and might reveal the user's identity, habits, social relationships or even health conditions [7, 12, 36]. Taking this into

SAC '25, March 31-April 4, 2025, Catania, Italy

consideration, this paper demonstrates the possibility of using data available to smartphone applications (e.g. Wi-Fi Access Points (APs) BSSIDs and SSIDs) as a fingerprint of users, even when other types of identifiers are blocked from access.

This paper shows the fingerprinting and re-identification risk of accessing Wi-Fi data through an installed smartphone application, that is, from the user's perspective. In spite of the efforts to avoid the use of other and more explicit unique identifiers and the well-known risks that advent from accessing such data, we conclude on the possibility of using Wi-Fi data as unique identifiers to fingerprint users. Until Android 9 (circa 2018), access to Wi-Fi data was possible with install-time permissions, which means without the user perception and without the possibility of revoking such access. This problem is transversal to other devices that still allow access to either location or Wi-Fi data (e.g. laptops). Despite the enhancements in more recent Android permissions, the fact that full network access is still asked in 99% of the smartphone applications, view Wi-Fi connections in 72% of the apps, and that one third of the apps request location permissions [16], emphasizes the importance of exploring the user's fingerprinting through location and Wi-Fi data.

Towards this goal, we relied on real-world data collected from a field study conducted with participants that carried our smartphones for at least one week [29, 30]. Relying on the contextual data (e.g. location and scanned Wi-Fi devices) collected through a smartphone application, we perform the fingerprinting and reidentification analysis. In this paper, we demonstrate that fingerprinting users with Wi-Fi data is possible and leads to a re-identification of about 99% of the users for a single snapshot of scanned Wi-Fi BSSIDs (i.e. an adversary with a single set of scanned Wi-Fi BSSIDs). When considering an adversary with information about the Wi-Fi AP with the strongest signal, nearly 83% and 97% of the users were re-identified with 1 and 2 highest signal strength SSIDs/network names, and 94% and 99% for the 1 and 2 highest signal strength BSSIDs. In line with these results, the re-identification risk assessment showed that 81 out of 82 users single scanned at least one Wi-Fi BSSID (MAC address), with the most frequent AP being enough to re-identify more than 90% of the users and the top-2 scanned BSSIDs sufficient to re-identify over 97% of the users. Similarly, over 95% of the users can be re-identified with the top-4 of Wi-Fi SSIDs, Wi-Fi locations or GPS locations (which is in line with previous work [12]). This highlights the privacy risks of accessing Wi-Fi information and is a call for action in raising user's privacy awareness and in the development of privacy-preserving mechanisms that take into account the data correlations among heterogeneous sources.

The remainder of this paper is structured as follows. Section 2 provides an overview of background concepts and related work, whereas Section 3 details the dataset. Section 4 presents the performed analysis on fingerprinting and evaluates the privacy risk through the re-identification metric. Section 5 discusses the privacy implications of Wi-Fi fingerprinting and corresponding privacypreserving strategies, and Section 6 draws the main conclusions. Throughout the paper, smartphone application might simply be referred to as app.

Mariana Cunha et al.

2 Background and Related Work

The growing and indispensable use of smartphones has allowed the access to a variety of personal and sensitive data. This has fostered personalized services and novel applications that take into account the user's profile and preferences. With the claimed purpose of providing a better service suited to the user, smartphone applications collect Personally Identifiable Information (PII), such as unique identifiers (IDs), from mobile devices to distinguish devices/users, but also track them [33, 47].

The Android Operating System (OS) offers a number of IDs with different characteristics in terms of scope (i.e. which systems can access the ID), resettability and persistence (i.e. the lifespan of the ID and how it can be reset), uniqueness (i.e. the likelihood of collisions), and integrity protection and non-repudiability (i.e. a difficult-tospoof ID) [14]. To ensure that the provided IDs are properly handled, Android defines best practices for developers related to the selection and use of unique IDs [14], such as choosing user-resettable IDs, avoiding hardware IDs, or respecting the purpose of the advertising ID. The latest versions of Android [5] restrict the access to hardware identifiers (e.g. IMEI and serial number) to applications that are device/profile owner apps (i.e. apps with administrative control over the device or a specific profile), have special carrier permissions (i.e. permissions limited to apps affiliated with mobile carriers), or have a special privileged permission (READ_PRIVILEGED_PHONE_STATE) only available to system apps that are part of the firmware or installed by the device manufacturer.

In spite of the introduced constraints and the official guidelines for working with Android IDs [14], previous research demonstrated that unique IDs and, specifically, persistent IDs are being accessed and often used for tracking users [31, 37, 38]. The authors of [31] identified 51 unique vulnerabilities that evidence the pervasive mishandling of user-unresettable identifiers (UUIs) in the latest Android phones. In this paper, we further demonstrate that the current countermeasures are insufficient and neglect the risk of identifying users through other and less explicit IDs. In particular, we conclude on the possibility of using Wi-Fi data as unique identifiers to fingerprint users.

Due to the privacy implications of exposing unique IDs, current research has been studying the uniqueness of human behavior from several contexts [52], including mobile apps usage data [1, 26, 42, 46] and mobility patterns [8, 12]. In terms of mobile apps usage data, four apps demonstrated being sufficient to uniquely re-identify about 90% of the users [1, 42, 46]. The analysis with this data goes further and allows re-identifying whether students are depressed or non-depressed [3]. Since Android 11 (circa 2020), accessing installed applications within a smartphone app is filtered by default and requires a QUERY_ALL_PACKAGES permission to query all installed apps on a device [15].

In regard to mobility patterns, the uniqueness of location data has become a concerning challenge. Human mobility traces are highly unique, which makes it possible to infer the user's identity, habits, social relationships or even health conditions [7]. In fact, four spatio-temporal points revealed being enough to re-identify about 95% of the individuals [8, 12]. This has led smartphone OSs to protect the collection of location data by requiring a permission to access a fine or coarse location. Nevertheless, these permissions

On the Difficulty of NOT being Unique: Fingerprinting Users from Wi-Fi Data in Mobile Devices

are often requested (by one third of the apps [16]) and apps with access to such data are able to build a fingerprint with locations to uniquely identify users [25].

Motivated by the large amounts of smartphone applications that have access to Wi-Fi information [16], we depart from previous works by demonstrating the uniqueness of such information and the possibility of creating a fingerprint through the scanned Wi-Fi access points. Despite the well-known risks of inferring location from side information, such as Wi-Fi [34], and the uniqueness of mobility traces through Wi-Fi [8], our work differs from the previous ones by focusing on the user's perspective (i.e. an app installed on the user's smartphone) and how the collection of scanned Wi-Fi APs can constitute a unique ID. Our goal is to show the privacy impact of fingerprinting users through Wi-Fi information and assess the re-identification risk that advent from scanning such data.

The existing literature has, in contrast, mainly focused on device fingerprinting from the perspective of Wi-Fi access points or other entities that are able to monitor wireless networks [50]. The fingerprints are commonly used by device identification systems that rely on relevant features to identify devices. Notwithstanding the potential benefits of using device fingerprints to enhance wireless security, several works demonstrated the possibility of not only tracking users/devices, but also using the available data (e.g. Wi-Fi probe requests sent by users' devices containing the MAC address that uniquely identifies the sending device [10, 20]) to infer information about the nearby users [32, 39, 45]. In particular, MAC address randomization emerged as a response to the resulting privacy violations [48]. In distinction to these studies, this paper examines a different perspective (user's perspective) of fingerprinting from Wi-Fi data through apps installed in users' devices, emphasizing the re-identification risk that results from the scanned Wi-Fi APs, and investigating how Wi-Fi data can constitute a unique ID in mobile devices.

3 Dataset and Overview

This section starts by describing the dataset that was used to study the privacy impact of fingerprinting users through Wi-Fi data and the resulting re-identification risk, followed by the analysis of installed applications and requested permissions.

3.1 Dataset Characterization

In order to study the user's fingerprinting within the smartphone's context, we selected the COP-MODE dataset [29, 30]. This dataset was collected in a real-world field study with 93 users, where the participants carried smartphones for at least one week with their personal applications pre-installed and an application responsible for the data collection. This app prompts users at every permission check (see Figure 1) and collects their input, as well as other contextual features at the time of the prompt. In this paper, we focus on specific contextual features that are of relevance to this work, namely:

· Datetime: timestamp of the request permission prompt. · Location: timestamp, latitude, longitude, and accuracy. · Wi-Fi: timestamp, BSSID, SSID, and RSSI for each scanned

device.

SAC '25, March 31-April 4, 2025, Catania, Italy

· Semantic location: the semantic location was collected from the user input, whose possibilities were: home, work, traveling or other.

Figure 1: An example of a permission prompt issued as a result of the app WhatsApp checking for the contacts permission.

We should note that location data is related to the last known location reading [13] and might not correspond to the current location, since the participant might have turned location off. With respect to Wi-Fi data, the scanned Wi-Fi devices correspond to the devices in the neighborhood that were obtained from a scan attempted every 5 minutes. These considerations will be taken into account during the exploratory data analysis that follows.

The COP-MODE dataset is composed by 2180302 permission requests from 93 participants. 65261 (2.99%) of the total requests were answered by participants, while the remaining were either unhandled or answered by the 30 minutes cache, timeouts or dismissed. In this work, we will consider the user answered requests, since only these have the selected semantic location. From the 65261 answered requests, 41602 requests (63.75% of the user answered requests) have Wi-Fi and/or location information from a total of 82 participants. This data constitutes the target of analysis in this paper.

3.2 Installed Applications and Requested Permissions

To better understand the applications that have access to Wi-Fi data and, in this way, understand the relevance of this problem, we start by studying the context of installed applications and requested permissions. In Android, applications are divided into system (i.e. apps with system privileges) and non-system apps (i.e. apps with limited privileges). The COP-MODE dataset contains a total of 3926 distinct apps and 1737 non-system distinct apps. Regarding the requested permissions, we now analyze which apps request the permissions required to access Wi-Fi data and the respective grant/deny result.

Scanning nearby Wi-Fi devices have been changing with the release of new Android versions, with the first mandatory locationrestrictions introduced in Android 9. Considering that the COPMODE dataset was collected in Android 9 devices, an app would require the ACCESS_COARSE_LOCATION or ACCESS_FINE_LOCATION permission along with CHANGE_WIFI_STATE permission to start a scan of Wi-Fi devices and ACCESS_WIFI_STATE

Permission

Re-identification (%)

SAC '25, March 31-April 4, 2025, Catania, Italy

permission to obtain the scanned Wi-Fi devices. In spite of the introduced constraints, where such access to scanned Wi-Fi devices also requires a location permission, the COP-MODE dataset shows that there are over 300 applications (10% of the total apps) that satisfy these conditions, which is corroborated by a recent work [43] that demonstrates that these permissions are among the most frequently requested in apps spanning multiple Android versions. Furthermore, Wi-Fi related permissions are classified as install-time permissions and, hence, are automatically granted when the app is installed and cannot be revoked, which still enables an app to access certain Wi-Fi information (e.g. RSSI) and/or change the Wi-Fi status without an explicit request.

From the performed analysis, the ACCESS_WIFI_STATE and the CHANGE_WIFI_STATE permissions were requested and automatically granted by 1499 (38%) apps and 581 (15%) apps, respectively. In addition, the location-related permissions were requested by 24% of the apps, with over 50% of granted permission requests. This is in line with recent analysis [16] that claims that full network access is still asked in 99% of the smartphone apps, view Wi-Fi connections in 72% of the apps, and that one third of the apps request location permissions. Such permissions are requested by diverse applications that can be categorized according to the Google Play Store. Figure 2 presents the percentage of distinct apps from each category in where each of the referred permissions is requested. Depending on the app category as well as the user expectation on the app objective, the permission decisions might be affected [29]. For instance, TRAVEL_AND_LOCAL category is expected to request the location permission and, consequently, users tend to grant it. On the other hand, since Wi-Fi related permissions are automatically granted independently of the app category and the users' preferences, privacy risks arise, leading to fingerprinting and identification of users.

ACCESS_COARSE_LOCATION ACCESS_FINE_LOCATION ACCESS_WIFI_STATE CHANGE_WIFI_STATE 0

BUSINESS

COMMUNICATION

ENTERTAINMENT

FINANCE

FOOD_AND_DRINK

GAME

HEALTH_AND_FITNESS

LIFESTYLE

MAPS_AND_NAVIGATION

MUSIC_AND_AUDIO

PERSONALIZATION

PHOTOGRAPHY

PRODUCTIVITY

SHOPPING

20

4P0ercentage (%60)

80

100

SOCIAL TOOLS

TRAVEL_AND_LOCAL

Figure 2: Percentage of distinct apps from each category in where the permission (y axis) was requested. Categories with a percentage of apps inferior to 1% were removed from the plot to simplify visualization.

4 Fingerprinting and Re-identification Risk from Wi-Fi Data

Building on the considerable number of applications that are able to collect either location and/or Wi-Fi data, this section performs an analysis on the privacy implications of collecting Wi-Fi data by studying the resulting fingerprinting and re-identification risk. Throughout this analysis, we shall use Wi-Fi SSID and Wi-Fi BSSID to refer respectively to Wi-Fi network name and MAC Address of the Wi-Fi Access Point (AP).

Mariana Cunha et al.

4.1 Fingerprinting Users from Wi-Fi Data

A fingerprint consists in a combination of features that uniquely identify individuals. While there might be benefits from this, such as personalized services, the fact that applications can uniquely identify their users might pose threats to user's privacy. In order to mitigate this problem, smartphone OSs have tightened the access to unique identifiers, as previously mentioned. This section addresses the construction of fingerprints from Wi-Fi data. An initial fingerprint can be composed of all the scanned Wi-Fi BSSIDs per participant during the COP-MODE field study. In this case, all users would have a unique fingerprint, since users have a unique set of scanned BSSIDs throughout the entire field study. However, generally it may not be possible to access all historical data of Wi-Fi BSSIDs because the full information about configured Wi-Fi networks is restricted to Device Owner (DO), Profile Owner (PO) and system apps since Android 10 (circa 2019) [5]. Therefore, we will consider the following more realistic fingerprinting setups:

(1) The attacker has access to a single snapshot of all scanned Wi-Fi BSSIDs, other than continuous access to scanned Wi-Fi networks. This corresponds to a weaker attacker model that has access to much fewer information (single snapshot) of scanned Wi-Fi networks. This can correspond to a situation in which an app is installed and immediately uninstalled;

(2) The attacker has access to the SSID (network name) of the scanned Wi-Fi network with the highest signal strength (RSSI), thus representing the Wi-Fi network the user would usually connect to.

In the first scenario, assuming an adversary model where the attacker has access to less information (e.g. a subset of data instead of whole data), we consider a random snapshot in time and the respective set of scanned Wi-Fi BSSIDs. For statistical significance, each selection was performed 100 times and, thus, the results will be presented with the confidence interval of 95%. From the results, a single snapshot of scanned Wi-Fi BSSIDs per user creates a unique fingerprint for about 99% of the participants, which means that collecting the set of scanned Wi-Fi APs once is enough to uniquely identify more than 99% of the users. This percentage goes up to 100% when considering three snapshots in time, as graphically represented in Figure 3.

100.00 99.75 99.50 99.25 99.0500

0 1 Number of2snapshots 3

Figure 3: Percentage of identified users and respective confidence intervals of 95% when considering the selection of random snapshots (x axis) and the set of scanned Wi-Fi BSSIDs.

In the second scenario, we assume the access to the SSID of the network with the highest signal strength (RSSI), which represents the case when an adversary has access to the networks the

On the Difficulty of NOT being Unique: Fingerprinting Users from Wi-Fi Data in Mobile Devices

users usually connect to [35]. This information can be obtained in runtime from the current Wi-Fi connection. Figure 4a represents the results for this scenario, where the availability of a varying number of connected Wi-Fi SSIDs (network names) was considered for calculating the risk of unique fingerprinting. This rate goes from 83% when considering a single network name, 97% when considering 2 network names, up to 100% when considering 5 network names. If instead of the network name one has access to the BSSID/MAC address, its unicity makes the fingerprinting risk grows to 94% with a single instance as depicted in Figure 4b. This is justified by the multiple Wi-Fi APs that share the same SSID (e.g. eduroam (education roaming), that is, a world-wide roaming access service that provides Internet connectivity across University campus). These results show the relevance of information derived from Wi-Fi connections as a mean to fingerprint users, highlighting that 5 names of connected Wi-Fi networks suffice to re-identify all users in the dataset. The results discussed in this section emphasize the privacy risks of exposing either nearby or connected Wi-Fi AP devices and corresponding uniqueness.

100 95 90 85 5800

0 1 Num2ber of ne3tworks/p4oints 5

Re-identification (%)

Re-identification (%)

100.0

(a) Wi-Fi SSID

97.5

95.0

92.5

905.00

0 1 Num2ber of ne3tworks/p4oints 5

(b) Wi-Fi BSSID

Figure 4: Percentage of identified users and respective confidence intervals of 95% when considering the selection of random snapshots in time (x axis) and the Wi-Fi SSID/BSSID with the highest signal strength (RSSI).

4.2 Re-identification Risk through Top-N

Building on the fingerprinting analysis, this section assesses the re-identification risk through Wi-Fi data. The re-identification risk is a relevant privacy metric that evaluates the possibility of exposing private information of a certain individual. One of the biggest concerns in data privacy is related to identity disclosure, commonly mitigated by removing explicit identifiers. However, there are other attributes, also known as Quasi-Identifiers (QIDs), that can generate a unique combination and enable user re-identification. In order to assess the re-identification risk, we adapted the well-known "top-N" locations attack [51] to a "top-N" features/attributes attack. This

SAC '25, March 31-April 4, 2025, Catania, Italy

attack consists in the selection of the top-N features/attributes of a

user (i.e. the N most frequent) and an assessment of its uniqueness.

If the selected top is unique, then the user is considered identified.

Figure 5 starts by presenting a semantic analysis of the top-N

Wi-Fi AP BSSID per user, with N from 1 to 3. Considering the

selected semantic location (Home, Work, Traveling or Other), we

are able to categorize the most frequent location of the top-N Wi-Fi

BSSIDs within an interval of 5 minutes. The baseline represented

in the chart consists in the distribution of the scanned BSSIDs per

semantic location, where 84% were at home, 9% at work, 4% in

other location, and 3% while traveling. As expected, the top-1 (i.e.

most frequent BSSID) corresponds to the home location in more

than 90% of the situations. Similarly, top-2 and top-3 contain the

home location in more than 85% of the cases, which can be explained

by the fact that users might scan more than one Wi-Fi AP at home

that will be in the most frequently scanned BSSIDs. Comparing

with the baseline, the main difference is on the distribution of the

remaining locations, where other location occurs with a higher

percentage in the most frequent locations than in the baseline. The

performed analysis stresses the need of protecting the end-points

of users' trajectories, specifically home and work locations, due to

their potential for user re-identification [22].

100

Percentage (%)

80

60 40 20 0 Baseline 1

Home Work

Traveling

Other

2

3

N

Figure 5: Semantic analysis of the scanned Wi-Fi BSSIDs (baseline) and the top-N Wi-Fi BSSID per user with N from 1 to 3 within a 5 minute interval between the collected data and the permission request prompt.

Figure 6 presents the percentage of re-identified users when considering the top-N attack (N from 1 to 7) for the following features: GPS location, Wi-Fi location, Wi-Fi SSID, and Wi-Fi BSSID. In line with the message from previous works [8, 12], four points are enough to uniquely identify over 95% of the users. From Figure 6, the lower value of re-identification occurs for the Wi-Fi SSID top1, which can be explained by the number of public Wi-Fi hotspots with common names, such as those provided by Internet Service Providers (ISPs). On the other hand, over 90% of the users can be re-identified through the most scanned Wi-Fi BSSID and over 97% by the top-2. This is especially concerning since, as supported by the semantic analysis, the most frequent locations (i.e. top locations) are related to a private location: home.

While the re-identification risk assessment relied on the most frequent Wi-Fi APs per user in these results, the fingerprinting analysis presented in Section 4.1 considered two adversary scenarios, where the attacker has access to (1) a set of scanned BSSIDs per user and (2) the SSID with the highest signal strength. These approaches justify the differences in the re-identification percentages. For instance, the top-1 BSSID of Figure 6 considers the most

Re-identification (%)

Frequency

SAC '25, March 31-April 4, 2025, Catania, Italy

100

80

60

40

GPS Location

20

Wi-Fi Location Wi-Fi SSID

01

2

3

N4

Wi-Fi BSSID 567

Figure 6: Percentage of identified users considering the top-N attack (N from 1 to 7) for the following features: GPS location, Wi-Fi BSSID, Wi-Fi SSID, and Wi-Fi location.

frequent BSSID per user, whereas the random snapshot in time of Figure 3 contains all scanned Wi-Fi BSSIDs in that period of time, hence explaining the higher re-identification risk. The next section demonstrates the risk of re-identification through k-anonymity, a privacy principle that could be used in an attempt to minimize the risk of fingerprinting and re-identification.

4.3 Re-identification Risk through k-anonymity

A common approach to protect the user's privacy and mitigate the re-identification risk consists of reducing the data uniqueness. For instance, the k-anonymity principle guarantees that in a set of k individuals, the identity of each one cannot be disclosed from at least k-1 individuals in the same set [40, 41]. The achieved privacy level can be measured by the value of k, such that a higher value of k corresponds to a higher privacy level (i.e. it is harder to deanonymize). Based on this concept, a user can be singled out if for a given number of combinations k of a set of Quasi-Identifiers (QIDs), the frequency of records that have the same combination of QIDs is one. This section relies on this concept as a metric to assess the re-identification risk [17].

For k=1, where each set is composed by one of the 18613 unique scanned Wi-Fi BSSIDs in the COP-MODE dataset, we compute the frequency of records that have the same QID (i.e. the users that scanned the same BSSID). If = 1, then the user is considered singled out and, hence, re-identified. Figure 7 presents the frequency of records and the respective count. From these results, = 1 for 16064 Wi-Fi BSSIDs, signifying that 86% of the Wi-Fi BSSIDs are scanned by only one user. In this case, 81 out of the 82 users single scanned one of these Wi-Fi APs at least once, which means that an individual could be re-identified by knowing a scanned BSSID within this set.

The assessment performed in this section concludes the analysis of this paper by emphasizing the uniqueness of Wi-Fi data (86% of the Wi-Fi BSSIDs are single scanned) and the resulting possibility of using such data as unique identifiers. This has serious implications for the user's privacy as discussed next.

5 Privacy Implications of Wi-Fi Fingerprinting

With the claimed purpose of enhancing personalized services aligned with users' preferences and behaviors, applications are allowed to collect diverse data. However, this is achieved at the cost of compromised users' privacy and lack of anonymity. In this paper, we have shown that a considerable amount of applications have the required

Mariana Cunha et al.

15000

10000

5000

1000

500

400

300

200

100

0

1 2 3 4 5 6 7 8 f9k 10 11 12 13 14 15 16 17

Figure 7: Frequency of the records for the Wi-Fi BSSIDs.

permissions to collect location and/or Wi-Fi data, thus leading to a high fingerprinting and re-identification risk. This stresses the difficulty of not being uniquely identified by apps even with the existing restrictions to access explicit unique IDs in smartphones. The ability to uniquely identify users can be used to launch further attacks to compromise users' privacy, resulting in serious privacy implications that will be discussed in this section.

Regardless of the innumerous opportunities and benefits for both users and service providers, fingerprinting and profiling are examples of severe privacy concerns in the current digital society that are worsened by the high data uniqueness. Profiling consists of creating detailed and accurate models of users based on their data, making it possible to identify and track them. The resulting privacy risks are exacerbated when data correlations or other linkable data are present. Building on the analysis performed in this paper, where we emphasized the uniqueness of Wi-Fi data, an attacker would be able to create users' profiles based on Wi-Fi data that could be enriched with other contextual information (e.g. hour of the day or location) to fingerprint or even track users. For illustration, tracking users would allow entities to know whether the user is at home or not, which poses privacy risks that go beyond physical safety. This is a real and increasingly worrying problem, as demonstrated in recent news [23, 24]. The privacy breach presented in [23] reports a real-world battery monitor app that was able to collect and share GPS coordinates, nearby cell phone towers, Wi-Fi access points, and also the user's street address. This is especially critical since location data (even if anonymized) can be used to profile users and infer sensitive information (e.g. religion, as exposed in the news article [19]). These real-world examples accentuate the insights of this paper as enablers of potential privacy issues.

Due to the subtle and pervasive way in which fingerprinting can be performed, finding a trade-off between effective fingerprinting and user's privacy is still a major challenge in the current privacy threats' landscape. Although users are often unaware of the large amounts of data that are collected about them and how this information can be used to identify their profiles, the pervasiveness of mobile devices has fostered a rich opportunity to collect personal data. As discussed in this paper, despite the efforts to restrict the access to unique IDs, fingerprinting users is still possible through Wi-Fi data. This is a transversal problem for mobile devices in general, not only present in smartphones.

On the Difficulty of NOT being Unique: Fingerprinting Users from Wi-Fi Data in Mobile Devices

5.1 Privacy-Preserving Strategies

To mitigate the discussed privacy implications, it is crucial to implement data protection mechanisms and strategies that further safeguard users' privacy, as summarized below.

· Limiting data collection: Limiting the collection of unnecessary data that may never be used, specifically preventing the collection and retention of personal data to reduce users' exposure to privacy risks.

· Risk analysis and re-identification risk assessment: The risk analysis and re-identification risk assessment should be performed in a more systematic manner, and be part of the procedure for warranting access to any data types.

· Usage of anonymization methods: Upon identification of privacy risks, usage of anonymization techniques should be considered to provide adequate privacy-utility trade-offs. In particular, except for user location (for which obfuscation is already available in recent mobile OSes), current permission systems typically operate on an all-or-nothing basis, meaning that either users have access to the data (full utility, no privacy) or do not have access at all. A middle ground through anonymization methods should be explored, yet through automated privacy protection mechanisms, since the average user is not available/knowledgeable enough to setup and configure such techniques.

· Promoting data transparency: Companies and organizations should have a clear understanding of who they are interacting with, warranting that the users' digital identity is secure, and privacy is respected. In addition, methods that allow users to exercise their privacy rights should be provided, such as controlling the use and disclosure of sensitive personal data.

· Enhancing user awareness and education: Users should be aware of the privacy implications of their online activities and identities, but also educated about privacy to make informed decisions about data sharing and protection.

These privacy-preserving strategies aim at protecting users from potentially unauthorized access to their data. As one of the most widely used devices, smartphones have been at the forefront of introducing restrictions that safeguard users' privacy, however, much still remains to be done, particularly when other mobile devices are concerned.

6 Conclusion

The proliferation of mobile devices has fostered a multitude of services and applications, but also a rich opportunity to collect large amounts of data. In particular, the high demand for personalized services has been leading to a special interest on uniquely identifying users. Due to the privacy risks that advent from the data uniqueness, smartphones have tightened the access to unique identifiers (IDs). In this paper, resorting to a dataset that collected user data for at least one week, we demonstrate the possibility of fingerprinting users through location and Wi-Fi data, showing that it is still possible to fingerprint users by relying on available data despite the efforts to avoid unique IDs. From the performed analysis, we concluded that a single snapshot of a set of scanned Wi-Fi BSSIDs (MAC addresses) per user is enough to uniquely identify about 99% of

SAC '25, March 31-April 4, 2025, Catania, Italy

the users. The most frequent Wi-Fi BSSID is sufficient to re-identify more than 90% of the users and goes up to 97% of the users with the top2 scanned BSSIDs. Moreover, having access to the strongest Wi-Fi AP, that the users would connect to, leads to a re-identification risk of about 83% and 97% with 1 and 2 of the strongest SSIDs (network names), respectively. Thus, based on our results and according to the COP-MODE dataset, more than 300 applications are able to use location and/or Wi-Fi data as unique identifiers, even when other types of identifiers are blocked from access. While fingerprinting can be beneficial to provide personalized services that are aligned with users' preferences and behaviors, the consequences and resulting privacy risks cannot be ignored. Users are often unaware of the data collected through their mobile devices and, specifically, through the installed smartphone applications. In fact, due to the subtle and pervasive ways in which information is collected, there is a difficulty to control and/or opt-out of such collection, as well as a lack of techniques to mitigate the users' tracking. For illustration, tracking users would allow entities to know whether the user is at home or not, which poses privacy risks that go beyond physical safety. Therefore, finding a trade-off between effective fingerprinting and user's privacy protection is still a critical challenge in the current landscape of always connected mobile devices.

Acknowledgment

This work is financed by National Funds through the Portuguese funding agency, FCT - Fundação para a Ciência e a Tecnologia, within project LA/P/0063/2020 (DOI 10.54499/LA/P/0063/2020). The authors wish to acknowledge the support of the project CISUC UID/CEC/00326/2020 and the European Social Fund through the Regional Operational Program Centro 2020 of FCT, and the project PRIVATEER funded by the Smart Networks and Services Joint Undertaking (SNS JU) under the European Union's Horizon Europe research and innovation programme under Grant Agreement No 101096110. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the EU or SNS JU. Mariana Cunha wishes to acknowledge financial support by the Portuguese funding institution Fundação para a Ciência e a Tecnologia (FCT) under the grant 2020.04714.BD (DOI 10.54499/2020.04714.BD).

References

[1] Jagdish Prasad Achara, Gergely Acs, and Claude Castelluccia. 2015. On the Unicity of Smartphone Applications. In Proceedings of the 14th ACM Workshop on Privacy in the Electronic Society (WPES '15). ACM, 27­36.

[2] Jagdish Prasad Achara, Mathieu Cunche, Vincent Roca, and Aurélien Francillon. 2014. Short paper: Wifileaks: Underestimated privacy implications of the ACCESS_WIFI_STATE Android permission. In Proceedings of the 2014 ACM Conference on Security and Privacy in Wireless & Mobile Networks. ACM, 231­236.

[3] Md Sabbir Ahmed and Nova Ahmed. 2021. Exploring unique app signature of the depressed and non-depressed through their fingerprints on apps. In International Conference on Pervasive Computing Technologies for Healthcare. Springer, 218­239.

[4] Efthimios Alepis and Constantinos Patsakis. 2017. There's Wally! Location Tracking in Android without Permissions. In Proceedings of the 3rd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,. INSTICC, SciTePress, 278­284.

[5] Android. 2024. Android 10. https://developer.android.com/guide/topics/ connectivity/wifi-scan. Accessed: 2024-07-05.

[6] John S. Atkinson, John E. Mitchell, Miguel Rio, and George Matich. 2018. Your WiFi is leaking: What do your mobile apps gossip about you? Future Generation Computer Systems 80 (2018), 546­557. https://doi.org/10.1016/j.future.2016.05.030

[7] Benjamin Baron and Mirco Musolesi. 2020. Where you go matters: a study on the privacy implications of continuous location tracking. Proceedings of the ACM

SAC '25, March 31-April 4, 2025, Catania, Italy

on Interactive, Mobile, Wearable and Ubiquitous Technologies 4, 4 (2020), 1­32. [8] Antoine Boutet and Sonia Ben Mokhtar. 2021. Uniqueness assessment of hu-

man mobility on multi-sensor datasets. In Proceedings of the 16th International Conference on Availability, Reliability and Security. ACM, 1­10. [9] Federal Trade Commission. 2016. Mobile Advertising Network InMobi Settles FTC Charges It Tracked Hundreds of Millions of Consumers' Locations Without Permission. https://www.ftc.gov/news-events/news/pressreleases/2016/06/mobile- advertising- network- inmobi- settles- ftc- charges- ittracked-hundreds-millions-consumers. Accessed: 2024-07-17. [10] Mathieu Cunche, Mohamed Ali Kaafar, and Roksana Boreli. 2012. I know who you will meet this evening! linking wireless devices using wi-fi probe requests. In 2012 IEEE International Symposium on a World of Wireless, Mobile and Multimedia Networks (WoWMoM). IEEE, 1­9. [11] Mariana Cunha, Ricardo Mendes, and João P Vilela. 2021. A survey of privacypreserving mechanisms for heterogeneous data types. Computer science review 41 (2021), 100403. [12] Yves-Alexandre De Montjoye, César A Hidalgo, Michel Verleysen, and Vincent D Blondel. 2013. Unique in the crowd: The privacy bounds of human mobility. Scientific reports 3, 1 (2013), 1­5. [13] Android Developers. 2023. Get the last known location. https://developer.android. com/training/location/retrieve-current. Accessed: 2024-07-05. [14] Android Developers. 2024. Best practices for unique identifiers. https://developer. android.com/identity/user-data-ids. Accessed: 2024-07-05. [15] Android Developers. 2024. Package visibility filtering on Android. https:// developer.android.com/training/package-visibility. Accessed: 2024-07-05. [16] Edvardas Mikalauskas. 2022. Android apps are asking for too many dangerous permissions. Here's how we know. https://cybernews.com/privacy/android-appsare-asking-for-too-many-dangerous-permissions-heres-how-we-know/. Accessed: 2024-07-05. [17] Khaled El Emam and Fida Kamal Dankar. 2008. Protecting privacy using kanonymity. Journal of the American Medical Informatics Association 15, 5 (2008), 627­637. [18] European Parliament and Council of the European Union. 2016. Regulation (EU) 2016/679 of the European Parliament and of the Council. http://data.europa.eu/eli/ reg/2016/679/oj [19] Lorenzo Franceschi-Bicchierai. 2015. Redditor cracks anonymous data trove to pinpoint Muslim cab drivers. https://mashable.com/archive/redditor-muslimcab-drivers. Accessed: 2024-11-11. [20] Julien Freudiger. 2015. How talkative is your mobile device? an experimental study of Wi-Fi probe requests. In Proceedings of the 8th ACM Conference on Security & Privacy in Wireless and Mobile Networks (WiSec '15). ACM, Article 8, 6 pages. [21] Julien Gamba, Álvaro Feal, Eduardo Blazquez, Vinuri Bandara, Abbas Razaghpanah, Juan Tapiador, and Narseo Vallina-Rodriguez. 2023. Mules and Permission Laundering in Android: Dissecting Custom Permissions in the Wild. IEEE Transactions on Dependable and Secure Computing (2023), 1­18. [22] Philippe Golle and Kurt Partridge. 2009. On the anonymity of home/work location pairs. In International Conference on Pervasive Computing. Springer, 390­397. [23] haxrob. 2023. Discovering that your car battery monitor is siphoning up your location data. https://haxrob.net/discovering-that-your-bluetooth-car-batterymonitor-is-siphoning-up-your-location-data/. Accessed: 2024-11-11. [24] Misha Rykov Jen Caltrider and Zoë MacDonald. 2023. Discovering that your car battery monitor is siphoning up your location data. https://foundation.mozilla.org/en/privacynotincluded/articles/its- officialcars- are- the- worst- product- category- we- have- ever- reviewed- for- privacy/. Accessed: 2024-11-11. [25] Kathryn Zickuhr. 2013. Main Report. https://www.pewresearch.org/internet/ 2013/09/12/location-based-services-2/. Accessed: 2024-07-05. [26] Tong Li, Tong Xia, Huandong Wang, Zhen Tu, Sasu Tarkoma, Zhu Han, and Pan Hui. 2022. Smartphone app usage analysis: datasets, methods, and applications. IEEE Communications Surveys & Tutorials 24, 2 (2022), 937­966. [27] Bin Liu, Mads Schaarup Andersen, Florian Schaub, Hazim Almuhimedi, Shikun Aerin Zhang, Norman Sadeh, Yuvraj Agarwal, and Alessandro Acquisti. 2016. Follow my recommendations: A personalized privacy assistant for mobile app permissions. In 12th Symposium on Usable Privacy and Security (SOUPS). 27­41. [28] Allan Lyons, Julien Gamba, Austin Shawaga, Joel Reardon, Juan Tapiador, Serge Egelman, Narseo Vallina-Rodriguez, et al. 2023. Log: It's Big, It's Heavy, It's Filled with Personal Data! Measuring the Logging of Sensitive Information in the Android Ecosystem. In Usenix Security Symposium. [29] Ricardo Mendes, André Brandão, João P Vilela, and Alastair R Beresford. 2022. Effect of user expectation on mobile app privacy: a field study. In 2022 IEEE international conference on pervasive computing and communications (PerCom). IEEE, 207­214. [30] Ricardo Mendes, Mariana Cunha, João P Vilela, and Alastair R Beresford. 2022. Enhancing User Privacy in Mobile Devices Through Prediction of Privacy Preferences. In Computer Security­ESORICS 2022: 27th European Symposium on Research

Mariana Cunha et al.

in Computer Security, Copenhagen, Denmark, September 26­30, 2022, Proceedings, Part I. Springer, 153­172. [31] Mark Huasong Meng, Qing Zhang, Guangshuai Xia, Yuwei Zheng, Yanjun Zhang, Guangdong Bai, Zhi Liu, Sin G Teo, and Jin Song Dong. 2023. Post-GDPR Threat Hunting on Android Phones: Dissecting OS-level Safeguards of User-unresettable Identifiers. In 30th annual Network and Distributed System Security Symposium. [32] ABM Musa and Jakob Eriksson. 2012. Tracking unmodified smartphones using wi-fi monitors. In Proceedings of the 10th ACM conference on embedded network sensor systems. Association for Computing Machinery, 281­294. [33] Suman Nath. 2015. MAdScope: Characterizing Mobile In-App Targeted Ads. In Proceedings of the 13th Annual International Conference on Mobile Systems, Applications, and Services (Florence, Italy) (MobiSys '15). Association for Computing Machinery, New York, NY, USA, 59­73. https://doi.org/10.1145/2742647.2742653 [34] Le Nguyen, Yuan Tian, Sungho Cho, Wookjong Kwak, Sanjay Parab, Yuseung Kim, Patrick Tague, and Joy Zhang. 2013. Unlocin: Unauthorized location inference on smartphones without being caught. In 2013 International Conference on Privacy and Security in Mobile Systems (PRISMS). IEEE, 1­8. [35] Changhua Pei, Zhi Wang, Youjian Zhao, Zihan Wang, Yuan Meng, Dan Pei, Yuanquan Peng, Wenliang Tang, and Xiaodong Qu. 2017. Why it takes so long to connect to a WiFi access point. In IEEE INFOCOM 2017-IEEE Conference on Computer Communications. IEEE, 1­9. [36] The Associated Press. 2021. Priest outed via Grindr app highlights rampant data tracking. https://www.nbcnews.com/tech/security/priest-outed-grindrapp-highlights-rampant-data-tracking-rcna1493. Accessed: 2024-07-05. [37] Abbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan, Mark Allman, Christian Kreibich, Phillipa Gill, et al. 2018. Apps, trackers, privacy, and regulators: A global study of the mobile tracking ecosystem. In The 25th annual Network and Distributed System Security Symposium (NDSS). [38] Joel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On, Narseo VallinaRodriguez, and Serge Egelman. 2019. 50 ways to leak your data: An exploration of apps' circumvention of the android permissions system. In 28th USENIX security symposium (USENIX security 19). USENIX Association, Santa Clara, CA, 603­620. [39] Fergus Ryan and Michael Schukat. 2019. Wi-fi user profiling via access point honeynets. In 2019 30th Irish Signals and Systems Conference (ISSC). IEEE, 1­4. [40] Pierangela Samarati and Latanya Sweeney. 1998. Generalizing data to provide anonymity when disclosing information. In PODS, Vol. 98. Citeseer, 188. [41] Pierangela Samarati and Latanya Sweeney. 1998. Protecting privacy when disclosing information: k-anonymity and its enforcement through generalization and suppression. Technical Report. technical report, SRI International. [42] Vedran Sekara, Laura Alessandretti, Enys Mones, and Håkan Jonsson. 2021. Temporal and cultural limits of privacy in smartphone app usage. Scientific reports 11, 1 (2021), 1­9. [43] Yash Sharma and Anshul Arora. 2024. A comprehensive review on permissionsbased Android malware detection. International Journal of Information Security (2024), 1­36. [44] Vincent Toubiana and Mathieu Cunche. 2021. No need to ask the Android: Bluetooth-Low-Energy scanning without the location permission. In Proceedings of the 14th ACM Conference on Security and Privacy in Wireless and Mobile Networks (Abu Dhabi, United Arab Emirates) (WiSec '21). ACM, 147­152. [45] Martin W Traunmueller, Nicholas Johnson, Awais Malik, and Constantine E Kontokosta. 2018. Digital footprints: Using WiFi probe and locational data to analyze human mobility trajectories in cities. Computers, Environment and Urban Systems 72 (2018), 4­12. [46] Zhen Tu, Runtong Li, Yong Li, Gang Wang, Di Wu, Pan Hui, Li Su, and Depeng Jin. 2018. Your Apps Give You Away: Distinguishing Mobile Users by Their App Usage Fingerprints. Proc. ACM Interact. Mob. Wearable Ubiquitous Technol. 2, 3 (2018), 23 pages. [47] Imdad Ullah, Roksana Boreli, and Salil S Kanhere. 2023. Privacy in targeted advertising on mobile devices: a survey. International Journal of Information Security 22, 3 (2023), 647­678. [48] Mathy Vanhoef, Célestin Matte, Mathieu Cunche, Leonardo S. Cardoso, and Frank Piessens. 2016. Why MAC Address Randomization is not Enough: An Analysis of Wi-Fi Network Discovery Mechanisms. In Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security. ACM, 413­424. [49] Gabriella Verga, Salvatore Calcagno, Andrea Fornaia, and Emiliano Tramontana. 2019. Smart Cities and Open WiFis: When Android OS Permissions Cease to Protect Privacy. In Internet and Distributed Computing Systems. Springer International Publishing, Cham, 457­467. [50] Qiang Xu, Rong Zheng, Walid Saad, and Zhu Han. 2015. Device fingerprinting in wireless networks: Challenges and opportunities. IEEE Communications Surveys & Tutorials 18, 1 (2015), 94­104. [51] Hui Zang and Jean Bolot. 2011. Anonymization of location data does not work: A large-scale measurement study. In Proceedings of the 17th annual international conference on Mobile computing and networking. ACM, 145­156. [52] Wanyi Zhang, Qiang Shen, Stefano Teso, Bruno Lepri, Andrea Passerini, Ivano Bison, and Fausto Giunchiglia. 2021. Putting human behavior predictability in context. EPJ Data Science 10, 1 (2021), 42.